# QR code phishing (quishing) in Microsoft 365: why filters miss it

> QR code phishing hides the malicious link inside an image, slipping past text-based email filters. Here is how quishing works and how to defend your team against it.

Source: https://olyteck.com/blog/qr-code-phishing-quishing-microsoft-365
Published: 2026-06-24
Author: Oleg Garasym, Olyteck (France, EU-hosted)
Product: Olyteck Guard
Topics: email security, phishing, quishing, qr code, microsoft 365
License: free to quote with attribution to Olyteck and a link to the source URL.

---

Quishing is phishing that delivers its malicious link as a QR code instead of as clickable text. The
email looks routine, often with a single image and a short instruction: "scan to verify your
account", "scan to view the secure document", "scan to keep your password". The victim lifts their
phone, scans the code, and lands on a credential-harvesting page that the email filter never had a
chance to see.

It works because it sidesteps the two things that usually protect a Microsoft 365 inbox: link
scanning and the corporate device. Understanding both is the key to stopping it.

## Why QR codes slip past email filters

Most email security reads text. It inspects the visible body, the headers and any URLs written into
the message, checks them against reputation data, and rewrites or blocks the bad ones. A QR code
defeats that model in two ways:

- **The link is inside an image.** There is no URL in the text for a text-based scanner to read. The destination is encoded in a picture, which many filters do not decode.
- **The click moves to a phone.** When the victim scans with a personal phone, the dangerous link opens outside your Microsoft 365 protections entirely: no Safe Links, no managed browser, often no endpoint controls. The riskiest moment happens on the least protected device.

That combination is why quishing rose so sharply once attackers realised text-link filtering had
gotten good. They simply moved the payload to where the filter is not looking.

## The lures that work

Quishing leans on the same psychology as classic phishing: authority, urgency and a routine-looking
action. The patterns that show up most:

- **MFA or password "re-enrollment"** that claims your security setup is expiring today.
- **Shared document or DocuSign** notifications with a QR code instead of a button.
- **Payroll, benefits or HR** messages timed around the end of the month.
- **Delivery and invoice** notices aimed at finance and operations staff.

> If a message wants you to scan a code with your phone to sign in or approve something, treat it as
> guilty until proven innocent, no matter how ordinary the sender looks.

## How to defend against it

No single control catches everything, and any honest vendor will tell you so. A layered approach
works:

1. **Decode and judge the code, not just the text.** Defences that actually read the QR image, extract the destination and weigh its reputation can flag the message that a text-only filter waves through.
2. **Warn the person in the message.** A plain-language banner that says "this email contains a QR code leading to an unrecognised site" turns an invisible risk into a decision the recipient can make. This matters most for the non-technical staff quishing targets.
3. **Make reporting one click.** When someone is unsure, the safe path is a report button that routes to whoever can act, not a forwarded email that gets lost.
4. **Reinforce the rule.** Sign-ins and approvals happen by navigating to the app yourself, never by scanning a code from an email.

This is the gap Olyteck Guard is built for: it scores inbound mail for spoofing, impersonation,
malicious links and QR codes, adds an in-message banner with a public "why it was flagged" page, and
gives people a one-click way to report. The detection lives where the attack lands, which is the
inbox, and the verdict is written in language a finance manager can act on.

## A practical baseline

- Use email security that decodes and evaluates QR codes, not only text links
- Add visible banners for image-only and QR-bearing messages
- Give staff a one-click report button and a clear escalation path
- Train on the "scan to sign in" pattern with real examples
- Set the rule: authenticate by going to the app yourself, never from a scanned code

Attackers moved the link into a picture because the picture was the blind spot. Close that blind
spot, make the warning visible, and quishing turns from an invisible trap into one more flagged
message your team already knows to ignore.

