QR Code Scams: What They Are and How to Protect Your Business
Your staff are careful with suspicious emails. They know not to click strange links. But a QR code in an email looks different - it looks like a document, an invoice, or a login prompt. It looks normal. And that is exactly why attackers are using them.
A QR code scam works by hiding a malicious web address inside an image. Your email filter scans text, not pictures, so the link inside the code passes straight through. When someone scans it, they do so on their phone - which sits outside almost all of the protection your business has on its computers. The attacker has moved your staff member off a protected device and onto a personal one without them noticing. This technique has a name: quishing. Microsoft reported a 146% rise in QR code phishing in the first quarter of 2026, climbing from 7.6 million attacks in January to 18.7 million in March. Most arrived hidden inside PDF attachments that looked like ordinary documents.
The scams follow predictable patterns. An email that looks like it is from your IT support or Microsoft, asking you to scan a code to re-enrol multi-factor authentication. A shared document that asks you to sign in before viewing. A PDF invoice with a code to pay faster - routing the payment to the attacker. A missed delivery notice with a code to reschedule. Even physical stickers placed over legitimate QR codes on parking meters and payment terminals. The page that opens at the other end is always the same kind of fake: a login screen, a payment form, something built to capture credentials or card details.
When this is handled well, your team knows what these scams look like before they encounter one. They pause before scanning a code that arrived in an email. They check the web address their phone shows before tapping through. They go directly to the real site if an email claims their account needs attention, rather than trusting a code to take them there. Multi-factor authentication is set up in a way that is resistant to phishing - so that even if a password is captured, it cannot be used without a second step that the attacker cannot intercept. That combination of habit and setup is what limits the damage, and it is the kind of layered approach that IT support for professional services firms is built around.
IT Stuffed ran a full systems cyber security audit for us, which was very eye-opening! They helped us implement the necessary changes and gave us some strategic advice on future steps. Daniel and the team are incredibly dedicated, great communicators and a real pleasure to deal with.
Ruby Williams
When faced with a cyber-attack a year ago we greatly appreciated the immediate and ongoing support we received from IT Stuffed. Happy to recommend this service.
Maggy Tai Rākena
If someone on your team has already scanned a suspicious code and entered details on the page that opened, move quickly. Change the password for that account, and any other account using the same password. Make sure multi-factor authentication is active. Contact your IT support so they can check for unusual sign-ins. If banking or card details were entered, call the bank. Acting within hours matters - the window where an attacker can use captured credentials is narrow if you close it fast. You can report phishing incidents to CERT NZ, which tracks these threats and provides recovery guidance for NZ businesses.
Most businesses have never briefed their team on QR code scams. A short message with a real example - what it looks like, what to do if you see one - is enough to raise awareness significantly. Your cyber security setup should also include email filtering that scans images, not just text, because standard filters will not catch these on their own. It is also worth reviewing the steps that reduce your overall breach risk, since QR code attacks are one of several vectors that often go unaddressed together.
ITstuffed works with professional services businesses across Canterbury on exactly this kind of layered protection. If you want a clear picture of where your business stands, book a 15-minute IT Fit Check and we will tell you what we find.
