QR Codes in Phishing Emails
Attackers put QR codes in emails to dodge filters and lure you onto a personal phone. How QR email phishing works.
QR codes in phishing emails are a fast-growing trick: attackers embed a scannable image instead of a clickable link so their message slips past email filters and lures you onto a personal phone with weaker protection. Once you know why they do it, the red flags become easy to see. 🐾
For years, email security has been an arms race over links. Filters got good at reading a message, extracting every URL, and comparing it to lists of known-bad sites. Attackers responded with a clever pivot: hide the link inside a QR code. Suddenly the dangerous address isn't text a filter can read — it's a picture. This is why quishing has moved so aggressively into the inbox.
Why would an attacker put a QR code in an email?
It seems almost backwards — you're reading email on a computer that can click links, so why send a code you have to scan with a phone? There are three deliberate reasons.
1. To evade email security filters
Most email gateways scan the text and links of a message. A QR code is an embedded image, so there's no link in the text for the filter to analyze. The malicious destination is encoded in the pixels, invisible to tools built to read words. The phishing email lands in the inbox looking clean. We cover the broader pattern in what is quishing?
2. To move you from a protected PC to an unprotected phone
This is the most important reason in a workplace. Your work computer likely has serious defenses: URL filtering, endpoint protection, a managed browser, warnings on suspicious sites. Your personal phone usually has none of that. By forcing you to scan the code with your phone, the attacker walks you around every corporate safeguard and lands you on the malicious page with your guard — and your device's guard — down.
The QR code in a phishing email is a bridge. It carries you off the defended computer and onto the phone in your pocket, where the same trap has a far better chance of working.
3. To exploit trust in codes
We've been trained that scanning a code is a normal, safe thing to do dozens of times a week. Attackers borrow that trust, dressing the code up as a routine action: verify your account, review a document, reset your multi-factor authentication.
What do these phishing emails usually pretend to be?
The framing is designed to feel routine and mildly urgent:
| Pretext | What the code really leads to |
|---|---|
| "Your MFA setup expires — rescan to keep access" | A fake sign-in page harvesting your password and MFA code |
| "You have a held/secure message" | A look-alike email login |
| "Review this shared document" | A cloud-storage credential trap |
| "HR: acknowledge the new policy" | A corporate portal clone |
| "Payroll/benefits update required" | A page capturing login and personal details |
Notice the common thread: each one nudges you to sign in. That's the payload — your credentials. Where the code sends you, and how to read that address, is the subject of QR codes and malicious URLs.
What are the red flags in a QR-code phishing email?
These messages give themselves away if you know the tells:
- A QR code where a normal link would do. If an email wants you to scan a code to log into something you'd normally just click, ask why. The most likely answer is filter evasion.
- Pressure to use your phone. Wording like "scan with your mobile device" is a giveaway of the PC-to-phone pivot.
- Urgency and consequences. "Access will be suspended in 24 hours" is manufactured pressure.
- A code embedded as an image with little other content, or a message that's mostly one big graphic (another way to dodge text filters).
- Sender oddities. A display name that says "IT Support" but an address that doesn't match your organization's real domain.
- Generic greetings and small inconsistencies in logos or wording.
How should I respond to a suspicious code in an email?
Your safest options, in order:
- Don't scan it. If the email is unexpected or pressuring, that alone is reason enough to stop.
- Verify through a known channel. If it claims to be from IT, your bank, or a colleague, contact them using details you already have — not anything in the email.
- Go direct. If you genuinely need to log in somewhere, open the official app or type the website address you know into your browser. Never reach a login page by scanning a code from an email.
- If you must inspect it, preview the link. A scanner that lets you scan a code safely and reveals the real destination first means you can read the domain without being dumped straight onto the page.
- Report it. Forward it to your security team or use your mail client's report-phishing button so filters and colleagues can be protected. See how to report a malicious QR code.
Why filters can't fully solve this for you
Security teams are catching up — some gateways now render and read QR images, and some flag emails that contain codes. But detection is imperfect, images can be obfuscated, and new tricks appear constantly. That means the human at the keyboard remains the most reliable line of defense. The reassuring flip side is that the human defense is easy: a QR code asking you to log into something, arriving by email, should almost always be treated as hostile until proven otherwise.
A quick sanity test
Before scanning any code in an email, ask yourself: Would this organization really ask me to scan a code to log in? Banks, employers, and major services overwhelmingly don't. If the answer is "probably not," trust that instinct. For a broader routine you can apply to any code, our QR code safety checklist is a good companion. And when you need to send codes to others, you can create a free QR code that points transparently at your real link.
Frequently asked questions
Why do phishing emails use QR codes instead of links?
Because a QR code is an image, many email filters can't read the hidden address the way they read a text link, so the message slips through. Codes also push you onto a personal phone, which usually lacks the security protections of a work computer.
Is it safe to scan a QR code from a work email?
Treat it with suspicion, especially if it asks you to log in or acts urgent. If you genuinely need to access a service, open its official app or type the known website yourself rather than scanning. When unsure, verify with your IT team first.
How can attackers get past email security with a code?
Standard filters analyze the text and links in a message. A QR code carries its malicious URL inside the pixels of an image, so there's no readable link for the filter to check, and the email can pass inspection.
What is the PC-to-phone pivot?
It's the tactic of using a QR code to move a victim from a well-defended office computer to a personal phone with weaker protection. The phone is more likely to open the malicious page without warnings, so the attack succeeds more often.
What should I do if I scanned one and entered my password?
Change that password immediately, and anywhere you reused it, then enable multi-factor authentication. Alert your IT or security team so they can protect accounts and other staff, and watch for unusual sign-in activity.
Make a QR code the honest way 🐾
Free forever, no tracking, no expiry — generated right in your browser.