Staff have spent years learning to hover over a link before clicking it. A QR code sidesteps that habit entirely, there's no text to preview, no domain to check, just a phone camera and a page that opens instantly. That gap is exactly what "quishing" scams are built around, and they're showing up in more Perth business inboxes than most owners realise.
Why QR Codes Beat Email Security
Most email filtering works by scanning link text and attachments against known bad domains and patterns. A QR code is just an image, the destination URL is encoded inside pixels, not text, so it doesn't get flagged the same way. By the time it's decoded, it's already on a personal phone, often outside whatever protection the business network provides. This is the same reason phishing tactics keep evolving, attackers move to whatever channel current defences haven't caught up to yet.
Where These Scams Actually Show Up
- Fake "re-verify your account" emails - mimicking Microsoft 365, DocuSign, or a bank, with a QR code replacing what would normally be a clickable button.
- Physical tampering - a sticker placed over a genuine QR code on a parking meter, invoice, or delivery notice, redirecting to a fake payment page.
- Fake delivery and invoice notices - particularly common around high email volume periods; see our guide to Black Friday and Cyber Monday scams for the seasonal version of this.
- Meeting room and event signage - a printed QR code left in a shared space, easy to swap without anyone noticing.
What Makes Them Effective
The scan usually happens on a personal phone, which sits outside the business's email filtering, DNS filtering, and endpoint protection entirely. Staff also tend to trust QR codes more than links, they associate them with menus, payments, and event check-ins rather than phishing, so the usual suspicion doesn't kick in the same way.
How to Defend Against It
Treat a QR code exactly like a link: don't scan one from an unexpected email, and don't enter credentials or payment details on a page it opens without checking the URL that loads. Enrol company phones in mobile device management so security policies still apply off the office network, and if your email platform offers QR code scanning as part of its filtering, confirm it's switched on. Beyond that, this is a staff awareness problem more than a technology one, worth a mention alongside your regular phishing and security training.
Frequently Asked Questions
Why do QR codes get past email security that would normally block a phishing link?
Most email filtering scans the actual text of a link for known bad domains. A QR code is an image, so the malicious URL inside it isn't visible as text until a phone camera decodes it, well after the email has already landed in an inbox.
Are QR codes in emails always suspicious?
No, plenty of legitimate marketing and invoicing emails use them. The red flags are the same as any phishing attempt: unexpected urgency, a request to "re-verify" an account or payment method, or a QR code replacing a link that would normally just be clickable text.
Can we block QR code phishing with a filter or firewall rule?
Some modern email security platforms can now decode and scan QR code images automatically, so it's worth checking whether yours does. Either way, technology alone won't catch every variant, staff awareness is still the more reliable layer.
What should staff do if they've already scanned a suspicious QR code?
Don't enter any credentials or payment details on the page it opens. If anything was entered, change that password immediately and check for unfamiliar sign-ins, the same response as any other phishing click.
We can add QR code awareness to your team's next security training session.
Cybersecurity Services →Not sure if your email filtering catches this?
Call 0433 087 091 for a free, no-obligation IT health check.
Book a Free IT Health CheckFor related reading, see Common Phishing Email Tactics Targeting Perth Businesses, Dark Web Monitoring for Perth Businesses, and Social Engineering Attacks: What Perth Businesses Need to Know.