What a QR code hides, and what your phone shows you
A QR code can store a web address as a pattern. You cannot read it by eye, but your phone can. Point the built-in camera at one and it shows a preview of the address before you tap. Read it every time, and use the camera that came with the phone rather than a downloaded scanner app.
It is not a guarantee. The address can redirect elsewhere once opened, and a plausible address does not prove the site behind it is genuine. The National Cyber Security Centre's advice is that context matters: a code on a restaurant menu is probably fine, a code stuck in a public place carries more risk, and a code that arrives by email or asks for a lot of information deserves real suspicion. Scanning a code does not, on its own, hand anyone your account. What you do on the page it opens is what counts.
The email version
An email arrives with a QR code in the body or in an attached PDF, and a reason to scan it: a voicemail to listen to, a document to sign, a password about to expire. You scan it with your phone, land on a page that looks like the Microsoft sign-in screen, and sign in.
The attack moves from your work computer to your phone. Mailbox filtering has already had its chance to catch the email, and configured account policies such as conditional access can still apply at sign-in, but a personal phone may lack some of the controls a managed work device has. Its browser also shows less of the address, so a lookalike domain is easier to miss.
Filtering is not blind to QR codes. Microsoft Defender for Office 365 extracts the address from the code image and checks it like any other link. Treat that as one layer, not the whole answer.
Multi-factor authentication reduces the risk. It does not remove it
If someone types their password into a fake page, multi-factor authentication is often what stops the criminal using it. But a code from an app or text message can be relayed through a fake page in real time, so a convincing fake page can collect both.
Phishing-resistant methods such as passkeys, Windows Hello for Business and FIDO2 security keys are designed to resist fake sign-in pages. They reduce the risk without removing every way an account could be compromised. Ask your IT provider to configure them, starting with anyone who can move money or has admin rights.
What to tell your team
Send your team one short message with three points.
- Treat a QR code in an email the same way you would treat an unexpected link from that sender. If it claims to be from Microsoft, go to the site yourself.
- For parking, use the operator's app if you already have it, or an official address you have checked independently, instead of relying on an unfamiliar code. An address printed on the same machine could be on the same fake sticker.
- Read the camera preview before tapping, and check physical codes for signs of tampering, such as a sticker covering the original.
If someone has already scanned and signed in, tell your IT provider straight away so the session can be revoked and the password changed. Then forward the email to report@phishing.gov.uk, for the NCSC to investigate.
If you print QR codes yourself
Menus, table signs, invoices, event posters: anyone can stick a code over yours and use your name to defraud your customers. Point your codes at your own domain, print the address underneath in plain text, and check regularly that the codes on tables and signs are still the ones you printed.
Where to start
Ask whether your Microsoft 365 sign-ins use a phishing-resistant method. If you would like us to look, get in touch or ring 01584 517234. We look after businesses across Shropshire, Herefordshire, Worcestershire and Powys.

