
Workplace MODULE
QR code phishing
One scan moves the attack onto a device your organisation often cannot see or protect.
How a printed square moves an attack from a computer your organisation defends onto a phone it often cannot see, why QR codes were a blind spot for mail filters and what attackers now do about it, why a phone hides where a link goes, and what to do instead. For everybody, at a desk and in a car park.
- Recognise a QR code as a request to continue on a device your organisation may not protect.
- Read a destination properly on a small screen, or decide not to open it.
- Spot a tampered physical code, and report a scan you regret quickly.
Your learning path
01The scan that changes deviceUnderstand why moving you onto a personal phone is the point of the attack.Locked02What a filter can and cannot do with a codeUnderstand why QR codes were a blind spot, how filters closed it, and why arrival is still not a verdict.Locked03Why a phone hides the destinationJudge a web address on a small screen, and recognise when you cannot.Locked04The sticker over the real codeRecognise a tampered physical code before you pay anybody anything.Locked05What the page does once you are on itRecognise what a landing page is collecting, and why it is so convincing.Locked06What to do instead, and what to do afterReplace the scan with a route that works, and act quickly if you have already scanned one.LockedPut your decisions into practice.
Complete each lesson’s scenario, then take eight new questions. A score of at least 80% earns a personal completion record. Retry with feedback; this is a learning exercise, not a timed exam or professional accreditation.
Lessons and scenarios are original Jatzo material informed by published guidance and research:
- NCSC: QR codes, what is the real risk
- Microsoft Security: email threat landscape, Q1 2026 trends and insights
- Action Fraud: quishing alert, £3.5 million lost in a year
- RAC: QR parking scams soar in number across the UK
- Barracuda: split and nested QR codes in quishing attacks
- Barracuda: ASCII-based QR codes and other novel phishing techniques
- Microsoft: how Defender for Office 365 innovated to address QR code phishing
- Ironscales: a QR code inside a PDF, used for targeted credential harvesting
- NCSC: report a suspicious email
- NCSC: warning on messaging app targeting and linked devices
