Security teams should treat QR codes as a delivery channel, not a trust signal. Users need to verify the source, inspect stickers or unusual placements, and avoid scanning codes from unfamiliar emails or messages. If a code prompts for credentials or payment, confirm the request through the organisation’s normal website, customer service line, or in person before taking action.
QR codes are a delivery channel, so treat them like any other untrusted entry point
QR phishing works because it bypasses a lot of the visual cues people rely on in email and on the web. A scan can move a user from a poster, invoice, package, badge, or message into a credential prompt or payment flow without the usual browser context, so security teams need controls that assume the code itself is not trustworthy.
The strongest defence is to verify the destination before any sensitive action. That means checking the source of the code, looking for tampering on physical stickers or printed materials, and confirming whether the request makes sense in the current business context. If a code leads to login, payment, or account recovery, users should pivot to a known official channel rather than continuing from the scan.
- Teach users to treat unexpected QR codes as suspicious, especially when they arrive by email, messaging apps, or paper labels in public places.
- Require a second path for high-value actions, such as visiting the organisation’s known website manually or calling a verified support line.
- Use awareness examples that show both physical tampering and digital lures, because attackers use both surfaces to create trust.
Controls should cover the physical, email, and mobile layers together
Reducing qr code phishing is less about blocking the image format and more about constraining the surrounding workflow. Organisations should combine user education with mail filtering, mobile security guidance, and web protections that reduce the chance a scan can lead directly to a successful compromise. Where QR codes are used internally, the team should also define approved use cases so staff can spot out-of-pattern requests.
For trusted business processes, make the destination predictable and easy to verify. A code that is supposed to support event registration, parking, asset tracking, or payments should route to a domain users already expect, and the request should never rely on a QR scan alone to establish trust. This matters because attackers commonly swap only the destination, not the visible appearance of the code.
- Limit QR use in workflows that handle credentials, payments, or account changes unless there is a strong business need.
- Register and monitor approved QR campaigns so staff can distinguish legitimate codes from lookalikes.
- Use anti-phishing controls on email and mobile endpoints, but do not assume they will catch every code embedded in an image or attachment.
Risk and Threat Considerations
QR code phishing creates risk because the scan step removes friction and often hides the true destination from the user until it is too late. The same technique can work on paper, packaging, signage, email, and chat, which expands the attack surface and makes social engineering harder to spot in time.
Failure mechanism: An attacker places a malicious QR code over a legitimate one or embeds one in a message, then directs the user to a spoofed login, payment, or support page that captures credentials or diverts funds.
Impact: The result can be account takeover, fraudulent payment, session compromise, or a broader incident if the stolen credentials unlock internal systems or downstream services.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-1 — Awareness and Training | User verification of QR sources depends on phishing awareness and safe-response habits. |
| PR.AC-1 — Identity Management, Authentication, and Access Control | QR phishing targets credential capture, so access controls must limit damage after capture. | |
| Recommendation — Train users to verify QR destinations before entering credentials or payment details. Use strong authentication and conditional access to reduce impact from stolen credentials. | ||
| CIS Controls v8 | 14.1 — Security Awareness and Skills Training | QR phishing is a social-engineering problem that requires recurring user education. |
| 9.2 — Email and Web Browser Protections | Many QR lures arrive through email or lead to malicious web pages after scanning. | |
| Recommendation — Include QR-code phishing scenarios in security awareness and phishing simulations. Filter suspicious email content and enforce browser protections for risky destinations. | ||
| OWASP Non-Human Identity Top 10 | NHI-03 — Secrets and Credential Exposure | QR phishing often aims to steal credentials or tokens after the user scans a lure. |
| NHI-05 — Rotation and Revocation | If QR phishing captures credentials, rapid revocation limits account abuse. | |
| Recommendation — Protect credential prompts and reduce exposure paths that let scanned links capture secrets. Rotate or revoke compromised credentials quickly after suspicious QR-related activity. | ||
| MITRE ATT&CK | T1566 — Phishing | QR phishing is a phishing delivery method that abuses user trust to obtain access. |
| T1189 — Drive-by Compromise | A scan can land users on malicious sites that initiate compromise without obvious warning signs. | |
| Recommendation — Detect and block phishing campaigns that use QR codes as the lure mechanism. Inspect and block malicious landing pages reached from scanned QR links. | ||
Practitioner Guidance
What to prioritise: Focus first on the highest-risk journeys, account recovery, payment approval, and any QR flow that can lead to a credential prompt. Those are the paths attackers most want because they turn a quick scan into immediate access or financial loss.
What to verify: Confirm that any QR-enabled process has a known destination, an alternative manual route, and a clear owner who can validate suspicious requests. If users cannot independently confirm the target domain or contact path, the workflow is too easy to abuse.
Practitioner takeaway: QR code phishing is best reduced by treating the scan as an invitation to verify, not as proof of legitimacy, and by designing critical user journeys so trust is established outside the code itself.
Related resources from NHI Mgmt Group
- How should security teams reduce device code phishing risk in Microsoft 365 environments?
- How should security teams reduce the risk of clipboard-based phishing leading to code execution?
- How should security teams reduce fraud risk when digital identities are reused across multiple apps and services?
- How should security teams reduce account takeover risk in high-friction digital channels?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org