QR codes have become part of everyday business.
You scan one to view a restaurant menu, pay for parking in downtown Albuquerque, join the guest Wi-Fi at a coffee shop, or open a shared document from a client.
Most of the time, you don’t think twice about it.
That’s exactly what makes QR codes so effective. They’ve become part of everyday life, so most people automatically trust them.
Unfortunately, cybercriminals know that.
As employees have gotten better at spotting suspicious links, attackers have simply found a new way to deliver them.
Instead of sending suspicious-looking links in emails, they’re hiding those links inside QR codes. Because the code is just an image, it can often slip past the email security tools that would normally detect a malicious website.
This type of attack has become so common that it now has its own name: quishing (QR code phishing).
The dangerous part is that many people scan these codes with their phones. While your work computer is likely protected by several layers of security, your personal phone often isn’t. That means a simple scan can move you outside many of the protections your business relies on every day.
Let’s look at how these scams work, why they’re becoming more common, and what Albuquerque businesses can do to avoid becoming the next victim.
What Is a QR Code Scam?
A QR code scam is simply a phishing attack that uses a QR code instead of a clickable web link.
Instead of including a website address in an email, the attacker hides it inside the QR code.
When you scan the code with your phone, you’re taken to a website that looks legitimate.
It might appear to be:
- A Microsoft 365 login page
- Your bank’s website
- A payment portal
- A document-sharing service
- A company login page
Everything may look normal.
But the page was created by criminals to steal your username, password, credit card information, or other sensitive data.
Why QR Code Scams Often Get Past Security
These attacks are successful for two simple reasons.
1. The malicious link is hidden inside an image.
Most email security tools inspect the text inside a message. They look for suspicious links, dangerous domains, and known phishing websites.
A QR code, however, is just a picture.
Many email filters can’t easily inspect the website hidden inside that image, allowing the message to arrive in your inbox looking completely harmless.
2. Scanning a code moves you to your phone.
This is where many businesses lose an important layer of protection.
Your work computer may have:
- Web filtering
- DNS controls that block known bad sites
- Endpoint protection
- Browser security controls
Your personal phone may not have the same protections. The moment you scan the QR code, you’ve moved away from the security controls your business relies on every day.
Attackers know this, which is why QR code phishing has become so popular.
QR Code Scams Are Growing Fast
QR code phishing is growing rapidly.
Microsoft reported detecting approximately 8.3 billion email-based phishing attempts during the first quarter of 2026.
Within that same period, QR code phishing attacks increased by 146%, rising from about 7.6 million attacks in January to 18.7 million attacks in March.
Microsoft also found most of these attacks arrived as PDF attachments. The QR code sits inside a PDF attached to an email, making everything look perfectly normal until someone scans it.
The good news is that most QR code scams follow a handful of common patterns. Once you know what to look for, they’re generally much easier to recognize.
5 Common QR Code Scams to Watch For
1. A “security” email.
An email looks like it’s from Microsoft, your IT provider, or another trusted company.
It says you need to scan a QR code to:
- Keep your account active
- Reset your password
- Re-enroll in multi-factor authentication
- Verify your identity
But the QR code leads to a fake login page designed to steal your credentials.
2. A shared document
You receive an email saying a coworker, vendor, or client shared a document with you.
Instead of clicking a link, you’re asked to scan a QR code.
After scanning, you’re prompted to log into Microsoft 365 or another cloud service before viewing the file.
Unfortunately, you’re giving your password directly to the attacker.
3. Fake invoices
An invoice includes a QR code with a message asking you to scan the code to pay faster.
But the payment doesn’t go to your vendor. It goes straight to the criminal.
4. Delivery notifications
You receive a text message or email saying you missed a package delivery. You’re instructed to scan a QR code to reschedule or pay a small delivery fee.
Instead of helping you reschedule a delivery, the page collects your payment information and sends it straight to the attacker.
5. Fake QR codes in public places
Not every QR code scam begins online.
Attackers have been known to place fake QR code stickers over legitimate ones on parking meters, event posters, and payment kiosks.
Whether you’re paying to park downtown, in Old Town, or anywhere else around Albuquerque, take a quick look before scanning the QR code.
A sticker placed over the original code could send you to a fake payment site instead of the city’s official system.
How Albuquerque Businesses Can Protect Themselves
The good news is that avoiding QR code scams usually comes down to building a few simple habits.
1. Treat QR codes like suspicious links.
If someone emails you a QR code asking you to log in, verify an account, or make a payment, pause before scanning.
Treat it with the same caution you would give a suspicious email link.
2. Look at the website address before opening it.
When you scan a QR code, your phone shows the website link before it opens.
Take a moment to read it.
If the web address doesn’t exactly match the company you expected, close it.
3. Go directly to the website instead.
If Microsoft says your account needs attention, don’t scan the QR code.
Instead, open your browser and go directly to Microsoft’s website using a bookmark or by typing the address yourself.
The same applies to your bank, vendors, or other online services.
4. Don’t let urgency make your decision.
Many phishing emails create artificial deadlines.
They may claim:
- Your account will be suspended today
- Your payment is overdue
- Your password expires immediately
That sense of urgency is often the biggest warning sign.
5. Use stronger multi-factor authentication.
Modern phishing-resistant authentication methods, such as passkeys, hardware security keys, or number-matching authentication, make stolen passwords much less useful to attackers.
Even if someone accidentally enters their password, these additional protections make the password much harder for an attacker to use.
6. Check public QR codes carefully.
If you’re using a parking meter, payment kiosk, or public terminal, make sure the QR code doesn’t appear to be a sticker placed over another code.
If something looks unusual, avoid scanning it.
7. Train your employees.
Most employees have never heard of quishing.
A short security awareness reminder with a real example can help employees recognize these attacks before they become a problem.
What to Do If Someone Scans a Fake QR Code
If someone on your team scans a malicious QR code and enters information, acting quickly can greatly reduce the damage.
Take these steps immediately:
- Change the password for the affected account.
- Change the password anywhere else that same password was used.
- Verify that multi-factor authentication is enabled for the account.
- Notify your IT provider so they can review login activity for suspicious access.
- If payment or banking information was entered, contact your bank or credit card provider immediately.
The faster you respond, the less opportunity attackers have to misuse the information they captured.
Don’t Let One Scan Become a Security Incident
QR codes make everyday tasks faster, which is exactly why attackers are using them more often.
For Albuquerque businesses, the biggest risk isn’t the technology itself. It’s trusting a QR code simply because it looks familiar.
Taking a few extra seconds to verify where a QR code is taking you can prevent stolen passwords, fraudulent payments, and a cybersecurity incident that could disrupt your entire business.
Not sure whether your employees could spot today’s phishing attacks? A Discovery Call is a great place to start. We’ll help you identify the biggest security risks facing your business and recommend practical ways to reduce them.
👉 Schedule your FREE Discovery Call below or give us a call at 505-821-6070
Book My 17-Minute CallBecause sometimes the most dangerous link isn’t the one you click, it’s the one you scan.





