QR Code Phishing Jumped 146% in One Quarter. Here's How to Protect Your Houston Business
QR codes are now a standard part of how Houston businesses operate. They appear on vendor invoices, parking terminals in The Woodlands and downtown Houston, office Wi-Fi instructions, and PDF documents sent by email. Your staff scans them dozens of times a week without a second thought. Attackers have taken notice. They have started hiding malicious links inside QR codes specifically because the technique bypasses the email security filters most businesses rely on—and because scanning a QR code typically happens on a personal phone that sits well outside your company’s security perimeter.
This attack type has a name: quishing, short for QR code phishing. In the first quarter of 2026 alone, Microsoft detected a 146% rise in QR code phishing attempts—from 7.6 million attacks in January to 18.7 million in March. In that same period, Microsoft blocked more than 8.3 billion phishing threats overall, with QR codes embedded in PDFs growing from 65% to 70% of QR-based attacks. We covered an earlier wave of this threat in our post on the unseen dangers of QR codes—the numbers have only risen since then.
Why QR Code Attacks Get Past Your Security
Standard email security filters scan the text of incoming messages for known malicious links. A QR code encodes its web address inside an image. The link is invisible to the filter—it reads a picture, not a URL—so the message passes through cleanly. Many legacy filtering tools have no mechanism to decode what a QR code points to before it reaches the inbox.
The second reason these attacks succeed is the device switch. When a staff member scans a code, they typically do so on a personal smartphone. That phone almost certainly lacks the web filtering, DNS controls, and endpoint protection that the company laptop has. From the attacker’s perspective, one scan moves the target from a protected environment onto a largely unprotected one. That gap is exactly what managed cybersecurity services in Houston are designed to close.
What QR Code Scams Look Like in Practice
Four patterns appear most frequently across Houston’s business community.
1. The MFA Re-Enrollment Message
An email arrives claiming to be from your IT team or Microsoft, warning that you must scan the attached code to re-verify your multi-factor authentication or keep your account active. The code leads to a convincing fake Microsoft login page that captures credentials in real time.
2. The Shared Document Email
A message says a colleague or vendor has shared a document and asks you to scan to view it. The landing page prompts you to sign in first—and the sign-in page collects your username and password for the attacker.
3. The Fake Invoice PDF
A PDF invoice includes a QR code presented as a faster payment option. The code routes payment to the attacker’s account rather than the legitimate vendor. Houston-area energy companies and construction firms that handle frequent wire transfers are repeat targets for this variant.
4. The Physical Sticker on a Payment Terminal
Attackers print QR code stickers and place them over legitimate codes on parking terminals and payment kiosks. The user believes they are paying for parking or accessing a service. They are providing payment details directly to the attacker. Several reports from the Houston metro area and across the Texas Gulf Coast have documented this method on public infrastructure.
Why These Attacks Keep Getting Past Business Security Systems
Even well-configured businesses are vulnerable because QR code phishing operates at the intersection of email security, personal device use, and social trust—three areas that managed cybersecurity programs historically treat separately. The attacker does not need to break through a firewall. They need a staff member to scan a code on their phone, which is almost never governed by corporate security controls.
This is why security awareness training is not a supplementary measure for QR code threats—it is the primary one. Your staff’s ability to recognize and pause before scanning an unsolicited QR code is the control that matters most when the technical filters have already let the message through.
What to Do If Someone on Your Team Already Scanned One
If a staff member scanned a suspicious QR code and entered credentials or payment details on the page that opened, the response is time-sensitive. Change the password for that account immediately, along with any other account using the same password. Confirm multi-factor authentication is enabled and check for recent logins from unfamiliar locations. Notify your IT provider so they can review sign-in logs for unauthorized access. If card or banking details were entered, call the bank within the hour.
Acting in the first hour limits what the attacker can do with what they captured.
What Elevate Technology Delivers for Houston Businesses
Elevate Technology provides managed cybersecurity services and managed security awareness training for businesses across Houston, Sugar Land, and The Woodlands. When it comes to QR code phishing and similar social-engineering attacks, staff training is the control that matters most—because no email filter catches every threat before it arrives, and the last line of defense is always the person holding the phone. Our cybersecurity awareness training for Texas businesses runs on a monthly cadence, uses real-world simulations including QR code scenarios, and builds the habits that stop threats the technology missed. For businesses using Proofpoint, we also configure image-scanning rules that decode QR codes within emails and flag suspicious destinations before they reach the inbox.
Are all QR codes in emails dangerous?
Not inherently, but they deserve the same scrutiny you would give an unexpected link. A code from a restaurant, a printed vendor document, or a legitimate event confirmation is generally safe. A code that arrives by email asking you to log in, update your MFA, or pay a bill is worth verifying by going directly to the known website rather than scanning. The risk is not the code itself—it is where the code points, and that destination is invisible until you scan it.
Can our existing email security stop QR code phishing attacks?
Many standard email security tools cannot, because they analyze text and URLs rather than images containing encoded QR codes. Enterprise-grade platforms—including Proofpoint, which Elevate Technology deploys for clients—now include image-scanning capabilities that decode QR codes within emails and check the destination against threat intelligence. No filter is absolute, which is why cybersecurity awareness training for Texas businesses remains the essential complement to any technical control.
→ Help your Houston team recognize and stop phishing attacks before they land. Visit our Security Awareness Training page.