QR Code Phishing Got So Bad Microsoft Teams Is Starting to Hide Them
- The Mess: Microsoft is preparing a new Teams security feature that will automatically obscure QR codes sent by people outside an organization. Users will have to deliberately reveal the image before they can view or scan the code.
- The Damage: QR-code phishing can move victims from a monitored corporate device to a personal phone, where malicious links may bypass parts of the security stack.
- The Fix: Don’t scan unexpected QR codes in Teams, especially from external users. Verify the sender first.
QR codes were supposed to make things easier.
Point your phone.
Scan the square.
Open the link.
Done.
Attackers noticed.
Now Microsoft is preparing to add friction back into the process.
A new Microsoft Teams feature currently in development will automatically obscure images containing QR codes when they are sent by people outside an organization.
The user will not see a ready-to-scan QR code immediately.
They will first need to reveal it.
That extra click is the whole point.
Microsoft is trying to make users stop for a second before their phone opens whatever destination an external sender decided to encode inside a black-and-white square. The feature is expected to begin rolling out in October 2026 across Teams desktop, Android, iOS and Mac.
The problem is known as quishing.
QR-code phishing works because the dangerous link is not written directly in the message.
It is hidden inside an image.
Traditional security tools are generally much better at inspecting visible URLs, domains and message content than convincing users to question a QR code.
And there is another advantage for attackers.
The victim often scans the code with a phone.
That means the attack can jump from a managed corporate device to a personal or less protected mobile device.
The Teams message arrives on a work laptop.
The QR code is scanned with a phone.
The phishing page opens somewhere else.
The victim may then enter Microsoft credentials, MFA codes or other information without ever clicking a suspicious link on the original corporate endpoint.
That makes QR codes a useful bridge around the security controls sitting between the user and a traditional phishing URL.
Microsoft’s move is particularly interesting because Teams has become another social-engineering surface for attackers.
Microsoft Threat Intelligence recently documented campaigns abusing Teams external collaboration to impersonate IT support or helpdesk staff and convince employees to grant remote access to their devices.
The attacker’s advantage is trust.
The message is not arriving from a random Gmail account.
It arrives inside a corporate collaboration platform.
The attacker can pretend to be IT support.
A colleague.
A vendor.
A business partner.
Then comes the QR code.
“Scan this to verify your account.”
“Scan this to approve MFA.”
“Scan this to access the secure document.”
“Scan this because your password expires today.”
The QR code itself hides the most important part of the attack.
The destination.
Users can inspect a suspicious URL.
They can sometimes spot a strange domain.
A QR code gives them a square of pixels and asks them to trust whatever appears after scanning it.
Microsoft’s planned protection does not block every QR code.
It does something more subtle.
It adds intent.
If an external user sends a QR code, Teams will obscure it by default.
The recipient must actively reveal it.
That won’t stop a determined attacker from trying.
But phishing often depends on speed.
Click now.
Scan now.
Your account expires in five minutes.
Security controls that interrupt that reflex can make a difference.
Microsoft already provides warnings and controls around potentially suspicious external chats, and Teams administrators can restrict external access. But QR codes create a different problem because the actual malicious URL can remain invisible until the victim scans the image.
And this is probably where phishing is heading.
Less obvious links.
More images.
More QR codes.
More messages inside platforms users already trust.
The phishing email is no longer the only battlefield.
Teams.
Slack.
Discord.
LinkedIn.
SMS.
Social media.
Anywhere users receive messages can become an initial-access channel.
- The Damage: A QR code can move a phishing attack away from the device and security controls that received the original message, putting credential theft one phone scan away.
The danger is not the QR code itself.
It is what happens after the scan.
A fake Microsoft login page.
A credential-harvesting site.
A malicious OAuth consent screen.
A fake MFA verification portal.
The victim may not even connect the phone activity with the Teams message anymore.
From the attacker’s perspective, that separation is useful.
The QR code did not need to exploit Teams.
It only needed Teams to deliver the image.
The phone did the rest.
- The Fix: Treat unexpected QR codes from external Teams users the same way you would treat an unexpected password-reset link.
Do not scan first and investigate later.
Check who sent the message.
Ask whether the request makes sense.
Verify it through another communication channel if necessary.
And administrators should review external Teams access policies rather than assuming every external collaboration request is legitimate.
The upcoming QR-code protection will help.
But users will still be able to reveal the image.
Microsoft can add friction.
It cannot stop someone from ignoring it.
Bugstoday Opinion
Phishing keeps getting harder to inspect.
First, attackers hid links behind shortened URLs.
Then came fake login pages.
Now they can put the entire destination inside a picture and make you open it on another device.
That is what makes quishing annoying.
The suspicious URL disappears from the message.
Your browser protections may be somewhere else.
And the victim’s phone becomes part of the attack chain.
Microsoft’s answer is refreshingly simple.
Don’t make the QR code immediately scannable.
Force the user to stop.
One click.
One extra decision.
One small moment where the victim might ask:
Why is an external stranger sending me a QR code in Teams?
Sometimes that is all security gets.
Not a perfect block.
Just one more second before someone makes a bad decision.
The phishing link disappeared into a QR code. Microsoft is now making users uncover it first.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
Microsoft Teams — Security and Phishing Protection Guidance
Microsoft Security — Impersonating IT Support Through Microsoft Teams External Collaboration
Microsoft 365 Roadmap — QR Code Protection in Microsoft Teams
Help Net Security — Microsoft Teams QR Code Phishing Protection, September 4, 2026




