Email security tools are good at catching suspicious links. So attackers stopped sending links. Instead, they send a PDF with a QR code in it: "Scan to review your updated benefits", "Your password expires today, scan to keep it", "Scan to sign the document". Security vendors have tracked a steady rise in these quishing attacks since 2023, and PDF attachments are one of the most common delivery methods.
Why QR codes in PDFs work so well for attackers
- Filters cannot easily read them. A QR code is an image. Many email scanners check links in text, not inside pictures in an attachment.
- The phone is a softer target. You scan with your personal phone, which often has fewer protections than a work laptop and may not show the full URL.
- It looks official. Company logos, a DocuSign-style layout or an HR letterhead make the PDF feel legitimate.
- It moves you off the managed device. Once on your phone, the attacker's fake login page is outside your company's security tools.
Common lures
- Multi-factor authentication "re-registration".
- Salary, bonus or benefits documents "awaiting signature".
- Voicemail or fax notifications.
- Parcel delivery problems.
- Shared documents from a colleague or vendor.
Red flags
- An unexpected PDF whose main content is a QR code. Legitimate HR or IT messages rarely ask you to scan a code from an attachment.
- Urgency: "within 24 hours", "account will be suspended".
- A generic greeting or slightly wrong company details.
- The QR code leads to a login page. Any request for your password or MFA code after scanning is a strong signal.
- The URL preview looks odd when your camera shows it: misspelled domains, URL shorteners, or unrelated domains.
Safe habits
- Do not scan QR codes from unexpected emails or attachments. Go to the service directly by typing its address or using the app.
- Preview before opening. Most phone cameras show the URL before you tap it. Read it.
- Ask through a separate channel. If HR "sent" a document, check with HR by phone or chat.
- Report it using your organisation's phishing button.
For IT and security teams
- Use email security that decodes QR codes in images and attachments.
- Train staff on quishing specifically, with realistic examples.
- Use phishing-resistant MFA such as passkeys or security keys, so a stolen password alone is not enough. See passkeys and secure document portals.
- Extend mobile device protection to phones used for work.
If you already scanned and entered details
- Change the password immediately from a trusted device, by going to the real site directly.
- Sign out of all sessions and review MFA settings.
- Tell your IT or security team straight away. Speed matters.
- Watch for unusual activity on the account.
Takeaway
A QR code in a PDF is a link you cannot see. Treat it with more suspicion than a normal link, not less. For other PDF threats, see malicious PDFs and how to stay safe and invoice fraud and business email compromise.