QR-code phishing is email with extra steps
A poster in the lobby or a PDF in the inbox. The destination is still a credential farm.
ITSIGN Administrator · June 4, 2025 · 2 min read
Staff will scan a code they would not click. Train that a QR code is a link. Preview it. Do not sign in because a lobby poster said the Wi-Fi changed.
Include one QR scenario in security awareness. It takes five minutes and sticks.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
