QR codes are everywhere now — on restaurant tables in downtown Johnson City, on parking meters in Kingsport, on the back of an invoice, in the footer of a perfectly normal-looking email. We've all been trained to point our phone at the little square and trust whatever pops up. Attackers noticed. That trust is exactly what they're exploiting, and the technique even has a name: quishing, or QR-code phishing.

This isn't a fringe threat anymore. Microsoft's threat intelligence team reported that QR-code attacks became the fastest-growing email attack technique in early 2026, with detected volumes climbing from roughly 7.6 million in January to 18.7 million in March. The reason it's exploding is simple and a little unsettling: a QR code lets an attacker walk right around the email security tools most Tri-Cities businesses are paying for.

What Quishing Actually Is

Phishing, the old-fashioned way, puts a malicious link in an email and hopes you click it. Your email filter is built to catch exactly that — it reads the text, follows the links, and blocks anything that smells wrong. Quishing skips the link entirely. Instead, the malicious web address is hidden inside the pixels of a QR-code image.

To your email gateway, that image is just a picture. There's no clickable URL to scan, rewrite, or sandbox. So the message sails through to the inbox looking clean. Then the human does the dangerous part: they pull out a phone, scan the code, and land on a fake login page — on a device that's usually nowhere near the company's protections.

Why It Slips Past Your Defenses

Quishing works so well because it breaks two assumptions your security stack is built on:

Surveys consistently find that most people — around three out of four — scan a QR code without ever checking where it actually leads. A printed square gives away none of the warning signs people are trained to look for in a suspicious link. There's no hover-to-preview on a sticker.

How the Scam Shows Up in Real Life

Quishing isn't one trick — it's a family of them. Here are the versions Tri-Cities business owners and their employees are most likely to run into:

The Fake MFA-Reset Email

This is the one that should worry employers most. An employee gets an email that looks like it's from Microsoft 365 or the IT department: "Your multi-factor authentication has expired. Scan this QR code to re-enroll your device." The code leads to a pixel-perfect fake Microsoft login. The employee enters their password and approves the MFA prompt — and the attacker, sitting in the middle, captures the live session token. Because the victim completed a real-looking login, no "MFA failed" alert ever fires. The criminal now has the keys to your email, your files, and your cloud accounts.

The Rigged Invoice or Payment Request

A vendor "invoice" arrives as a PDF with a QR code labeled "Scan to pay" or "Scan to view secure document." The code routes to a credential-harvesting page or kicks off a fraudulent payment. For a busy accounts-payable clerk at a manufacturer or construction firm, scanning a payment code feels like a normal Tuesday — which is exactly the problem.

Fake Parking Meters and Public Stickers

This one has hit physical streets. Criminals print a sticker with a malicious QR code and slap it right over the legitimate one on a parking meter, EV charger, or gas pump. The fake site mimics the real parking-payment portal — sometimes a single letter off, like "PoyByPhone" instead of "PayByPhone" — and pockets the driver's card details. Cities in multiple states have peeled hundreds of these decals off public meters. If your team parks downtown for client meetings, this is a personal-finance landmine too.

Table Tents, Flyers, and Unexpected Packages

Scammers leave doctored QR codes on restaurant table-tent menus, event flyers, and posters. The FBI's Internet Crime Complaint Center even issued a public warning in 2025 about unsolicited packages that arrive containing a QR code — scan it, and you're handing over personal data or installing malware. The package with no return address isn't a mystery gift. It's bait.

Would Your Team Scan the Code?

Most employees have never been tested against a QR-based lure. Blue Ridge IT's BlueHook phishing simulations include real-world quishing scenarios that show you exactly who's at risk — before an attacker finds out for you.

Test Your Team

What a Single Successful Scan Can Cost

It's tempting to dismiss this as a consumer scam, but the business impact is real and growing. State-sponsored groups have used embedded QR codes in targeted spear-phishing against U.S. organizations, and run-of-the-mill criminals use the same playbook against small and mid-sized companies every day.

When a quishing attack succeeds against an employee, the fallout can include:

How to Defend Your Business Against Quishing

The good news: quishing is beatable with a mix of smarter habits, better technology, and trained people. Here's where to focus.

Treat Every QR Code Like an Unknown Link

The core rule is simple — a QR code is a link you can't see, so treat it with the same suspicion. Don't scan codes that arrive by email, especially ones urging you to "verify," "re-enroll," or "pay." When you do scan a physical code, check the preview URL before tapping through, and look for tampering: a sticker placed over the original is a giant red flag.

Verify Before You Act

If an email or document asks you to scan a code to reset MFA, view an invoice, or make a payment, confirm it through a separate channel. Call IT directly. Log in to Microsoft 365 by typing the address yourself rather than scanning anything. Reach the vendor at a phone number you already have. Urgency is the scammer's favorite tool — slowing down defeats most of these attacks.

Move to Phishing-Resistant MFA

Classic MFA — text-message codes and authenticator-app prompts — no longer stops attackers who steal your session token mid-login. Phishing-resistant MFA, like FIDO2 hardware security keys or passkeys, does, because it cryptographically ties the login to the real website's domain. A fake page simply can't complete the handshake. If your business handles sensitive data, this upgrade should be near the top of your list.

Train People for the Threat They'll Actually Face

Security awareness training that only covers "watch for bad grammar" is a decade out of date. Employees need to see what a quishing email looks like and practice the right reflex. Ongoing, realistic simulations build that muscle memory far better than an annual slideshow. Pair training with strong endpoint and email security across your cybersecurity stack so that a single human slip doesn't become a company-wide breach.

The Bottom Line for Tri-Cities Businesses

QR codes aren't going away — they're convenient, and customers expect them. The point isn't to fear the technology; it's to respect that attackers have turned a tool we all trust into a doorway into your network. The businesses that adapt — verifying before scanning, deploying phishing-resistant MFA, and training their people on the threats that exist today — will shrug off attacks that quietly drain their less-prepared competitors.

At Blue Ridge IT Solutions, we help Kingsport, Johnson City, and Bristol businesses close exactly these gaps: layered email and endpoint defense, modern MFA rollouts, and human-risk training that reflects how criminals really operate in 2026.

Don't let a two-second scan undo everything. Contact Blue Ridge IT Solutions today for a security assessment built for how attacks actually work now.