Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice with a QR code leading, via a .ru-hosted fake "security scan" page behind Cloudflare, to a freshly registered Microsoft 365 credential-harvesting login page; Hornetsecurity's write-up documents this technical chain but does not confirm the employee scanned the code or that any downstream step actually occurred.
Reviewed by the Social Engineering Examples team.
In a post published 19 May 2023, email-security vendor Hornetsecurity disclosed that it had detected and analyzed a QR-code phishing ("QRishing") attack targeting a single employee at an unnamed US-based managed service provider; the exact date of the underlying attack is not disclosed. The phishing email was disguised as a support-ticket notification, spoofed to display the targeted MSP's own name as sender, and used Microsoft and Microsoft Authenticator branding to claim the recipient's multi-factor authentication had been deactivated and needed to be "reactivated" by scanning an embedded, Microsoft-logo-branded QR code with a smartphone. Hornetsecurity noted the email had bypassed Microsoft 365's native security filtering. Hornetsecurity's write-up traces where the QR code leads rather than confirming what the employee did: scanning and tapping through would lead to a .ru-domain page staging a fake antivirus/security-scan animation (CAPTCHA-style verification theater) that resolves to a green "Success" checkmark, hosted behind Cloudflare so the attackers could exploit Cloudflare's antibot protections to hinder automated security analysis, and from there to a spoofed, recently registered Microsoft 365 login page designed to harvest credentials. Hornetsecurity's report frames the credential theft as the page's "likely" purpose rather than a confirmed compromise, and does not state whether the employee scanned the code, reached the interstitial page, or reached the final phishing page; it discloses no financial loss and no named threat actor.
The write-up describes a four-stage attack chain engineered to evade email-security filters and antibot/analysis tools; Hornetsecurity does not confirm the targeted employee completed any step beyond receiving the email, so stages (2)-(4) below describe where the chain leads rather than confirmed victim actions: (1) Lure email: a spoofed "support ticket" style message with the display name forged to show the targeted MSP's own name, carrying Microsoft and Microsoft Authenticator logos, telling the recipient "Multi-Factor Authentication (MFA) is no longer active on your organization account. To help keep your account safe and secure. Please reactivate your authentication by following the instructions on your device," with a call-to-action to scan an embedded QR code (also Microsoft-logo-branded) with a smartphone rather than click a text link. (2) QR code as evasion layer: because the phishing link lived only inside a scannable image, filters relying on URL/text analysis rather than computer vision or QR decoding would not flag it, and scanning with a smartphone camera, as the email instructed, would move the click chain outside the monitored corporate email/endpoint environment; the source does not confirm whether the code was actually scanned or whether the device would have been personally owned or corporate-issued. (3) Fake "security scan" interstitial: the QR code, if scanned and tapped through, led to a page on a .ru top-level-domain that simulated a security/antivirus scan animation (CAPTCHA-style verification theater) and then refreshed to show a green checkmark and the word "Success," a design meant to manufacture false reassurance before the real payload page loaded; this interstitial reused attributes/behaviors Hornetsecurity had seen in a separate campaign it had previously reported, and it was hosted behind Cloudflare specifically so the attackers could piggyback on Cloudflare's antibot protections to frustrate automated security-vendor analysis. (4) Credential harvester: the chain's final destination was a spoofed Microsoft 365 login page on a domain Hornetsecurity verified had been very recently registered, designed to capture an M365 username and password; Hornetsecurity describes credential harvesting only as the page's "likely" purpose, not a confirmed outcome, and does not state whether the employee ever reached or interacted with this page.
Lure: an email disguised as a support-ticket / IT-helpdesk notice, with the sender display name spoofed to the targeted MSP's own name, and Microsoft plus Microsoft Authenticator logos embedded to look like an official Microsoft security notice. The body read, in substance: "Multi-Factor Authentication (MFA) is no longer active on your organization account. To help keep your account safe and secure. Please reactivate your authentication by following the instructions on your device," an urgency/loss-of-access trigger paired with a QR code (itself carrying a Microsoft logo) as the only call-to-action, rather than a clickable hyperlink. Tells that would have been visible to a trained eye: MFA "deactivation" notices are not something Microsoft delivers by asking a user to scan a QR code; legitimate Microsoft security/authenticator prompts happen in-app or via admin center, never via a support-ticket-styled email urging a phone-camera scan; the instruction to leave the desktop email client and use a smartphone to "resolve" an urgent account-security issue is itself atypical; and the subsequent "security scan" animation culminating in a green "Success" badge is a fabricated trust signal with no relationship to any real security product.
Hornetsecurity's own filtering/detection identified and documented the campaign after it slipped past Microsoft 365's native email-security defenses; the vendor does not report whether the single targeted employee actually scanned the code or entered credentials into the final M365 phishing page, and its write-up explicitly stops short of confirming an account compromise, describing the credential capture only as the "likely" purpose of the fake login form. No breach notification, ransom, data-exfiltration claim, or follow-on incident (e.g., a reported downstream MSP client compromise) has been publicly tied to this specific case. The lasting outcome is the vendor's published technical dissection, used as an awareness/training case study rather than a confirmed-breach disclosure.
The case is a compact, real-world demonstration of why QR-code phishing defeats conventional email-security controls: the malicious link exists only as an image, so filters that scan URLs/text (rather than using computer vision or QR decoding) miss it outright, and the intended click/scan step happens on a smartphone camera, stepping outside the monitored corporate email and endpoint perimeter entirely if it occurs. It also shows a layered anti-analysis design that security teams increasingly encounter: a throwaway .ru redirect, a fabricated "security scan passed" trust signal to lower victim suspicion, and a Cloudflare-fronted interstitial page used defensively by the attackers themselves to slow down vendor/analyst investigation before the real Microsoft 365 credential-harvesting page is ever reached. Because the victim was an MSP, a successful compromise here would carry outsized downstream risk: MSP credentials are a well-known pivot point into every downstream client tenant the MSP manages, making this a supply-chain-relevant target even though only one employee and one organization were directly hit, and even though Hornetsecurity never confirms the compromise progressed past the initial email.
Hornetsecurity's recommendations: (1) security-awareness training that specifically covers QR-code risks, teaching users not to scan QR codes from unknown/unsolicited sources or tap resulting links without verifying legitimacy; (2) layered third-party email security on top of Microsoft 365's native filtering, since the malicious email bypassed Microsoft's native detection; (3) email security tooling that uses Computer Vision to detect phishing links embedded inside QR-code images (image-based threats that text/URL-only filters miss); (4) protection extended from mailbox to browser and to mobile devices, since QR codes are scanned on smartphones outside the corporate email/endpoint perimeter where traditional controls apply; (5) awareness that "security-scan" or "CAPTCHA-style" interstitial pages showing a green success indicator are a manipulation technique, not proof of safety.
LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…