LevelBlue's MDR SOC documented a real client quishing case in which a PDF impersonating a Microsoft MFA-setup notice, hiding a malicious QR code, drove multiple employees to a fake Microsoft login page that harvested several employees' credentials before the attack was fully remediated with no confirmed data loss.
Reviewed by the Social Engineering Examples team.
In a case documented by LevelBlue (formerly AT&T Cybersecurity) and published October 10, 2023, the LevelBlue Managed Detection and Response (MTDR) security operations center detailed a real client incident involving "quishing" (QR-code phishing). Multiple employees at an unnamed customer organization received a phishing email with a PDF attachment containing a QR code and an urgent message impersonating a Microsoft/Windows multi-factor-authentication (MFA) setup requirement. Employees who scanned the QR code with their phones were redirected to a fake Microsoft login page that harvested their usernames and passwords; several users' credentials were compromised. The customer flagged the email as suspicious and engaged LevelBlue analysts, who decoded the QR code's destination (srvc1[.]info/mcrsft2fasetup/index.html), analyzed the credential-harvesting page's network behavior using a decoy account and Chrome DevTools, and researched the attacker's infrastructure via OSINT. LevelBlue then guided the customer through remediation: closing active sessions before resetting credentials, purging the phishing email from inboxes, blocking the malicious domains, and confirming no data had been exfiltrated. No exact employee count, dollar figure, or victim organization name/sector was disclosed in the public write-up.
Attackers sent a phishing email to multiple employees at the customer organization, styled as an urgent notification that Windows/Microsoft multi-factor authentication (MFA) needed to be set up on the recipient's account. Rather than a clickable link, the email carried a PDF attachment instructing the recipient to scan an embedded QR code to complete MFA enrollment. Because the malicious payload was an image (the QR code) rather than a URL or macro, it evaded traditional email-gateway link/attachment scanning. Employees who scanned the code with their phones (deliberately chosen by the attacker because mobile devices typically have weaker security controls than corporate-network endpoints) were redirected to a convincing fake Microsoft sign-in page and entered their real credentials, which were captured by the threat actor. LevelBlue MDR SOC analysts, engaged after the customer flagged the email as suspicious, decoded the QR code to the URL srvc1[.]info/mcrsft2fasetup/index.html, then used a decoy email address and Google Chrome's Inspector/DevTools network panel to observe what the credential-harvesting page did after "Sign In" was clicked, finding a single outbound call to logo.clearbit[.]com/email.com (an innocuous marketing-intelligence lookup, returning HTTP 404) rather than further malicious exfiltration traffic. OSINT on srvc1[.]info showed it was a recently registered, ownership-obscured domain with no other footprint, and the customer confirmed neither srvc1[.]info nor Clearbit were part of its normal business tooling.
Lure: an email posing as an official notice that the recipient's Microsoft/Windows multi-factor authentication needed to be set up, with a PDF attachment containing a QR code to "complete enrollment" and urgency language pressuring quick action. Tell (in hindsight): legitimate MFA enrollment is initiated by internal IT/identity systems, not via an unsolicited PDF with a QR code; the destination domain (srvc1[.]info/mcrsft2fasetup) had no relation to microsoft.com or the organization's actual identity provider; and the attacker's explicit bet, that victims would scan with a phone precisely to bypass corporate network security, was itself an exploitable "tell" once flagged (why would MFA setup require leaving the managed device?).
Several employees' credentials were compromised, but LevelBlue's investigation found no evidence of successful data exfiltration and no indicators the phishing email had spread further inside the organization. Working with LevelBlue MDR SOC analysts, the customer closed all active sessions before resetting user credentials (to prevent the attacker retaining access through the reset), purged the phishing email from all inboxes, and blocked the external domains tied to the QR code (srvc1[.]info and the Clearbit lookup domain). The incident was declared fully remediated and the customer used it as a lessons-learned exercise to retrain staff on phishing and malicious-QR-code risks. No public confirmation of the victim organization's identity, sector, employee count, or any financial/breach-notification impact was released.
This is one of the earliest widely cited vendor-documented cases showing quishing succeed specifically against an MFA-related lure: attackers exploiting the fact that MFA enrollment/setup notices are routine, expected, and rarely questioned by employees, making them an effective disguise for credential theft. It also demonstrates a specific and repeatable evasion technique: encoding the malicious link as a QR code inside a PDF (rather than a clickable hyperlink) to slide past email/URL-scanning security controls, then explicitly steering victims to scan with personal mobile devices, which typically sit outside corporate EDR, DNS filtering, and conditional-access policies, to complete the compromise on a weaker-security surface. The case is frequently cited in security-awareness training precisely because it operationalizes both the "QR bypasses email filters" and "mobile device bypasses corporate controls" tactics in one real, remediated incident with a clear SOC investigation narrative (QR decode, DevTools network tracing, OSINT domain analysis) that defenders can learn from.
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset,…