September 7, 2026
Microsoft Teams Is Hiding QR Codes to Stop Phishing Attacks
A vendor you’ve never met sends a “new invoice portal” QR code in a Teams chat. It looks routine — vendors do this constantly. Someone on…

By Xpert4Cyber
1 min read
A vendor you've never met sends a "new invoice portal" QR code in a Teams chat. It looks routine — vendors do this constantly. Someone on the finance team scans it on their phone without a second thought. Thirty seconds later, they've handed over a Microsoft 365 session token to an attacker who never wrote a single line of malware. They just asked, politely, to be scanned.
This is the exact scenario Microsoft is now trying to interrupt.
Starting October 2026, Microsoft Teams will automatically blur QR codes sent by external users — guests, vendors, contractors, anyone outside your tenant — until the recipient manually reveals them. It's a small UI change, but the security rationale behind it is significant.
QR codes have become one of the fastest-growing phishing vectors in the enterprise, and for a simple reason: the destination URL is invisible until scanned. A malicious hyperlink can be inspected, hovered over, checked against a blocklist. A QR code embedded in an image skips all of that — most secure email gateways and chat-based URL scanners were built to inspect text, not pixels.
That blind spot is exactly what attackers have been exploiting, and Teams becoming a delivery channel for the same tactic isn't a surprise. It's the logical next step once email defenses started catching up.
Microsoft's fix, listed under Roadmap ID 570439, doesn't block QR codes outright. It forces a deliberate "do I actually want to see this?" decision point before the image renders — friction, not prohibition.
But here's what security teams need to understand: revealing a QR code confirms curiosity, not safety. This feature alone won't stop quishing. It needs to sit alongside tightened external access policies, phishing-resistant MFA, and updated awareness training that finally treats chat-based QR lures as seriously as email-based ones.
Full breakdown of the rollout timeline, a realistic attack scenario, and a detection-and-prevention checklist for SOC teams:
https://www.xpert4cyber.com/2026/09/microsoft-teams-qr-code-protection.html