Scam Detective
Scam verdict · Educational pattern check
Scam Detective research desk · Updated August 2026
No — phishing

An email from IT says my password is expiring and shows a QR code to scan — is it legit?

No. “Quishing” emails impersonate your IT department or Microsoft 365 with an urgent password deadline and a QR code — the code opens a perfect copy of your company's login page on your phone, where your organization's email filters and desktop protections can't see it, and every credential typed in goes straight to the attacker. Real IT teams don't distribute sign-in links by QR code. Report the email without scanning, and if you already entered your password, change it immediately from a device and path you navigate to yourself.

Educational verdict from documented scam patterns — not a live report. For a 0–100 risk score on the exact link in your hand, run the checker.

Check a URL freeRead the full guide

From the research desk — this pattern is one of those documented in This Week's Scam Wave, in NumbersAugust 19, 2026

Why now · August 2026

Why you’re seeing this now

Because “quishing” — phishing by QR code — is now ranked among the fastest-growing email attack types security teams track, with millions of QR lures identified in the first half of 2025 alone, and August 2026's inboxes are full of them wearing an IT-department costume. The code is the trick: it moves the phish from your managed work laptop onto your personal phone, outside your organization's email filters and desktop protections, where a perfect copy of your company's login page harvests whatever you type.

The script · As it arrives — work email, then the login page it opens

The exact words they use

Quoted from documented versions of this script so you can recognize it on sight. The words are the scammer’s — the patterns inside them are what give the con away.

“IT Notification: Your Microsoft 365 password expires TODAY.”

“To avoid losing access to your mailbox, scan the QR code below with your phone camera and confirm your credentials within 24 hours.”

“Accounts not updated within this window will be SUSPENDED. — IT Helpdesk”

“[On the phone page] Sign in with your work account — Email — Password — Next.”

Script language quoted for recognition — if the message in your hand reads like this, you already have your verdict.

The checklist

Five red flags — any one is enough

The email pushes you from your work computer onto your phone — escaping the company's filters and desktop protections is the whole point of the QR code.
Sign-in is delivered by QR code at all — real IT departments link you to a known internal portal; they don't distribute credential pages as images.
A deadline measured in hours and a suspension threat — urgency is the payload.
The display name says IT or Helpdesk, but the sender's actual domain isn't your company's — or is a one-letter-off lookalike.
The page the code opens asks for your full password — and often your MFA code — on a domain that isn't your organization's.
What to do now

Your next three moves

1
Don't scan it. Report the email with your organization's report-phishing button, or forward it to your IT or security team.
2
If you already entered your password, change it immediately — from a device you trust, navigating to the sign-in page yourself — and tell IT so they can revoke active sessions.
3
Check your account's recent sign-ins and mailbox rules for anything you didn't create; attackers who get in often leave forwarding rules behind.
Instant URL Check · $2, one-time
Holding the actual message? Check the exact link, number, or sender.
Paste it into the instant check — free risk signal in 60 seconds, then the full report for $2: a 0–100 scam risk score, a plain-English verdict, the top 5 red flags found, and a 3-step what-to-do-now list. No subscription.
Run the $2 instant check
Follow-up questions

People also ask

Why a QR code instead of a normal link?

Email filters are built to inspect links; a QR code is just an image, and it moves you onto a personal phone the company doesn't manage. Both blind spots belong to the attacker, not to you.

The email looked like it came from inside my company — doesn't that make it real?

No. Display names are free text, and internal-looking mail can be spoofed or sent from a compromised colleague's account. Judge the request, not the costume: credential collection by QR code is never house style.

I scanned the code but closed the page without typing — am I OK?

Almost certainly. Scanning alone hands over nothing; the harvest happens when you type credentials. Close the page, report the email, and mention the scan to IT so they can watch for probes.

Does any legitimate IT process use QR codes?

A few do — MFA enrollment at an onboarding you initiated, for example. The difference is context: a process you started with people you can call, not an unsolicited expiring-password email with a deadline.

Related verdicts

People asking this also asked

Is that “Amazon took payment” email a scam?Almost alwaysIs decision-study.org a scam?Treat as data-harvestIs that Wells Fargo / Bank of America fraud call or text real?Verify it yourself
← Browse all 95 answers
$2, one time
No subscription, no account, nothing to cancel.
Verdict in minutes
Full report on screen and as a PDF, usually within minutes.
Honest verdicts
If it looks safe, we say so — a clear “safe” is worth $2 too.
Got a link of your own?

Sixty seconds of checking beats a four-figure mistake.

Paste any URL for a free instant preview — the full 0–100 report is $2, one-time. No subscription.

Check a URL free
Spot the scam before it spots you.
For businesses · $29, one-time
Is someone impersonating your brand?

The costume in these scams — a lookalike domain, a copied storefront, a spoofed sender — is exactly what the brand impersonation audit researches for your company: lookalike domains, typosquats, and copycat sites trading on your name, each with evidence and a risk rating, plus a ready-to-send takedown-request template.

Audit my brand — $29
Free brand scan first — you only pay for the full audit.