Skip to content
CyberSmithSECURE
Under Attack

Phishing Simulation & Awareness

QR Code Phishing Simulation

A QR code defeats email security by not being a link. It has no URL to rewrite, no domain to check against reputation, and no text to scan — and the moment the target raises their phone, the interaction leaves the managed estate entirely. Mail filtering, endpoint protection and web filtering all stop at the edge of the screen. That jump is the whole point of the technique and the reason it needs testing separately.

Methodology

  1. 01

    Scope and channel selection

    Email-delivered, physically placed, or both. Physical placement requires separate authorisation and coordination with facilities and reception.

  2. 02

    Pretext development

    Scenarios where a QR code is genuinely expected: MFA re-enrolment, parking, canteen payment, document collection, visitor wifi.

  3. 03

    Infrastructure preparation

    Landing pages built mobile-first, since every target arrives on a phone. Device and user agent captured to establish whether arrivals are managed or personal.

  4. 04

    Email campaign

    QR codes embedded as images, with and without accompanying text, to measure whether image-only messages bypass more controls.

  5. 05

    Physical placement

    Where in scope: codes placed in agreed locations — car parks, reception, kitchens, printer areas — with each location tracked separately.

  6. 06

    Device analysis

    Whether scans arrive from managed or personal devices, which determines whether any of the organisation's controls applied at all.

  7. 07

    Control assessment

    Whether mail filtering detected the QR code, whether mobile device management would have intervened, and whether web filtering applies on personal devices.

  8. 08

    Reporting and training

    Technical report and executive summary, with training targeted at the specific behaviour rather than at phishing generally.

Approach to testing

  • Device type is recorded for every scan, because a scan from an unmanaged personal phone means no organisational control applied and that is the finding.
  • Email campaigns run with and without accompanying text, since image-only messages frequently pass filters that text-based lures do not.
  • Physical placement requires facilities, reception and security to be informed, and every code is retrieved and accounted for at the end of the engagement.
  • Landing pages are mobile-first, because a desktop page that renders badly on a phone measures page design rather than susceptibility.
  • No application installation is requested. The simulation stops at the landing page and never asks a target to install anything on a personal device.

Types of assessment

Email-delivered (default)

QR codes in email, testing both user judgement and mail filtering. Easiest to run and to repeat.

Physical placement

Codes placed in the workplace. Tests a different instinct entirely, since a code on a poster carries implied authority.

Combined campaign

Both channels, so results can be compared. Physical placement usually returns markedly higher scan rates.

MFA re-enrolment scenario

The highest-risk pretext, since it is a context where a QR code is genuinely expected and the payoff is account access.

Frameworks and standards

MITRE ATT&CK T1566
Phishing technique reference; QR delivery is a sub-variant of link-based phishing.
NIST SP 800-50
Awareness programme structure for the training that follows.
OWASP MASVS
Where the campaign tests whether targets would authenticate through an unmanaged device.
ISO/IEC 27001 Annex A.6.3 / A.8.1
Awareness and user endpoint device controls.

Tools used

Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.

Gophish with QR generation

Campaign delivery, unique code per recipient and result tracking.

Custom mobile-first landing pages

Pages built for a phone, with device and user agent capture.

Unique QR codes per target

So scans can be attributed and forwarding between staff can be detected.

Printed media

Where physical placement is in scope, matched to the client's own signage style.

Checklist approach

The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.

Email controls

  • QR code detection in mail security tooling
  • Image-only message handling versus messages with text
  • Whether the destination URL is extracted and checked at all
  • External sender warnings on image-heavy messages
  • Attachment-delivered QR codes, such as PDF invoices

User behaviour

  • Scan rate by delivery channel
  • Credential submission rate after scanning
  • Report rate, and whether staff know a QR code can be reported
  • Whether targets checked the destination before proceeding
  • Forwarding of the message to colleagues

Device posture

  • Managed versus personal device for each scan
  • Whether mobile device management is enrolled and enforcing
  • Web filtering coverage on mobile devices
  • Conditional access requiring device compliance
  • Whether personal devices can reach corporate authentication at all

Physical

  • Scan rate by placement location
  • Whether placed codes were noticed, questioned or removed
  • Time from placement to first scan and to removal
  • Whether anyone reported a suspicious code
  • Visitor and contractor exposure in public areas

Authentication

  • Whether conditional access blocked the sign-in from an unmanaged device
  • MFA behaviour when authentication originates from a personal phone
  • Session persistence after authentication from an unmanaged device
  • Detection of sign-in from an unrecognised device

How findings are scored

Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.

Critical
Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
High
Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
Medium
Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
Low
Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
Informational
A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.

Scan types selected

  • Safe Checks
  • Standard / OWASP Top 10
  • Destructive
  • SANS Top 25
  • Business Logic Vulnerability Testing

Standard toolset by stage

OSINT
Datasploit, Google Dorks, Shodan
Enumeration & Scanning
Nmap, Wfuzz, Unicornscan
Domain Enumeration
Nikto, DnsRecon, Knock
Crawling & Fuzzing
Burp Suite, Acunetix, Netsparker
Vulnerability Analysis
OpenSSL, sqlmap, CVE-Details
Exploitation
Metasploit, Netcat, Exploit-DB

How CSS tests

A unified swarm of agents, for blind spot detection

AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.

  • Mail control testing across permutations — image-only, image with text, PDF-embedded, varying code sizes and error correction levels — is combinatorial and identifies precisely which variant bypasses filtering.

  • Device and user agent analysis across every scan produces the managed-versus-personal split, which is the finding that matters and is lost if scans are only counted.

  • Correlating scans against the client's conditional access and sign-in logs establishes whether authentication from those devices would have been blocked.

  • Unique code tracking across recipients detects forwarding, which spreads exposure well beyond the tested population.

Every campaign is reviewed by a human and approved by the client before any code is sent or placed. Agents assist with variant generation and result analysis; nothing is delivered to staff without explicit sign-off.

Why this differs

What CSS does that most vendors do not

Every one of these is checkable. Ask any vendor for the same and compare the answers.

Device posture is the finding

Most vendors report a scan rate. The number that matters is how many scans came from unmanaged personal phones, because that is where the organisation's controls stopped applying entirely.

Filter bypass mapped by variant

Testing image-only, text-accompanied and PDF-embedded codes identifies which specific variant defeats the client's mail security, which is actionable in a way a single scan rate is not.

Physical and digital compared

Running both channels shows where the organisation is weaker. Physical placement usually returns far higher scan rates and is almost never tested.

Both reports, always

Technical report on controls and device posture, executive summary on behaviour and exposure.

Reporting

Two documents, two audiences

Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.

Technical assessment report

For the engineers who will fix it

  • Disclaimer, and Limitations on Disclosure and Use
  • Risk Level & Description — the five levels above, scored on CVSS 3.1
  • Scan Type — which of the five assessment types were selected
  • Assessment Scope — the control areas covered
  • Assessment Date — the exact testing window
  • Objective of the Assessment — objectives listed against completion status
  • Tools Utilization — manual and automated tooling by stage
  • Summary of the Assessment
  • Overall Recommendations, split into Must Have and Should Have
  • Vulnerability Overall Classifications as per Organization
  • Security Issues Highlighted
  • The Key Findings — each with evidence and detailed recommendation
  • Summary of Findings & Conclusion

For this assessment specifically

  • Scope, channels, pretexts, placement locations and the campaign window
  • Scan, submission and report rates by channel and by location
  • Device analysis: managed versus personal, operating system, browser
  • Mail control findings by QR delivery variant
  • Conditional access and sign-in analysis for authentication attempts
  • Physical placement observations including time to removal
  • Recommendations split between technical control and awareness

Executive summary

For the people who will fund the fix

  • Objectives, each against a completion status
  • Overall Finding of the Assessment — total threats identified, broken down by component and severity
  • Summary of the Assessment
  • Artefacts of the Assessment — the key findings as a numbered register with severity
  • Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
  • Overall Recommendation, including a Business Enabling Recommendation sequence
  • Must Have and Should Have actions

For this assessment specifically

  • How many staff scanned, and how many did so on a device the organisation does not control
  • Whether mail security detected the codes at all
  • Whether authentication from an unmanaged phone would have been blocked
  • The three changes that most reduce exposure
  • One page

Case studies

What this finds in practice

Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.

A professional services firm of around 600 staff, combined email and physical campaign.

Finding
Email scan rate was 9%. Codes placed on printed notices in kitchen areas returned 34%, and one remained in place for eleven days before anyone removed it. Of all scans, 81% came from personal phones with no device management.
Recommendation
Add conditional access requiring device compliance for corporate authentication, brief facilities on unauthorised signage, and run awareness specifically on physical QR codes.
Outcome
Conditional access deployed within six weeks, which closed the authentication path regardless of scan rate. Facilities now remove unattributed notices as routine.

A financial services firm with a well-regarded mail security platform.

Finding
QR codes embedded directly in the message body were detected and quarantined reliably. The same code inside a PDF attachment styled as an invoice passed through untouched, and returned a 17% scan rate among finance staff.
Recommendation
Enable attachment content inspection for QR codes, and treat PDF-embedded codes as a distinct detection requirement with the vendor.
Outcome
The vendor enabled attachment QR inspection on the tenant within a month. The finding was raised with the vendor as a product gap and reportedly informed a wider roadmap change.

A healthcare provider, MFA re-enrolment pretext delivered by email.

Finding
A message claiming MFA re-enrolment was required before a deadline returned a 22% scan rate and 14% credential submission. Every submission came from a personal phone. Conditional access permitted authentication from unmanaged devices for the affected user group.
Recommendation
Require compliant devices for authentication, move MFA re-enrolment to an in-person or verified process, and never legitimately ask staff to re-enrol via a QR code in email — because doing so trains them to accept the attack.
Outcome
Device compliance enforced for clinical staff over two months. The organisation also stopped a planned legitimate QR-based enrolment campaign that would have undermined the training.

Next

Scope this assessment

Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.