Phishing Simulation & Awareness
QR Code Phishing Simulation
A QR code defeats email security by not being a link. It has no URL to rewrite, no domain to check against reputation, and no text to scan — and the moment the target raises their phone, the interaction leaves the managed estate entirely. Mail filtering, endpoint protection and web filtering all stop at the edge of the screen. That jump is the whole point of the technique and the reason it needs testing separately.
Methodology
- 01
Scope and channel selection
Email-delivered, physically placed, or both. Physical placement requires separate authorisation and coordination with facilities and reception.
- 02
Pretext development
Scenarios where a QR code is genuinely expected: MFA re-enrolment, parking, canteen payment, document collection, visitor wifi.
- 03
Infrastructure preparation
Landing pages built mobile-first, since every target arrives on a phone. Device and user agent captured to establish whether arrivals are managed or personal.
- 04
Email campaign
QR codes embedded as images, with and without accompanying text, to measure whether image-only messages bypass more controls.
- 05
Physical placement
Where in scope: codes placed in agreed locations — car parks, reception, kitchens, printer areas — with each location tracked separately.
- 06
Device analysis
Whether scans arrive from managed or personal devices, which determines whether any of the organisation's controls applied at all.
- 07
Control assessment
Whether mail filtering detected the QR code, whether mobile device management would have intervened, and whether web filtering applies on personal devices.
- 08
Reporting and training
Technical report and executive summary, with training targeted at the specific behaviour rather than at phishing generally.
Approach to testing
- Device type is recorded for every scan, because a scan from an unmanaged personal phone means no organisational control applied and that is the finding.
- Email campaigns run with and without accompanying text, since image-only messages frequently pass filters that text-based lures do not.
- Physical placement requires facilities, reception and security to be informed, and every code is retrieved and accounted for at the end of the engagement.
- Landing pages are mobile-first, because a desktop page that renders badly on a phone measures page design rather than susceptibility.
- No application installation is requested. The simulation stops at the landing page and never asks a target to install anything on a personal device.
Types of assessment
Email-delivered (default)
QR codes in email, testing both user judgement and mail filtering. Easiest to run and to repeat.
Physical placement
Codes placed in the workplace. Tests a different instinct entirely, since a code on a poster carries implied authority.
Combined campaign
Both channels, so results can be compared. Physical placement usually returns markedly higher scan rates.
MFA re-enrolment scenario
The highest-risk pretext, since it is a context where a QR code is genuinely expected and the payoff is account access.
Frameworks and standards
- MITRE ATT&CK T1566
- Phishing technique reference; QR delivery is a sub-variant of link-based phishing.
- NIST SP 800-50
- Awareness programme structure for the training that follows.
- OWASP MASVS
- Where the campaign tests whether targets would authenticate through an unmanaged device.
- ISO/IEC 27001 Annex A.6.3 / A.8.1
- Awareness and user endpoint device controls.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
Gophish with QR generation
Campaign delivery, unique code per recipient and result tracking.
Custom mobile-first landing pages
Pages built for a phone, with device and user agent capture.
Unique QR codes per target
So scans can be attributed and forwarding between staff can be detected.
Printed media
Where physical placement is in scope, matched to the client's own signage style.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Email controls
- QR code detection in mail security tooling
- Image-only message handling versus messages with text
- Whether the destination URL is extracted and checked at all
- External sender warnings on image-heavy messages
- Attachment-delivered QR codes, such as PDF invoices
User behaviour
- Scan rate by delivery channel
- Credential submission rate after scanning
- Report rate, and whether staff know a QR code can be reported
- Whether targets checked the destination before proceeding
- Forwarding of the message to colleagues
Device posture
- Managed versus personal device for each scan
- Whether mobile device management is enrolled and enforcing
- Web filtering coverage on mobile devices
- Conditional access requiring device compliance
- Whether personal devices can reach corporate authentication at all
Physical
- Scan rate by placement location
- Whether placed codes were noticed, questioned or removed
- Time from placement to first scan and to removal
- Whether anyone reported a suspicious code
- Visitor and contractor exposure in public areas
Authentication
- Whether conditional access blocked the sign-in from an unmanaged device
- MFA behaviour when authentication originates from a personal phone
- Session persistence after authentication from an unmanaged device
- Detection of sign-in from an unrecognised device
How findings are scored
Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.
- Critical
- Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
- High
- Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
- Medium
- Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
- Low
- Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
- Informational
- A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.
Scan types selected
- Safe Checks
- Standard / OWASP Top 10
- Destructive
- SANS Top 25
- Business Logic Vulnerability Testing
Standard toolset by stage
- OSINT
- Datasploit, Google Dorks, Shodan
- Enumeration & Scanning
- Nmap, Wfuzz, Unicornscan
- Domain Enumeration
- Nikto, DnsRecon, Knock
- Crawling & Fuzzing
- Burp Suite, Acunetix, Netsparker
- Vulnerability Analysis
- OpenSSL, sqlmap, CVE-Details
- Exploitation
- Metasploit, Netcat, Exploit-DB
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Mail control testing across permutations — image-only, image with text, PDF-embedded, varying code sizes and error correction levels — is combinatorial and identifies precisely which variant bypasses filtering.
Device and user agent analysis across every scan produces the managed-versus-personal split, which is the finding that matters and is lost if scans are only counted.
Correlating scans against the client's conditional access and sign-in logs establishes whether authentication from those devices would have been blocked.
Unique code tracking across recipients detects forwarding, which spreads exposure well beyond the tested population.
Every campaign is reviewed by a human and approved by the client before any code is sent or placed. Agents assist with variant generation and result analysis; nothing is delivered to staff without explicit sign-off.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Device posture is the finding
Most vendors report a scan rate. The number that matters is how many scans came from unmanaged personal phones, because that is where the organisation's controls stopped applying entirely.
Filter bypass mapped by variant
Testing image-only, text-accompanied and PDF-embedded codes identifies which specific variant defeats the client's mail security, which is actionable in a way a single scan rate is not.
Physical and digital compared
Running both channels shows where the organisation is weaker. Physical placement usually returns far higher scan rates and is almost never tested.
Both reports, always
Technical report on controls and device posture, executive summary on behaviour and exposure.
Reporting
Two documents, two audiences
Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.
Technical assessment report
For the engineers who will fix it
- Disclaimer, and Limitations on Disclosure and Use
- Risk Level & Description — the five levels above, scored on CVSS 3.1
- Scan Type — which of the five assessment types were selected
- Assessment Scope — the control areas covered
- Assessment Date — the exact testing window
- Objective of the Assessment — objectives listed against completion status
- Tools Utilization — manual and automated tooling by stage
- Summary of the Assessment
- Overall Recommendations, split into Must Have and Should Have
- Vulnerability Overall Classifications as per Organization
- Security Issues Highlighted
- The Key Findings — each with evidence and detailed recommendation
- Summary of Findings & Conclusion
For this assessment specifically
- Scope, channels, pretexts, placement locations and the campaign window
- Scan, submission and report rates by channel and by location
- Device analysis: managed versus personal, operating system, browser
- Mail control findings by QR delivery variant
- Conditional access and sign-in analysis for authentication attempts
- Physical placement observations including time to removal
- Recommendations split between technical control and awareness
Executive summary
For the people who will fund the fix
- Objectives, each against a completion status
- Overall Finding of the Assessment — total threats identified, broken down by component and severity
- Summary of the Assessment
- Artefacts of the Assessment — the key findings as a numbered register with severity
- Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
- Overall Recommendation, including a Business Enabling Recommendation sequence
- Must Have and Should Have actions
For this assessment specifically
- How many staff scanned, and how many did so on a device the organisation does not control
- Whether mail security detected the codes at all
- Whether authentication from an unmanaged phone would have been blocked
- The three changes that most reduce exposure
- One page
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
A professional services firm of around 600 staff, combined email and physical campaign.
- Finding
- Email scan rate was 9%. Codes placed on printed notices in kitchen areas returned 34%, and one remained in place for eleven days before anyone removed it. Of all scans, 81% came from personal phones with no device management.
- Recommendation
- Add conditional access requiring device compliance for corporate authentication, brief facilities on unauthorised signage, and run awareness specifically on physical QR codes.
- Outcome
- Conditional access deployed within six weeks, which closed the authentication path regardless of scan rate. Facilities now remove unattributed notices as routine.
A financial services firm with a well-regarded mail security platform.
- Finding
- QR codes embedded directly in the message body were detected and quarantined reliably. The same code inside a PDF attachment styled as an invoice passed through untouched, and returned a 17% scan rate among finance staff.
- Recommendation
- Enable attachment content inspection for QR codes, and treat PDF-embedded codes as a distinct detection requirement with the vendor.
- Outcome
- The vendor enabled attachment QR inspection on the tenant within a month. The finding was raised with the vendor as a product gap and reportedly informed a wider roadmap change.
A healthcare provider, MFA re-enrolment pretext delivered by email.
- Finding
- A message claiming MFA re-enrolment was required before a deadline returned a 22% scan rate and 14% credential submission. Every submission came from a personal phone. Conditional access permitted authentication from unmanaged devices for the affected user group.
- Recommendation
- Require compliant devices for authentication, move MFA re-enrolment to an in-person or verified process, and never legitimately ask staff to re-enrol via a QR code in email — because doing so trains them to accept the attack.
- Outcome
- Device compliance enforced for clinical staff over two months. The organisation also stopped a planned legitimate QR-based enrolment campaign that would have undermined the training.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.