A finance manager scans a QR code in a Teams thread from someone who looks like a vendor. Ninety seconds later their session cookie sits on an attacker box, and your identity logs show a clean interactive sign-in. No brute-force spike. No malware alert. The ticket still reads “user clicked a link” even though no link ever touched the mail gateway. QR phishing in collaboration chat is already a cybersecurity incident pattern, and Microsoft’s October 2026 hide-the-code feature is a late admission of that.
Help Net Security reports that Teams will automatically hide QR codes sent by people outside the organization. Users will have to reveal the image before they can view or scan it. The work is still in development, with rollout expected to begin in October 2026 on Android, desktop, iOS, and Mac. Treat that date as a reminder. Your control gap is already in production.
Phone cameras walk around your cybersecurity stack
Most of your threat-protection stack assumes the dangerous thing is a URL that crosses a proxy. Email rewriting, sandbox detonations, firewall TLS inspection, even a lot of chat DLP, all sit on that assumption. A QR code breaks it in one motion. The payload is a picture. The click happens on a phone camera that never talks to your secure web gateway.
The user still lands on a fake Microsoft login. The attacker still gets a token. Your threat detection still waits for a hash or a domain your intel feed already knows. Quishing works because it moves the last mile off the managed browser and onto a device your CASB barely sees.

You already spent years on cyber security awareness that says hover the link. A QR code has nothing to hover. The code is the link, rendered as pixels, often in a screenshot, a PDF, or a Teams image drop from a guest. Defense in depth that stops at the email gateway has a hole the size of every phone in the building.
Microsoft Teams will automatically hide QR codes sent by people outside the organization. Users will need to reveal the image first before they can view or scan it, with rollout expected to begin in October 2026 for Android, desktop, iOS, and Mac.
Internal senders are still in play. A compromised mailbox or a guest added last quarter can post the same image. Microsoft’s planned control is scoped to people outside the organization. That is a useful default. It is also a map of what the feature will miss: lateral phishing from an account that already lives in your tenant.
October’s hide toggle will not rewind stolen sessions
A feature in development in September does not protect the chats happening this afternoon. Attackers do not pause for vendor roadmaps. They will keep sending codes in email, SMS, Slack, Zoom chat, and every other place your users already mix work identities with personal scanning habits.
Once the Teams control lands, expect the lures to move. Compromised internal users. A polite “please reveal this, it’s the visitor Wi-Fi.” A screenshot of a QR so the detector sees a photo of a photo. Codes that sit in a document, not an inline image. You have seen this movie with attachment blocking. The bypass shows up in the next ticket.
Stolen sessions are the cost. QR lures in Microsoft 365 ecosystems often feed adversary-in-the-middle kits. The user types a password and an MFA prompt on a page that looks right. Your incident response then spends hours labeling the case while the refresh token is still valid. Name it session theft and revoke it like you mean it.
This is a bad look for a platform that already knows chat is where work happens. Microsoft is adding friction to an image because users will scan it. Fair. You still own the months between now and that rollout, plus every channel the toggle will never touch.
Cleanup is ugly. Finance gets a wire request from the hijacked account. Helpdesk gets lockout noise that looks like a password problem. Your SOC burns a night on sign-in logs that look legitimate because they were. That bill is why a reveal step in front of a picture is arriving at all.
Untrusted QR codes need a hide-first policy now
Do not wait for October to enforce the behavior Microsoft is about to ship. You can make “hidden until revealed” the rule across chat, mail, and mobile today, with controls you already own. Security hardening here is placement: keep the scan off the work identity, and keep the token short when a scan still happens.
- Immediate: Restrict who can post images and files into work chats, especially guests and federated users. Default external images to hidden, blocked, or download-only so a code is not sit-and-scan bait.
- Immediate: Write a one-line policy your helpdesk can enforce: work accounts are never used to scan QR codes from chat, email, or SMS. If a URL is real, it gets typed into a managed browser.
- Immediate: Prefer phishing-resistant MFA (FIDO2, passkeys, or certificate-based) for anyone who can move money, reset identity, or administer cloud tenants. A cloned login page should not mint a durable session.
- Ongoing: Hunt sign-ins from new networks shortly after image-heavy external threads. Treat those as credential incidents. Revoke refresh tokens first, then talk about training.
- Ongoing: Tabletop a guest-posted QR, a personal-phone scan, and an adversary-in-the-middle kit. If your playbook still opens with “was it a malicious link,” rewrite the playbook.
Shorten session lifetimes for web apps that still accept passwords plus a push prompt. Continuous access evaluation helps only if someone is watching the signal. Pair it with a helpdesk script that asks how the user got to the login page. “I scanned a code in Teams” should auto-escalate the same way a reported phishing mail does.
Extend the hide-first habit off Teams. Slack, Zoom chat, SMS, printed “Wi-Fi” signs in the lobby, and PDF invoices are the same class of problem. If your DLP can flag QR-like images in mail, turn that on and route hits to the queue that already handles credential phishing. If it cannot, log external image shares as a high-signal event and sample them weekly.
Mobile is the real browser in this attack. Work profiles, managed chat clients, and a ban on personal-device SSO for privileged roles cut the chance that a kitchen-table camera completes a tenant login. You will not catch every intern. You can stop the people who can export your directory.
If you need a single test this week, send a QR from a guest account to a pilot group and watch whether anyone scans it with a work profile. Then check whether your identity platform would have alerted on the resulting sign-in. That gap is your real control list. Close it before a vendor toggle does the easy third of the job.
Sources
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
