Microsoft is developing a Microsoft Teams safeguard that will obscure images containing QR codes in messages from external users by default. Recipients will have to deliberately reveal an image before they can view or scan its QR code, reducing the chance that a malicious destination is opened through an unsolicited message. Microsoft expects the protection to begin rolling out in October 2026 for Teams on Android, iOS, Windows and Mac.
The change addresses QR-code phishing, in which attackers use codes to conceal fraudulent or malicious links from users until after a scan. QR codes are also used in consumer scams, including deceptive codes delivered on unexpected packages, making deliberate verification of a code’s source and destination an important defense against fraud and credential theft.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The U.S. Federal Trade Commission warned consumers to treat QR codes on unexpected packages as suspicious, citing their potential use in scams.
Microsoft is developing a Teams safeguard that obscures QR-code images sent by external users until recipients explicitly choose to reveal them. The planned feature is intended to reduce QR-code phishing and fraud risk across Android, desktop, iOS, and Mac clients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcenordvpn.com
Open sourceconsumer.ftc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.