
QR-Code PDFs Steal Microsoft 365 Logins
Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…
Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies, session-token theft, and device-code (OAuth) phishing, enabling mailbox takeover, internal re-phishing, and in some cases ransomware follow-on activity.
Cisco Talos incident response data for Q2 2026 shows phishing as the leading initial access method, present in more than half of engagements where the access vector was known. One persistent campaign used auto-generated, victim-tailored PDF documents containing QR codes that pointed to adversary-controlled Microsoft 365 credential harvesting pages. Because the malicious link is embedded as an image inside a QR code rather than plain text, many email security gateways failed to flag it. Once a mailbox was compromised, attackers used it to send additional phishing emails to internal contact lists, extending the attack's reach through trusted internal relationships.
A second technique involved device-code phishing, where victims are prompted to complete a Microsoft OAuth device authorization flow. This lets attackers obtain valid access tokens without stealing a password at all, a method associated with a phishing-as-a-service platform Talos calls ARToken.
Several factors let these techniques succeed:
Defenders should treat the following as warning signs:
Organizations can reduce exposure by treating QR codes in email attachments as untrusted links that require the same scrutiny as any URL, and by considering policies that block or flag PDF attachments containing QR codes. Because authentication abuse is now common, transitioning from push- and SMS-based MFA to phishing-resistant methods such as FIDO2/WebAuthn and hardware security keys reduces the value of stolen sessions and tokens. Monitoring for anomalous inbox rule creation, SharePoint staging, and outbound email spikes helps catch mailbox takeover early, limiting how far an internal re-phishing campaign can spread before it is contained.
These findings apply broadly across employees, finance teams, executives, and IT and identity administrators, since the initial lure relies on ordinary document-sharing and sign-in workflows rather than technical exploitation.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers embed a QR code inside a PDF attachment rather than a clickable link, so the malicious destination is hidden from text-based email scanners until the recipient scans it with a phone.
Yes. Talos observed device-code phishing that abuses the OAuth device authorization flow, letting attackers obtain valid access tokens without ever capturing the victim's password.
Attackers often create inbox rules for defense evasion, stage malicious documents on SharePoint, and send large volumes of phishing emails from the compromised account to internal and external contacts.
Talos IR recommends moving from push- and SMS-based MFA to phishing-resistant methods such as FIDO2/WebAuthn and hardware security keys.
You get an email: “Document shared with you (scan QR to view).” Looks like SharePoint, from a coworker, PDF attached. You open the PDF, no link, just a big QR code. You scan it on your phone, land on a Microsoft 365 login, and sign in. That’s the trap: it’s a QR-PDF phish stealing your M365 session, not just your password. Behind the scenes, tools like ARToken use that sign-in to grab tokens, bypass MFA, and turn your mailbox into a launchpad, auto-sending more QR PDFs from your real account and staging files in SharePoint. Aha moment: a QR code in a PDF is just a hidden link. If a PDF tells you to scan a QR and sign in to Microsoft, stop. Close it, and go to office.com or your normal M365 app instead.

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

Attackers abused Microsoft’s OAuth “device code” sign-in so victims completed a real Microsoft login and MFA, but the resulting session tokens were issued to…