QR Code Phishing and MFA Push Fatigue: Stop the New Wave of Account Takeovers

Attackers have shifted from typo-riddled emails to clean, believable lures that exploit everyday habits - scanning QR codes and approving MFA prompts on autopilot. Here's how to cut off these attack paths without slowing down your team.


Why this matters now

QR codes are everywhere: office posters, packages, emails, lobby signage, even "parking tickets." Malicious codes route users to credential-harvesting pages that look identical to Microsoft 365 or Google.

MFA is being bypassed through "push bombing" and social engineering. Users get repeated prompts and tap approve to make them stop, or attackers call the help desk pretending to be the user.

Once an attacker is in, they add their own MFA method, create inbox rules, change bank details, and impersonate staff - often undetected for days.

How these attacks work

QR code swaps: A sticker placed over a legitimate QR code redirects to a fake login. The page proxies credentials in real time, defeating basic MFA.

MFA fatigue: Attackers trigger dozens of prompts, often at night. When the user is exhausted, they approve one. Some attackers then call "from IT" to "verify" the login.

OAuth consent tricks: Instead of credentials, the attacker requests app permissions ("read your mail," "send on your behalf"). Once granted, they don't need your password.

Red flags your team should recognize

QR codes sent by email or chat for "urgent" updates, storage upgrades, invoice previews, or new policies

MFA prompts you didn't initiate, especially late night or early morning

Consent screens asking for broad mailbox or file access from unfamiliar apps

Login pages that load through shortened or odd-looking URLs before landing on a brand domain

Controls that actually reduce risk

Stronger MFA and fewer prompts

Move high-risk roles (finance, admins, execs) to FIDO2 security keys or device-bound passkeys.

Require number-matching in the authenticator app; disable simple "Approve/Deny."

Set sign-in frequency and reauthentication policies to reduce noisy prompts.

Conditional access and device trust

Block or require extra verification for sign-ins from risky locations, TOR/VPN, or unmanaged devices.

Enforce compliant devices for access to sensitive apps and data; consider an MDM baseline for BYOD.

Safe Links and time-of-click protection

Turn on URL scanning that rewrites links and checks them at click-time - including links behind QR codes.

Block unknown top-level domains and known-bad URL shorteners in email.

QR code policy and safe alternatives

Treat emailed QR codes as untrusted by default. Prefer clickable, verified links or direct app navigation.

For physical signage, print short branded URLs alongside QR codes so staff can type them directly if unsure.

Consent governance for OAuth apps

Restrict who can consent to apps; require admin approval for broad scopes (mailbox/file access).

Monitor for anomalous consents and recently added OAuth apps; review and revoke monthly.

Incident-ready mailbox and identity monitoring

Alert on new inbox rules, forwarding rules, and changes to MFA methods.

Watch for impossible travel, unusual file downloads, and suspicious app enrollments.

Finance and help desk verification scripts

Payment change requests: "We only accept banking changes verified via a known phone number on file."

Unexpected MFA prompts: "If you didn't start a login, tap Deny and report it to IT immediately."

Help desk identity checks: "Please provide the secondary verification phrase from onboarding."

Rapid response if something seems off

Unexpected MFA prompt: Deny, then report.

Clicked a QR code and logged in: Change your password, report to IT, and have sessions revoked.

Suspected mailbox rules/forwarding: Remove rules, reset sessions, review OAuth consents, and enable audit logging.

Money moved: Call the bank's fraud line right away; speed is critical.

Metrics to track

Percentage of high-risk users on phishing-resistant MFA (target: 90%+)

OAuth app consents reviewed and approved (target: 100% of new broad-scope apps)

Time-to-report suspicious prompts or links (target: under 15 minutes)

Incidents tied to QR codes or link shorteners (target: trending down)

How Vector Choice can help

Identity and email security baseline for Microsoft 365: Conditional access, Safe Links, Safe Attachments, mailbox rule monitoring, and audit-ready logging

Phishing-resistant MFA deployment: FIDO2/passkeys rollout with change management focused on finance/admin/execs

SaaS governance: Admin consent workflows, risky app detection, and monthly access reviews

Awareness micro-drills: 10-minute monthly exercises covering QR scams, push fatigue, and consent traps

Managed detection and response: 24×7 monitoring for account takeover and BEC behaviors