Appearance
How to Recognize Modern Scams — QR Codes, Fake Texts, and AI-Generated Tricks
Applies to: All devices and platforms
Article Type: Informational
Last Updated: 2026-06-17
Summary
Scammers have moved beyond email. This article covers the newest attack methods — QR code phishing (quishing), SMS and text message scams (smishing), and AI-generated deepfake calls — with real-world examples and practical steps to protect yourself.
Prerequisites
- None — this is an awareness article for all users.
Instructions
1. QR Code Scams (Quishing)
QR codes are everywhere — parking meters, restaurant menus, conference badges, and emails. Scammers exploit this trust by replacing or overlaying legitimate QR codes with malicious ones.
How it works:
- A scammer places a fake QR code sticker over a legitimate one (e.g., on a parking meter or restaurant table).
- You scan it, and it opens a convincing fake login page that captures your username and password.
- QR codes in emails bypass traditional link-scanning tools because the URL is embedded in an image, not clickable text.
Red flags:
- A QR code on a printed sticker placed over another QR code.
- A QR code in an email asking you to "verify your account" or "confirm your identity."
- The scanned URL does not match the expected website (e.g., you scanned a code at a hotel but the URL is
secure-login-verify.cominstead ofhilton.com).
How to protect yourself:
- Preview the URL before tapping. Most phone cameras show the URL before you open it. Read the full domain name — look for misspellings or extra words.
- Never enter your password on a page opened from a QR code unless you have independently verified the URL matches the legitimate site.
- If a QR code in an email asks for credentials, ignore it. Go to the website directly by typing the URL in your browser instead.
- Report suspicious QR codes on physical signage to the venue staff.
2. Text Message Scams (Smishing)
Smishing — phishing via SMS — uses text messages to trick you into clicking a malicious link or calling a fake number.
Common smishing scenarios:
- "Your package could not be delivered. Confirm your address: [link]"
- "Unusual sign-in detected on your Microsoft account. Verify now: [link]"
- "Your bank account has been locked. Call [number] to restore access."
- "IT Department: Your password expires today. Reset here: [link]"
Red flags:
- Urgency. "Act now," "immediate action required," "your account will be suspended."
- Unknown sender. A short code or phone number you do not recognize.
- Suspicious links. URLs with unusual domains, random strings of characters, or misspelled brand names (e.g.,
micros0ft-verify.com). - Requests for personal information. No legitimate service asks for your password, Social Security number, or credit card via text.
How to protect yourself:
- Never tap a link in a text message you did not expect — even if it appears to come from a known company.
- Go directly to the source. If a text claims to be from your bank, open your banking app or type the bank's URL directly in your browser. Do not use the link in the text.
- Do not reply to suspicious texts — not even to say "STOP." Replying confirms your number is active.
- Report spam texts. Forward the message to 7726 (spells "SPAM" on your keypad). This reports it to your carrier.
- Block the sender on your phone after reporting.
3. AI-Generated Voice and Video Scams
AI tools can now clone a person's voice from a few seconds of audio. Scammers use this to impersonate executives, IT staff, and family members.
Common AI voice scam scenarios:
- A call that sounds like your CEO asking for an urgent wire transfer or gift card purchase.
- A call from "IT support" asking you to share your screen or read back a verification code.
- A voicemail from a "colleague" asking you to click a link they sent by email.
Red flags:
- Unusual requests. Your boss would not normally call you directly to ask for a wire transfer or gift cards.
- Urgency and secrecy. "Do not tell anyone about this." "This must be done before end of day."
- Bypassing normal process. Legitimate financial requests go through formal approval channels, not a phone call.
- Slight audio artifacts. AI-generated voices may have unnatural pauses, robotic intonation, or background noise that does not match the environment.
How to protect yourself:
- Hang up and call back using a known number. If someone calls claiming to be your boss or IT, hang up and call them using the number in your company directory — not the number that recently called you.
- Verify through a second channel. If you receive a suspicious call, confirm the request via Teams chat, email, or in person.
- Never share verification codes, passwords, or remote access over the phone — regardless of who the caller claims to be.
- Establish a verbal code word with your team for high-stakes requests (e.g., financial transfers).
4. AI-Generated Phishing Emails
The old advice — "look for typos and bad grammar" — no longer works. AI-written phishing emails are grammatically perfect, professionally formatted, and often personalized with your name, role, and company.
What to look for instead:
- Unexpected requests. Did you expect this email? Is the sender asking you to do something outside your normal workflow?
- Urgency. "Respond within 1 hour" or "your account will be deactivated."
- Unusual sender address. The display name may say "IT Support" but the email address is
[email protected]. Always check the actual sender address. - Links that don't match. Hover over any link (do not click) and check if the URL matches the claimed destination.
- Requests for credentials or sensitive data. No legitimate internal process asks you to email your password.
How to protect yourself:
- When in doubt, do not click. Close the email and verify the request through a different channel.
- Report suspicious emails using the Report button in Outlook. See How to Report an Email in Outlook.
- Check the sender's email address carefully — not the display name, but the actual address in the "From" field.
- For a complete guide to spotting phishing, see How to Identify a Phishing Email.
5. What to Do If You Fell for a Scam
Act quickly to limit the damage.
- Change your password immediately from a clean, trusted device. See How to Change Your Microsoft 365 Password.
- Enable MFA if it is not already active. See How to Use the Microsoft Authenticator App.
- Check your sign-in activity for unauthorized access. See How to Check If Your Email Was Compromised.
- Contact your IT department immediately. Report what happened, what information you provided, and when it occurred.
- Monitor your bank accounts if you provided financial information.
- Run a full security scan on the affected device using Windows Security > Virus & threat protection > Scan options > Full scan.
6. Report the Scam
Reporting helps protect others and may help catch the attacker.
- Report to your IT department or helpdesk — include screenshots if possible.
- Report spam text messages by forwarding the text to 7726 (SPAM).
- Report the email in Outlook using the built-in Report button. See How to Report an Email in Outlook.
Troubleshooting
WARNING
No legitimate IT department, bank, or service will ever ask for your password by text message, QR code, or phone call. If someone does, it is a scam — even if they know your name, your role, or your company.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Scanned a QR code and entered credentials | Quishing attack — credentials may be compromised | Change your password immediately from a clean device. Enable MFA if not already active. Report to IT. |
| Clicked a link in a suspicious text message | Smishing — device may have loaded malicious content | Close the browser tab immediately. Do not enter any information. Run a security scan on your phone. Report the text by forwarding to 7726. |
| Received a call from "IT" asking for your password | Social engineering or AI voice cloning | Hang up. Call your IT helpdesk using the number from your company directory — not the number that called you. Never share your password over the phone. Afterwards, report it: tell IT the number that called you and what they asked for, so they can warn everyone else. |
| Colleague sent an unusual request via email | Possible compromised account or AI-generated spoof | Do not reply to the email. Contact the colleague through a different channel (Teams, phone) to verify the request is legitimate. |
| Received an MFA prompt you did not initiate | Someone may have your password and is trying to sign in | Deny the prompt immediately. Change your password right away. Report to IT. See How to Understand MFA and Prevent Account Lockouts. |
Related Articles
- How to Identify a Phishing Email
- How to Recognize and Avoid Tech Support Scams
- How to Spot Fake Microsoft Login Pages
- How to Check If Your Email Was Compromised
- How to Report an Email in Outlook
- Understanding Microsoft 365 Account Security — What Protects You and Why
- How to Use the Microsoft Authenticator App
- How to Understand MFA and Prevent Account Lockouts