# The phishing that arrives by phone, text and QR code

> Your mail filtering never sees a phone call, a text, a QR code or a Teams message from outside your organisation. Here is how to defend the other channels.

*Source: https://panoptic.ie/blog/phishing-by-phone-text-and-qr-code*

# The phishing that arrives by phone, text and QR code

Your team has been trained to spot a suspicious email. Attackers have responded by using the channels your mail security cannot see.

David Griffith, Managing Director · 4 September 2026

![A black office desk phone with coiled cord and documents displayed on a stand beside scattered papers in a modern office space.](https://panoptic.ie/_astro/blog_phishing_by_phone_text_and_qr_code_c15388fc5b_Z1Lrbda.png)

In short

Email filtering, external-sender banners and link rewriting all sit on your mail flow, so they never see a phone call, a text to a personal mobile, a QR code or a Teams chat request from outside your organisation. Verizon's 2026 report puts 41% of social engineering outside email. The fix is a written verification procedure, not sharper instincts.

Your team has been trained to spot a suspicious email. That training is worth having, and it covers one of the four ways an attacker now reaches them.

A phone call, a text to a personal mobile, a QR code printed on an invoice and a Teams message from outside your organisation all arrive somewhere your mail security never looks. Verizon's [2026 Data Breach Investigations Report](https://www.verizon.com/business/resources/reports/dbir/) attributes 41% of social engineering breaches to a route other than email.

## Your filtering only sees one of the channels

Think about what you pay for to protect the inbox. Spam and malware filtering. A banner marking mail from outside the organisation. Link rewriting that checks a destination at the moment someone clicks it. Quarantine, so a suspect message never reaches the person at all.

Every one of those controls is bound to mail flow. A text message to a staff member's own phone passes none of them. Neither does a call to the practice landline, a QR code someone points a camera at, or a chat request that lands in the app your team uses for internal conversation all day.

This is not a failure of your mail security. It is doing the job it was bought for. The problem is that we call the whole risk "phishing", train for it as an email problem, and are then caught out when it arrives on a different wire.

## The four routes we see most

### The phone call

Someone rings claiming to be from your IT provider, your bank, or Revenue. They have your name, your role and often the name of a colleague, all of which are on your website or LinkedIn. The goal is usually one of three things: a password, a code read aloud, or approval of a prompt that has appeared on your phone.

Our own [phishing and social engineering testing](https://panoptic.ie/blog/phishing-and-social-engineering-testing) work reflects the wider data here. Median click rates on simulated email sit near 1.4%, while phone-based approaches reach about 2%. Staff are more likely to be caught on the phone than in the inbox, and almost every awareness course they have sat through was built around the inbox.

### The text message

A short message about a failed delivery, a Revenue refund, or an urgent request from a manager whose name the sender knows. Personal mobiles are outside your control entirely. There is no quarantine, no banner, and no administrator who can pull the message back.

### The QR code

A code printed on a letter, an invoice or a parking sign takes the reader to a login page on a device your organisation may not manage. Scanning happens on a phone, where the address bar is short, the domain is truncated, and the usual advice to hover over a link does not apply.

### The Teams message

This one deserves particular attention, because it is common and most businesses have never considered it. Microsoft Teams allows chat with people in other organisations, and where that setting is open, anyone who registers their own tenant can start a conversation with your staff.

Attackers register a tenant and set a display name such as "IT Support" or "Helpdesk". The message then appears in the same application your team uses for genuine internal chat, alongside their colleagues, in a place they have been taught to treat as internal. Some approaches open with a friendly warning about an account problem, followed by an offer to help fix it.

The defence is partly a setting. Your administrator can restrict external chat to a named list of domains, or turn it off. Ask who holds that setting in your organisation and what it is currently set to.

## When the attacker rings your help desk

The most effective version of this reverses the direction. Rather than ringing a staff member, the attacker rings your help desk or your IT provider, pretends to be one of your people locked out before a meeting, and asks for a multi-factor authentication reset.

That call is a request to hand over an account, and it is answered by someone whose job is to be helpful under time pressure. It is the technique behind several of the largest breaches of the last two years, and it needs no malware at all.

So the verification question runs both ways. Ask your provider what proof they demand before resetting an authentication method, and whether that proof is something an attacker could read on your website. If the answer is a date of birth or a manager's name, it is not proof.

## Verification is a procedure, not a state of alertness

Telling people to stay vigilant does not work, because vigilance fades by Thursday afternoon. A written rule works, because it survives a bad week.

The rule we recommend has three parts:

1. **Nobody approves an authentication prompt they did not trigger.** If a prompt appears unexpectedly, the answer is always no, followed by a report. A prompt you did not ask for means somebody else has your password.
2. **Verification happens on a number your team looks up, never one they are given.** A caller claiming to be your IT provider is thanked, hung up on, and rung back on the number in your own directory. Legitimate support staff expect this and are not offended by it.
3. **Requests to change bank details, payroll details or authentication methods are confirmed on a second channel.** A person your team knows, on a number they already hold, before anything changes.

Put those three lines on one page, give it to every new starter, and repeat it when someone reports an attempt. Reporting is the behaviour to praise, including when the report turns out to be a genuine caller.

Where an attempt does succeed, speed matters more than blame. Our guidance on [spotting a hijacked mailbox early](https://panoptic.ie/blog/account-takeover-spotting-a-hijacked-mailbox-early) covers what to do in the first hour.

## What to check this week

- Find out whether external chat in Teams is open to any organisation, and restrict it to domains you work with.
- Ask your IT provider what identity proof they require before resetting multi-factor authentication, and say plainly whether you find it sufficient.
- Write the three-part verification rule above on a single page and circulate it.
- Agree one internal number staff can ring to check whether a request is genuine, and make sure it is answered.
- Check that the people most likely to be targeted, meaning finance, reception and practice managers, know they have permission to refuse an urgent request until it is verified.

The technology side of this is a handful of settings. The rest is a procedure your team can follow when they are busy. If you would like a second opinion on either, [talk to us](https://panoptic.ie/contact) about how your current setup handles the channels outside the inbox, or read more about what sits inside [managed IT](https://panoptic.ie/services/managed-it).

What is vishing, and how is it different from phishing?

Vishing is phishing carried out by voice call. The attacker rings a member of staff, poses as IT support, a bank or a supplier, and talks them into giving up a code, a password or approval of an authentication prompt. It works on the same trust as email phishing, but no filtering product sits between the caller and your phone system.

Can attackers really contact my staff through Microsoft Teams?

Yes. Teams supports chat with people in other organisations, and where that setting is left open, anyone who registers their own tenant can message your staff. Attackers use display names such as "IT Support" so the request appears alongside genuine internal conversation. Your administrator can restrict external chat to approved domains or switch it off.

Is it safe to scan a QR code on a letter or an invoice?

Treat it the same way you would treat a link in an unexpected email. Scanning usually happens on a phone, where the address bar is short and the real domain is hard to read, and the device may not be managed by your organisation. If the code leads to a login page, close it and reach the service through an address you already know.

Can Microsoft 365 filtering stop a phishing text message?

No. Mail filtering, external-sender banners, link checking and quarantine all operate on mail flow. A text message to a personal mobile never passes through them, and neither does a phone call or a QR code on paper. Those channels need a verification procedure your staff follow, because there is no product sitting in the path.

Should phishing simulations include phone calls and texts?

They should, if you want the result to mean anything. Testing email alone measures the one channel your team has already been trained on. Adding voice and SMS shows how people respond where they have no filtering and no banner to fall back on, which is where a real attacker is now more likely to start.

[All blog posts](https://panoptic.ie/blog)

## Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.

[Talk to us ](https://panoptic.ie/contact)[See how we onboard](https://panoptic.ie/how-we-onboard)
