Microsoft Teams blocks fake QR codes
Microsoft is adding a feature to Teams that hides QR codes sent by outside contacts until you choose to reveal them. It is meant to stop people from impulsively scanning QR codes that lead to fake login pages or scam payment sites.
- Report priority
- Medium
- Targets
- Microsoft 365
How it works
Attackers hide malicious links inside QR code images because a picture is harder to inspect than a normal web link, then send those images through Teams chats from external accounts to pressure people into scanning them quickly.
What to do
Check whether your organization's Microsoft 365 admin has reviewed the Teams external communication settings ahead of the October 2026 rollout listed under Microsoft 365 Roadmap ID 570439.
Employees should still verify any sender through a separate trusted channel before revealing or scanning a code, and never enter work credentials after following a QR code link.
Technical details
Affected software: Microsoft 365
Microsoft 365 Roadmap ID 570439 describes a Teams messaging change that blurs QR codes embedded in images sent by external tenants until the recipient takes an explicit action to reveal them. It targets Android, iOS, desktop, and Mac clients in worldwide standard multi-tenant cloud environments, with Targeted Release and General Availability planned for October 2026. It is a UI friction control against quishing (QR phishing), not a fix for a specific exploited flaw, and it complements existing external access policies, guest controls, and identity protections.