QR Phishing as a Cross-Device Detection Gap
The interesting part of QR phishing is not the code. It is the jump from a managed inbox to a less visible device.
Research finding
What caught my attention about QR phishing was the boundary change. An email attachment may be inspected on a managed system, while the encoded destination is opened on a personal phone with different controls and visibility.
I would not centre the defence on any specific lure. Scanning needs to cover rendered documents and encoded links, while awareness training needs to address cross-device actions rather than only suspicious email links.
Simulation requirement
An authorised simulation should measure the decision points that matter without reproducing unnecessary offensive detail. The useful outputs are whether the content was opened, whether the destination was visited, and which controls or guidance prevented progression.
That boundary is why I keep returning to campaign-level coverage. Protection can look strong in one system while the attack moves to a less visible channel.