Microsoft Teams to Block Malicious QR Codes in Messaging
Key Takeaways Microsoft Teams will implement new security measures to combat QR code-based phishing and fraud. The feature will automatically obscure QR codes sent by external users in Teams chats....
Key Takeaways
- Microsoft Teams will implement new security measures to combat QR code-based phishing and fraud.
- The feature will automatically obscure QR codes sent by external users in Teams chats.
- Users will need to manually reveal obscured QR codes, adding a deliberate pause before scanning.
- The rollout is scheduled to begin in October 2026 across desktop and mobile Teams clients.
- The update targets risks associated with external collaboration, encouraging user vigilance.
Microsoft Teams Fortifies Against QR Code Phishing in External Communications
Microsoft Teams is set to introduce enhanced protection mechanisms aimed at mitigating phishing and fraudulent activities propagated through QR codes within chats involving external participants. This proactive measure seeks to bolster security for organizations that rely on Teams for collaboration beyond their internal network.
Table Of Content
Currently listed as “In Development” on the Microsoft 365 roadmap, the forthcoming feature will automatically conceal images containing QR codes when they originate from senders outside an organization. This ensures that potentially malicious QR codes do not immediately expose users to risk.
Rollout Details and Availability
The new QR code protection functionality in Microsoft Teams is slated for a phased rollout commencing in October 2026. It will be universally available across all Teams clients, including desktop, Mac, Android, and iOS, specifically for organizations operating within the Worldwide Standard Multi-Tenant cloud environment. Microsoft has designated this update for both Targeted Release and General Availability, identified under Roadmap ID 570439, with its addition to the Microsoft 365 roadmap on September 3, 2026, and last modification on the same date.
Addressing the QR Code Threat Vector
While QR codes offer a convenient method for sharing web links, they have also become a favored tool for threat actors. Attackers leverage these codes to redirect unsuspecting victims from secure or monitored messaging platforms to malicious websites, often designed for credential harvesting or malware distribution. A QR code embedded within an image can appear innocuous, especially when delivered by a seemingly legitimate external contact, a compromised account, or an unfamiliar sender, making it a potent social engineering vector.
By requiring an explicit user action before content is displayed, Microsoft Teams intends to introduce a critical pause, prompting users to consider the legitimacy of a QR code before scanning it. This intervention aims to disrupt the immediate, unthinking interaction often exploited by attackers.
Mechanism of Protection
Under the planned security update, any QR code image shared by an external sender will be obscured by default. A Teams user receiving such an image will be required to actively reveal it before they can view or scan the embedded QR code. This design choice is intended to foster a more deliberate engagement with QR code content, preventing impulsive scanning directly from a message thread.
This feature is particularly vital for entities that extensively use Teams for engaging with customers, suppliers, contractors, partners, and other external stakeholders. While external communication is essential for business operations, it simultaneously creates avenues for sophisticated social engineering attacks. A fraudster might impersonate a vendor, project lead, or support agent, sending a QR code that directs recipients to a phishing page or other fraudulent destination.
Microsoft’s approach does not restrict access to legitimate QR codes. Instead, it introduces a visible and deliberate friction point, allowing recipients to evaluate the sender, the context of the conversation, and the expectedness of the request before proceeding to reveal and scan the code.
What You Should Do
- Review External Access Policies: Security teams should assess and refine their policies regarding external access and guest communications within their Teams environments in anticipation of this rollout.
- User Education: Remind employees that revealing a QR code does not equate to verifying its safety. Users must exercise caution and independently verify the legitimacy of unexpected QR codes.
- Verify Unexpected Codes: Advise users to confirm unexpected QR codes through a trusted, alternative communication channel, especially when the code is linked to sensitive actions such as login requests, document sharing, payment instructions, or urgent account-related messages.
- Stay Informed: Monitor Microsoft’s official communications and the Microsoft 365 roadmap for further updates on the feature’s availability and specific configurations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.