Nano-lesson · usually takes 2–3 minutes
Dangerous attachments & QR codes
When a file or QR code is a trap — and what to do about it.
Two everyday traps
A sticker with a QR code on the car park payment machine. An unexpected .zip file with an “invoice”. Both can hide malware — malicious software — or a fake login page.
Watch out for
- Unexpected Office files that ask you to “enable macros” — a macro is a small piece of built-in code that can install malicious software. Don't do it.
- .zip / .html / .iso files from unknown senders.
- QR codes in emails, on posters — or stuck over the genuine code on, say, a car park payment machine. You can't tell just by looking where a QR code leads.
Where does the QR code lead?
https://www.royalmail.com.track-parcel.info/track
A QR code can lead to a domain like track-parcel.info — not royalmail.com. You can't see that with the naked eye; always check the address once the page opens, before you log in.
Do
only open files you're expecting. Have you scanned a QR code? Check the address at the top before you type anything. In doubt? Ask IT.
Remember
What the research says
QR phishing is growing rapidly — executives are targeted 42× more often than others — precisely because the QR code moves you onto a private mobile device and bypasses mail filters, and anyone with a mobile in their pocket is a possible target. Well-designed browser warnings, on the other hand, stop 75–90% of users — as long as they don't click straight past them.
Abnormal Security 2024 · Akhawe & Felt, USENIX Security 2013.
Question 1 of 3
You open an emailed “invoice” in Word. A yellow bar at the top says: “Enable content to view the document”. What do you do?
✓ Correct!
“Enable content” launches hidden code that can install malicious software — and antivirus doesn't always catch it. A genuine document doesn't need that click.
Question 2 of 3
You scan the QR code on a car park payment machine. The page asks for your card details — but the address at the top is pay-parking.info. What do you do?
✓ Correct!
Scammers stick fake QR codes over the genuine ones. The amount doesn't matter — it's your card details they're after. Pay through a route you know and trust.
Question 3 of 3
A company you've never dealt with sends “Invoice_40912.zip”. What's the safest thing to do?
✓ Correct!
An unexpected .zip is a classic way to deliver malicious software — and phones can be affected too. If the invoice is genuine, the sender is sure to follow up.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.