Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Typos, suspicious-looking links and spam filters are no longer enough to identify every phishing attempt. QR codes can move a click from a monitored inbox to a phone; OAuth consent phishing can use a genuine sign-in service to ask for dangerous app permissions; and AI can make a fake message or voice sound convincing. The safest response depends on what the attacker is asking you to trust—not just whether the message looks polished.

Why familiar phishing checks can miss the attack

Many older checks focus on the message itself: Is the grammar awkward? Does the visible link look strange? Did the email reach the inbox? Those questions still help, but they do not cover every step in a modern phishing flow.

A QR code can conceal the destination until someone scans it on another device. A consent prompt can appear within a legitimate identity provider even though the app requesting access is malicious. AI-assisted wording or a familiar-sounding voice can remove clues people once relied on. In each case, the weak point is not necessarily a misspelled email or a fake-looking login page; it is a decision to scan, grant access, disclose a code or trust an unexpected request.

How do I know if a QR code is safe to scan?

You cannot determine that from the pattern of squares alone. Treat an unexpected QR code that asks you to sign in, open a shared file or resolve an urgent account issue as an unverified link. If your camera displays a destination before opening it, inspect that destination; if it is unclear, unexpected or not the service you intended to use, do not continue. The safer option is to reach the service through its known app, a bookmark or an address you enter yourself, then check whether the request is actually there.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

QR phishing, sometimes called “quishing,” places a QR code in an image or document and persuades the recipient to scan it. The scan can open a credential-harvesting page on a mobile device. Because the interaction leaves the email and moves to a phone, ordinary email link inspection may not reveal the eventual destination, and the phone may not be covered by the organization’s endpoint controls. Microsoft Learn’s phishing trends guidance describes this device shift.

This is not a reason to treat every QR code as malicious. It is a reason not to let a code in an unexpected message make the destination decision for you.

What the reported Kimsuky campaign shows

In a January 8, 2026 alert, the FBI described Kimsuky QR-code spear-phishing campaigns against think tanks, academic institutions and U.S. and foreign government entities. The alert discusses campaigns from May and June 2025, including attacker-controlled redirects, mobile-optimized credential pages, collection of device and identity attributes, session-token theft and persistence.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That is an account of targeted incidents, not a measurement of how common QR phishing is across all email users. For an individual recipient, the practical lesson is to verify a QR-linked request independently rather than assuming it is safe because it appears in a document or looks work-related.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a phishing attack use a real Microsoft or Google sign-in?

Yes. A familiar identity provider can be involved without the app asking for access being trustworthy. In OAuth consent phishing, an attacker tries to persuade a user to grant a malicious cloud application permissions. The user may authenticate through a legitimate provider and see a real consent interface, yet still authorize an app that can access data under the permissions granted. Microsoft’s guidance on protecting against consent phishing explains the distinction.

Before approving an access request, check the application name, publisher or verified-publisher details, and the specific permissions requested. Ask whether those permissions make sense for the task you were trying to do. A familiar provider’s logo or a valid sign-in page confirms neither the app’s identity nor the appropriateness of its requested access.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What to do if you clicked Cancel

Cancel is not a guarantee that every part of a suspicious flow has safely ended. Microsoft documented a 2025 campaign in which a user who clicked Cancel on a malicious permission prompt was still redirected to the app’s reply URL and then to an adversary-in-the-middle domain for another phishing attempt. If an unexpected consent flow behaves strangely, close the browser or app rather than following further redirects, and report the event through your organization’s security process. The edge case is described in Microsoft’s article on evolving identity attack techniques.

What “ConsentFix” means here

The term “ConsentFix” appears in the supplied article title, but the accessible official sources cited here do not establish it as a named technique or attack family. They do document OAuth consent phishing and other abuses of identity flows. Without verified sourcing for a distinct “ConsentFix” definition or sequence, it would be misleading to describe it as a documented technique; the supported explanation is the consent-phishing mechanism above.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How AI changes the lure, not the underlying warning signs

AI can help attackers draft more polished phishing or spear-phishing messages, and it can be used to impersonate someone’s voice. Microsoft reports observed use of large language models for phishing content and suspected generative-AI use in a credential-phishing campaign. The FBI has also reported an impersonation campaign using AI-generated voice messages. These reports establish observed uses, not a universal share of phishing attributable to AI or a way to identify a message as AI-generated just by reading it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Better grammar is not proof that a message is legitimate, just as polished wording is not proof that AI was involved. A familiar-sounding voice is not proof of identity either. When a message or call asks for money, credentials, an MFA code, a download or an unusual account action, verify the request through a contact method you already trust. Do not reply using contact details supplied in the unexpected message, and never disclose an MFA code in a message. The FBI’s alert on impersonation of senior U.S. officials recommends independent identity verification and caution with links and downloads.

Device-code phishing is related, but it is not consent phishing

A separate identity-flow attack can use a real verification page without asking the victim to approve an app’s permission prompt. In the FBI’s May 21, 2026 alert about the Kali365 phishing-as-a-service kit, a victim enters a device code on a legitimate Microsoft verification page and unknowingly authorizes a device controlled by the attacker. The alert says the kit offered AI-generated lures and OAuth token capture. That makes device-code phishing a useful adjacent example of why a legitimate page alone does not prove a request is safe; it does not make device-code phishing another name for consent phishing or “ConsentFix.”

The FBI recommends restricting or blocking device-code flow where feasible, while auditing legitimate dependencies and allowing limited exceptions where needed. Its Kali365 alert addresses this control. Because some organizations may rely on device-code authentication, administrators should assess dependencies before applying a broad block.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the attack patterns differ

Pattern What the victim is asked to trust Typical objective in cited reporting Control that interrupts the flow
QR phishing An encoded destination reached by scanning, often on a phone Credentials, session tokens or account access, as described in the FBI’s targeted Kimsuky campaign Verify the destination independently; use appropriate mobile, QR and identity monitoring in managed environments. FBI alert
OAuth consent phishing A legitimate-looking consent flow and a malicious app’s request for permissions Permission-based cloud data access and tokens Constrain consent, inspect app details and permissions, and audit app grants. Microsoft guidance
AI-assisted phishing Polished text or an impersonated voice Persuade a target to engage, disclose information or authorize an action Verify the sender or caller using a known, separate contact channel; keep MFA codes private. FBI guidance
Device-code phishing (related, distinct) A real verification page paired with a code supplied by an attacker OAuth access or refresh tokens and persistent account access, as described in the Kali365 alert Restrict device-code flow where feasible and audit exceptions and dependencies. FBI IC3 alert

What individuals should do when a request feels off

  • For an unexpected QR code asking you to sign in or access a file, navigate to the service independently instead of scanning through to the requested action.
  • For an unexpected app-permission prompt, stop and check who publishes the app and what access it wants before granting anything.
  • For a message or call from someone you know that asks for an unusual action, verify through a separate, known channel, such as a number already in your contacts or an established workplace directory.
  • Never send an MFA code in response to a message or call. If you entered credentials or approved access before recognizing a problem, contact your organization’s IT or security team promptly so it can assess the account and any grants.

What Microsoft 365 administrators and security teams should change

Controls should match the identity mechanism being abused. For Microsoft 365, Microsoft advises administrators to limit user consent to approved or verified applications and selected low-risk permissions, routinely review application grants, monitor third-party app activity and investigate suspicious grants. These measures reduce the chance that one user’s approval silently gives a malicious app ongoing access.

Organizations should separately assess whether device-code authentication is needed, identify legitimate dependencies and restrict the flow where feasible. For QR campaigns, consider whether mobile devices and QR-linked identity activity are visible to the organization’s security controls; a mail gateway alone may not see where a person goes after scanning. Awareness training should teach people to evaluate requested permissions and verify unexpected requests—not merely to search for typos or hover over email links.

For incident handling, treat an unexpected grant, QR-driven credential entry or suspicious device-code authorization as an identity event, not just a questionable email. Security teams can then investigate app permissions, grants, sign-in activity and sessions appropriate to the suspected flow.

Why “look for typos” is no longer a complete defense

Typos and suspicious URLs remain useful clues, but each attack pattern shifts attention to something else: the destination hidden in a code, the permissions behind a legitimate consent screen, or the identity behind fluent text and convincing audio. A sound defense checks the whole decision being requested—where the code leads, what an app will be allowed to do, and whether the person making the request is really who they claim to be.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.