security

Blurred PDF Invoices With QR Codes: HP Wolf's Quishing Warning

Valley Printer Pros Team
6 min read

On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.

Key takeaways

  • HP released its September 2026 HP Wolf Security Threat Insights Report on September 17, 2026, covering campaigns seen in customer telemetry from April through June 2026.
  • Phishing emails carried PDF invoices blurred behind a QR code that told recipients to scan it with their phone, a technique known as quishing.
  • Moving the victim to a phone sidesteps the email and browser protections on a managed work PC, and the QR code led through redirects to a fake Microsoft sign-in page.
  • Printing, scanning or forwarding an invoice doesn't disarm its QR code, so shared payables inboxes and scan folders need the same rule: never scan codes in unexpected invoices.
  • Verify invoices by phone with a known contact, protect Microsoft 365 with multi-factor authentication, and report suspicious invoices to IT.
Share:
#phishing#quishing#hp-wolf-security#accounts-payable#scan-to-email

Your accounts-payable inbox has a new kind of invoice to be suspicious of. On September 17, HP released its September 2026 HP Wolf Security Threat Insights Report, and one of its findings is aimed squarely at the people who open PDFs all day: invoices with the document blurred out and a QR code on top, according to HP, Help Net Security and Security MEA.

The idea behind it is simple: get the target off the protected office PC and onto a phone. Here's how the scam works, why it matters for your office scanner and shared inboxes, and what to tell the people who pay your bills.

What did HP's September threat report find?

The report reviews campaigns HP Wolf Security saw in its customer telemetry during the second quarter of 2026, April through June, per HP's threat research team and Help Net Security. For most offices, the headline is QR-code phishing hidden in PDF invoices.

The report also covered a fake "AI crypto trading agent" spreading an info-stealer called Needle Stealer, and a new malware loader named Phantom Gate. We'll get to those briefly below.

How does the blurred-invoice QR scam work?

The email carries a PDF presented as an invoice, but the content is blurred, supposedly "for security," and a note tells the recipient to scan a QR code with their phone to see it. That's QR-code phishing, better known as "quishing," according to HP, Help Net Security, Cyber Magazine and GSMDome.

Here's the chain, step by step, based on HP's findings and Help Net Security's write-up:

StepWhat the recipient seesWhat's really happening
1An email with a PDF invoice attachedThe lure: invoices are routine for bookkeepers and front desks
2A blurred document, a QR code and a note to scan it with a phoneThe blur is the bait; the QR code is the real payload
3The phone opens a page, then anotherThe QR code runs through several redirect pages
4A Microsoft sign-in page (Help Net Security says it resembles OneDrive)A convincing fake built to capture Microsoft 365 credentials

Why do scammers want you on your phone?

Because a phone usually has fewer defenses than a managed work PC. HP says moving the victim onto a smartphone sidesteps the protections guarding a work computer, so a scam link already blocked on the PC can open freely on the phone. Help Net Security notes that a work PC may have email gateways and browser protections that already block a known phishing domain.

In other words, your email filter can do its job on the PC while the QR code simply walks around it. "We have spam filtering" isn't a complete answer to this one.

Where do office printers and scanners come in?

A QR code doesn't care whether it's on a screen or on paper. Printing a suspicious invoice, or scanning a paper one into a shared folder, keeps the same code pointing to the same site. That makes the office MFP and its scan-to-email workflow part of the story:

  • Printing doesn't disarm it. If someone prints the "invoice" to deal with later, the printed QR code still leads to the same phishing page, now sitting in a paper inbox.
  • Scan-to-email and scan-to-folder copy it. Once a document with a QR code is scanned into a shared folder or sent to a shared mailbox, everyone with access has a copy of the code.
  • Shared inboxes multiply the odds. An invoice sent to a shared billing or payables address lands in front of several people, and it only takes one of them to scan it.
  • "From the scanner" isn't proof. Our post on how attackers abuse Microsoft 365 Direct Send, one of the ways a scanner can send scan-to-email through Microsoft 365, explains how phishing can be made to look like it came from inside your own organization. A "scanned invoice" that seems to come from your own copier deserves the same QR-code rule.

For more on keeping scanned and printed documents under control, see our secure document printing guide.

What else was in HP's report?

Two items worth a quick look, even if nobody at your office trades crypto:

  • A fake "AI crypto trading agent." Attackers advertised it to spread Needle Stealer, which scans the browser for crypto-wallet extensions such as MetaMask and Coinbase Wallet and swaps them for malicious lookalikes that capture the wallet password, per HP, Help Net Security and Netzwoche.
  • Phantom Gate. HP identified a new malware loader by that name that appears to extend the Phantom Stealer campaign, according to HP, Cyber Magazine and IT Brief.

The office takeaway: staff shouldn't install "AI assistants" or trading tools on work PCs, and everyday accounts shouldn't have the admin rights that make installing them easy.

What this means for San Fernando Valley offices

Any Valley business that pays vendors by invoice should take this one seriously, from law firms and medical billing offices to property managers and production accountants. Nothing about this trick is tied to one region: an emailed invoice reaches a Woodland Hills bookkeeper as easily as anyone else.

The weak points are the ones most small offices share: one or two people who handle payables, a shared inbox, a scanner that emails PDFs, and personal phones that double as work devices. None of that needs expensive tools to fix. It needs a clear rule, a phone call before paying anything unusual, and a scanner and mailbox setup that doesn't hand every document to everyone. Our checklist of printer security features for small businesses is a good companion, and we work with offices across the San Fernando Valley communities we serve.

What to do now

  1. Make it a written office rule: never scan a QR code that arrives inside an emailed invoice or document. To view a real invoice, sign in to the vendor's portal from a saved bookmark or call the vendor at a number you already have.
  2. Treat "blurred for security, scan to view" PDFs as phishing. Don't forward them to coworkers; report them to whoever handles IT, then delete them.
  3. Verify invoices, and especially any change to payment or bank details, by calling a known contact at the vendor.
  4. Turn on multi-factor authentication for every Microsoft 365 account, using phishing-resistant methods where possible, and include phones used for work email in your security policies.
  5. If someone scanned the code and entered a password, change it right away from a trusted computer, and have IT sign that account out everywhere and review its MFA methods and mailbox rules.
  6. Tighten scanning workflows: limit who can reach the shared payables mailbox and scan folders, and restrict the MFP's scan-to-email to internal addresses where possible. Email authentication (DMARC, SPF and DKIM) also makes your domain harder to spoof; our sister site StopSpoofingMe specializes in it.
  7. Only install software from known vendors, and keep everyday accounts off local admin.

Want help locking down scan-to-email and your MFP's settings? Book a free virtual consultation and we'll review your setup with you.

Frequently asked questions

What is quishing?
Quishing is QR-code phishing: a scam that hides a malicious link inside a QR code so you scan it with your phone instead of clicking it on your computer. In campaigns HP Wolf Security reported on September 17, 2026, PDF invoices were blurred behind a QR code that led to a fake Microsoft sign-in page.
Why would a PDF invoice be blurred behind a QR code?
It's a lure. HP Wolf Security found phishing emails with PDF invoices blurred "for security" that told recipients to scan a QR code with their phone. Moving the victim to a phone sidesteps the email filters and browser protections on a managed work PC. Treat any invoice that asks you to scan a code to read it as suspicious.
Is it safe to scan a QR code on a printed or scanned invoice?
Treat it with the same caution. Printing or scanning a document doesn't change where its QR code leads. If an invoice asks you to scan a code to view or pay it, go to the vendor's website or portal from a bookmark you already trust, or call the vendor at a number you already have.
What should I do if I entered my Microsoft 365 password after scanning a QR code?
Act right away. Change the password from a trusted computer, tell whoever handles your IT, and ask them to sign the account out of all sessions and review its MFA methods, forwarding and inbox rules. Warn coworkers who received the same email, and watch for unusual sign-ins or payment requests afterward.

Sources

Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.

  1. HP Research: Cybercriminals Leaning into Agentic AI Momentum to Steal Crypto Wallets — HP Inc., 2026-09-17
  2. HP Wolf Security Threat Insights Report: September 2026 — HP Wolf Security, 2026-09
  3. Fake AI trading agent research (HP Wolf Security report coverage) — Help Net Security, 2026-09-17
  4. Cybercriminals using agentic AI momentum to steal crypto wallets — Security MEA, 2026-09-17
  5. HP Wolf Security: Phantom Gate, Needle Stealer and Quishing — Cyber Magazine
  6. HP Flags Fake AI Crypto Agents and QR Phishing in Latest Threat Report — GSMDome
  7. HP warns of AI lures, QR phishing targeting crypto — IT Brief
  8. Cyberkriminelle ködern Krypto-Nutzer mit gefälschten KI-Trading-Agents — Netzwoche, 2026-09-21

About Valley Printer Pros Team

Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.

Get Expert Advice

Related Articles

security
September 2026 Patch Tuesday: Critical Windows Print Flaw Fixed

Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.

Sep 14, 20267 min read
security
PaperCut NG/MF Zero-Days Exploited: What Offices Should Check Now

On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.

Aug 31, 20267 min read
security
Sharp and Toshiba Copier Flaws: Turn On User Authentication

On July 31, Sharp and Toshiba Tec disclosed three flaws in their office MFPs, and NIST's vulnerability database published them August 3. The most practical one: affected models built for markets outside Japan, including the US, shipped with user authentication turned off. Turn it on, and ask your dealer for the firmware that fixes the other two.

Aug 10, 20268 min read

Need Help with Your Printer Decisions?

Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.