Cybercriminals build fake QR codes out of tiny code tables instead of pictures to sneak past email security and steal passwords.
Cybersecurity researchers have uncovered a tricky new scam where internet hackers use fake QR codes made of tiny computer code boxes instead of regular picture files to trap unsuspecting workers.
Normally, when someone receives an email, security programs scan attached pictures to see if they contain dangerous bar codes.
However, cybercriminals have found a way to draw scannable black and white square codes directly onto the screen using ordinary web page tables.
When a worker opens the email, the computer screen displays what looks like a simple square barcode. The moment the victim scans the code with a smartphone camera, the link secretly takes them to a fake login website designed to steal private passwords and account details.
The technical security alert was documented in threat intelligence reports published on Thursday, September 3, 2026.
Cybersecurity researchers tracked these clever attacks across corporate email networks, noting that bad actors are increasingly using this method to bypass traditional security filters.
Instead of sending attached picture files that trigger automatic alarm systems, the attackers send plain HTML messages containing hundreds of tiny table cells.
Because the email looks like a basic layout document to protective software, the message lands right inside the victim’s main inbox without any warnings.
The primary reason this new hacking trick is so dangerous is that it tricks both security programs and everyday computer users at the same time.
Built in email security tools are trained to look for picture attachments and known virus files. Because there is no picture file attached, the security scanner assumes the email is harmless text.
At the same time, when the victim looks at their computer screen, their human eyes see a clean, ordinary square barcode.
To make the scam look even more convincing, the hackers place the victim’s actual company name inside the website link so people do not suspect anything is wrong when they scan it.
Explaining how cybercriminals build fake barcodes out of simple computer code tables to trick email filters, cybersecurity analyst Tushar Subhra Dutta reported that a recent phishing campaign is abusing QR codes in a new way, “turning simple HTML tables into working codes that redirect users to malicious sites”.
Detailing why traditional computer security software fails to spot these clever hidden code patterns inside standard office messages, Tushar Subhra Dutta added that “instead of embedding a QR image in the email body, the attackers build the code from hundreds of tiny table cells, each styled as black or white”.
See Also: Critical Security Flaw Discovered in WhatsApp Video Call System Allows Remote Hijacking
Warning that security teams must update their defense tools to inspect web layout tables as potential graphic threats, security research teams at the Internet Storm Center noted that “this approach bypasses many QR inspection engines, which are tuned to scan actual image attachments or inline image data”.
By exposing how hackers use invisible code tables to build fake barcodes, cybersecurity experts are helping workers stay safe online.
Double checking web addresses before typing in passwords and avoiding scanning unknown square codes received in unexpected emails ensures that personal accounts, work files, and private bank details stay locked away from internet thieves.

