Bezalu
All newsletters

August 2026: QR Code Scams and How to Stop Email Spoofing

QR codes now show up in menus, invoices, and payment terminals — and scammers have noticed. This issue explains “quishing”: how a malicious link hidden inside an image slips past email filters, why scanning moves you onto an unprotected phone, and the habits that stop it. QR code phishing rose 146% in a single quarter, most of it arriving as PDF attachments. It’s a timely addition to our cybersecurity guidance.

We also show how three DNS records — SPF, DKIM, and DMARC — stop criminals from spoofing email in your company’s name, including the DMARC setting most businesses get wrong (leaving p=none in place). Getting this right protects both your clients and your email deliverability.

Plus: a calm, five-step plan for the first hour of a cyberattack, privacy checks for AI meeting note-takers, why lingering Windows 10 machines are now a real risk, and how passkeys make logins that can’t be phished. Need help hardening email and identity? Talk to us about managed IT services.

In this issue

  • QR code scams (quishing): what they are and how to spot them
  • How to stop scammers sending email in your company's name (SPF, DKIM, DMARC)
  • What to do in the first hour of a cyberattack
  • Who can see what your AI note-taker records?
  • Still on Windows 10? Here's why it's a risk now
  • Passkeys: the login that can't be phished

Read the full newsletter

Your browser can't display the embedded PDF.

Download the PDF instead