Talos Takes

Don't scan that! QR code phishing and cloud-native threats

Cisco Talos

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 22:25

What happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Attackers are ditching traditional malware for "cloud-native" tactics — using personalized QR code phishing to bypass corporate defenses and operate entirely within the cloud.

Beyond the technical details, Amy and Terryn chat about the pressure of defending environments where patient care is on the line and why a blameless culture is a great defense. Take a listen for some practical, down-to-earth advice on how to audit your own logs and keep your team prepared for when things go sideways.

Talos IR Trends Q2 2026: https://blog.talosintelligence.com/ir-trends-q2-2026/


Amy Ciminnisi

Welcome to the Talos Takes Podcast, where we discuss Talos' latest research and security news. This podcast is for everyone, from the C suite to the front lines. Hello, everyone, and welcome to Talos Takes. I'm your host, Amy Ciminnisi. Today is a very exciting episode for me because we are examining a real incident that Talos Incident Response faced last quarter. It impacted an Australian medical center, and it really shows how attackers are bypassing defenses by operating entirely within the cloud. We are going to discuss a few things. First, the rise of QR-based phish. Second, the challenges of securing non-corporate devices. And three, the human impact of defending these high-stakes environments. So joining me to walk through the investigation is senior incident response consultant Terryn Valikodath. How are you doing?

Terryn Valikodath

I'm doing well. How about yourself? It's been a little bit since I've been on here, but I'm glad to be back.

Amy Ciminnisi

I know. I'm very glad to have you back. Uh, listeners, you may know Terryn from an episode of Humans of Talos that we released several months back. Um, if you want to learn more about his background, uh his love for dinosaur bones and forensic anthropology, uh, go right ahead. Go check that out. Okay. So, Terryn, let's get into this. You worked on this incident yourself, right?

Terryn Valikodath

Yes, that's correct. Yep. I was a part of it, the entire length of it.

Amy Ciminnisi

Wow. I I feel like one of the most interesting things to me about this incident is that it is involving, you know, a medical center where the stakes are higher than, you know, a typical corporate environment, right? Because people's lives can be on the line. Um, when you join that initial call, how do you like manage the tension and pressure of knowing that an incident here could impact patient care?

Terryn Valikodath

Yeah, no, it's a it's a huge kind of undertaking to realize sometimes that what's going to happen could actually impact things to that degree, um, especially having someone, uh, my wife that actually works in healthcare as well. They know it too far too well of how much that can be a disruption. Um, but realistically, I I don't think it changes too much. Um, I think it really is about just making sure that you kind of remain even more calm and collected because oftentimes the people that we're working with, they don't have that luxury. So we need to make sure that we can for them and kind of explain exactly what we're going to do. And when we're talking about medical, I think it really comes down to understanding um impact, like what is truly going to be impacted, and knowing that there might be things that they just cannot risk, that they might need to make decisions that maybe a different enterprise would say, no, let's hold off on that. But for them, it's critical and they need to take that risk. So being very thorough about what exactly you're finding and giving clear recommendations and alternatives, um, I think is is really what comes up in those types of cases.

Amy Ciminnisi

Um, and so in this case specifically, there was a very specific, highly personalized lure uh that kind of opened the door to compromise. Can you walk us through, you know, what did that initial email to the employee look like? Uh, how how was it able to bypass those typical red flags that we are trained to look for?

Terryn Valikodath

Yeah. Um, so the email was a little bit different because it came in as a phishing email that I'm sure everyone is familiar with. Um, it pretended to be um a payroll adjustment, so to capture kind of the employee's attention right away. Um, but the unique thing was that it had a PDF attachment, which is also not unusual. But within the PDF was actually where we see the QR code. And that's where it kind of changes things up a little bit because when you see a QR code, people naturally want to scan it. And you're not scanning it with the device you're using, you're scanning it with a mobile device.

Amy Ciminnisi

Yeah.

Terryn Valikodath

Um, so what happens in that case is the user scans it with their mobile device, they get the fake login page like we see over and over again. But the problem being it's on a device that doesn't have the same protections, uh, that's not as visible to the organization. So when they put in those credentials into that page, uh, everything is kind of happening almost offline. Uh so it presents a much bigger challenge uh because the adversary on the other side, they're kind of using that information live. They're taking those logins, trying to log in directly. That's going to maybe prompt MFA for the user, which they would expect. They just put credentials in. So it looks very normal from their standpoint. So when you lack the visibility from an organization security standpoint, you would have no idea. Um, it's just something that kind of happens completely offline, but from the attacker perspective, you know, it's everything they would need to get in. Um, and the victim just is completely unaware, uh, all because it's on a separate device.

Amy Ciminnisi

I'm curious how we need to change how we're thinking about like corporate owned versus personal device security. Like, obviously, uh, you know, you can't put all of these security controls on people's personal devices who are your employees. Um wow, big issue. Um, but like what can we do to try and like mitigate that risk that the situation present presents?

Terryn Valikodath

Yeah, I think it's it really comes down to like, like you said, it's it's not a feasible task, in my opinion, to be able to get only provide phones that belongs to organizations that have these protections. And even when we're talking about phones in general, uh, we just can't see it the same way we would see a Windows laptop. So even if we did have that, I don't know if it would really change too much in terms of what you can change and do. Um, but I think a lot of it really just come down to the simple answer of just educating people. Like when you see a QR code via PDF, like that's probably something you shouldn't scan. Or like if you're going to interact with anything that's asking for you to log in, make sure it's on those kind of approved devices or going through a certain method. Um, it's a really tough situation to kind of get around. I think it's one of those avenues that clearly shows threat actors are just getting more and more savvy by just kind of taking advantage of how we do our everyday life. It's not like they're doing some crazy exploit or doing some ultra-technical task. Uh, it's really just watching, observing how people do their day-to-day and then seeing where they can kind of insert themselves. Uh, so there's unfortunately not an easy answer. I think it's really just uh a matter of educating, hopefully, like we are now, so you know that these types of things can occur and what they could potentially lead to.

Amy Ciminnisi

As an incident responder, this QR code phishing, we have put out like a few different articles and such about it over the years. Um, but like how how often do you see that pop up in your incidents? Is it often, is this kind of the first case in a while that you've seen? Um, and how how prevalent is it really that we know of?

Terryn Valikodath

Yeah, I would say it's pretty recent that it's becoming more notable. Um, I'll admit, like maybe five years ago, the the idea of QR code phishing was kind of like this anomaly, even for myself, of like, yeah, sure, it's technically possible, but how would that actually be done? Yeah. Uh, but now we're kind of seeing, like, yes, it can clearly still be done. Um, and that inherent trust is still there. And I think the the difficulty and the scary part is if it happens, you won't necessarily know what's happening unless you're talking with the user. You can kind of do that comparison, you can look at those emails yourself. So, yeah, it's definitely something more recent, I would say. Um, it definitely was not top of the radar before like it is now, but now I think it's clearly shown that um it can still work um and it can lead to some pretty crazy stuff, even though uh it's relatively simple and it might be one of those things that people scoff at when they first hear about it.

Amy Ciminnisi

Yeah, adding that into your employee training is just so necessary now.

Terryn Valikodath

Yeah. Yeah, and I think also a point to anyone that's doing those education trainings, being able to show what it can lead to, I think is a really good way to emphasize it. Because everybody knows phishing exists, but I think until you kind of put into the frame of what can happen as a result of your account being compromised, um, is a is a good way to put it forward rather than folks just kind of assuming that, oh, they don't need my data, so they're not gonna go after me. That's not really what it's about in a lot of these cases.

Amy Ciminnisi

100%. Yeah. Okay. So let's talk about um how this kind of took place within Microsoft uh cloud products, right? Nothing ever touched, you know, an internal workstation or a server. Um can you kind of talk about that and what that means for like hunting for evidence?

Terryn Valikodath

Yeah, absolutely. So in this case, what we saw is as soon as they got those credentials, they they logged in using that user's information. Um, and from that point, um, all they really did was go into things like SharePoint. Uh we didn't see it, but they could access things like OneDrive or anything else that uh you would kind of work with your day-to-day type of work for documents and things like that. Um, but the interesting thing we saw with this is they actually accessed uh SharePoint and they tried to stage one of the SharePoint sites as another phishing link and then invite as many users as they can, from what we can tell. I think just their entire contact list. So this is internal users and even other companies. Um, so they're just blasting this out to as many people as possible. Luckily, I think that was blocked, so it didn't get to that point. Um, but you can see them kind of trying to do this worming of get into one location, expand out, and just keep going and going and going until they can hit as many as they possibly can. Um, but like you said, the the interesting thing is they never touched, you know, a user's desktop, they never accessed someone's server, they never really got into what we would traditionally think of uh of a hack. Um they're really just staying within the account, uh within SharePoint, within these Microsoft products that are just all online available. Uh so it does introduce some complexities in investigating too, because uh some of these things are not by default set up to show you every little thing that happens. Um, so there is a lot more inference you have to make, there's a lot more details you have to kind of extract from different locations rather than something as clear as like a Windows event log that's gonna clearly tell you here's what this user account did from A to B. Uh so doing that kind of comparison is becoming more of a skill that we're realizing you need to keep up uh because those things change so often. And Microsoft also likes to change, you know, how they log certain things or what they're doing. So being on top of what you can actually see uh is half the battle, in my opinion.

Amy Ciminnisi

Kind of a recurring theme over the past several Talestakes episodes that I've noted is the idea of bypassing MFA and traditional MFA not always being enough. Um you mentioned that we don't have the exact play-by-play of you know the user's screen and you know what they saw, but we do know the outcome that the adversary got in. Um what are some of the signs that an adversary is abusing a session in the cloud? And you know, what what should teams be looking for in their logs to try and catch this a little bit earlier?

Terryn Valikodath

Yeah, no, great question. Um, I think one of the first things we often look for is the sign-ins to see are they suddenly signing in from uh a new country or kind of a new uh range IP range that you wouldn't expect. Other things we commonly look for is new devices being registered. Uh, one common thing we like we see adversaries like to do is once they get into someone's account to kind of retain that access, they'll register their own phone or a different device that can take the MFA request from that point on. And then um uh if you really want to get down to technical details, if you look into uh token usage, um, you can see very clearly in some of the logs that uh when a token is being reissued or it's being reset, or maybe they're using the same one over and over again in different sessions where that isn't typically the case. Uh so yeah, a lot of it is coming down to just those anomalies and discrepancies. Uh, but I think the biggest challenge you'll have is making sure you have some kind of understanding of what the normal is. Where are they typically logging in from? You know, do they live in multiple locations? Is there a reason a different IP address may pop up? Uh so it does take a lot of coordination either with the user themselves or just kind of an understanding of what's going on in the environment. So you can clearly show that this is an anomaly because you'll be surprised how many uh uh false positives you'll see just because people use VPNs, people might be untraveling and accessing things on their phone. So uh it is definitely a little bit of a game of understanding the common behaviors, and then you can do a better job of looking for those anomalies.

Amy Ciminnisi

So once organizations catch that first indicator, um, you know, they look into it, they triage it, um, and determine that it's something that they need to look into and open an incident. What are the steps that you take to remediate something like this? Um, and how do you know when the environment is sufficiently normal enough to close out the incident?

Terryn Valikodath

Yeah. Um, so the first thing I think anytime you see activity like this where someone's account's being compromised is having a very quick way to either disable the account, reset the password, revoke the sessions, which all of that is built into Microsoft tools, so it's not too difficult, but making sure you can do it as fast as possible. Um, and I think the next thing that we often run into is being able to provide access to say us or anyone else that's going to help investigate. Um, sometimes it's the first time organizations will do this, so they don't have a clear idea of how to provide external access. Uh, we of course help out with that, but knowing that ahead of time can certainly speed things up. Or if you know, you know, which logs we need to grab, it can extract those ahead of time. Those types of steps um go a long way. Um, but yeah, really a lot of it is just looking at those discrepancies, um, not being afraid to kind of do a little bit more if you have to, right? Um, in some cases we see like this, uh maybe there was multiple users that were involved in that invitation. Uh, you might just take that precaution. Let's just reset the password for all of them. You know, even if we don't see a clear that sign in or some other type of evidence, uh, being able to take those actions is always best. I mean, as much as we love to preserve evidence as much as possible, at the end of the day, we want to make sure things don't get worse. So we would much rather you take action and we lose a little bit of evidence than waiting too long and things get worse before any action is taken at all.

Amy Ciminnisi

Yeah, 100%. Um, and I can't help but think about both the IT teams of the organization and also like the person who fell victim to the phishing link. I feel like there might be kind of a knee-jerk reaction to blame that person and to assign that blame. Um, from your perspective, how do you kind of steer leadership or steer whoever you're communicating with toward kind of more of a blameless and educational culture that focuses on those educational improvements rather than you know pointing fingers at people who didn't know or maybe were a little bit careless in a situation like this.

Terryn Valikodath

Yeah, absolutely. Uh yeah, we I don't think you can ever really blame a user in those situations. When we're talking about the situation like right here with the QR code, yeah, it's so hard to imagine something like that would even happen. Um if you're thinking about your work every day and then something like this occurring, that's not even close to the top of your mind if you're working in accounts payable, HR, wherever else. Um, so of course, it's not really their main concern. But um, yeah, I think a lot of it is just sharing more. I think it really does just come down to just being more upfront about when you see these things even happening in the organization. So, example with this one, uh, as soon as we saw this, we asked them, like, hey, is it worth just issuing a communication to the rest of your um organization about, hey, this has happened, watch out for it. Just so when you see that, people feel more willing to kind of come up to you and tell you those things. Because I'm sure there's situations that happen that just nobody reports, nobody mentions that it's actually occurred until it gets to a point that it feels very uh it feels the need to blame someone.

Amy Ciminnisi

Yeah.

Terryn Valikodath

But usually that means there could have been a proactive measure, whether that's just educating people more about what's going on. And sometimes it's more about making it more interesting on how you're educating people, because nobody likes doing the annual training sometimes. So you might have to be a little bit creative on how you're sharing information, what you're sharing with them, um, and finding those people that do care and you know, doing the other approach for them of and uh encouraging them more, like finding those folks that do report to you a lot and finding a way to kind of loop them in more and use that to your advantage, as opposed to pushing people away that um are you know willing to kind of give come forward with that type of thing. So it is a it's it's always going to be a push-pull. I think it's always gonna be a reason uh why these things are so complicated. And I think it also ties back to understanding your environment more, right? If you can just understand the typical user behaviors, then you can kind of see those discrepancies a little bit faster. You can alert on those types of things rather than seeing it appear for the first time, it's clearly a bad thing, and just blaming the user. Uh, there's always other things that you can do, even though they're not the most fun or easy.

Amy Ciminnisi

Yes. Yeah. And and as you said, like these kinds of incidents can happen to anyone, any organization. And so, like for the practitioners who are listening to this, looking at their own environments and wondering if that could happen to them, um, as a closer, what are the top two or three things that they should be doing or auditing or implementing today to kind of prevent this cloud native attack or at least kind of minimize the blast radius for them?

Terryn Valikodath

Yeah. Um, I think a lot of it is gonna come down to um getting a good feel for what you can actually see in your environment today. So, you know, as soon as you're done with this, go look into your Microsoft um tenant and try to see what kind of logs you can even see. Can you actually view uh someone getting a phishing email, whether it's quarantined, what actions are taken? Can you see whether they clicked on a link, like what kind of detail you actually have? Uh, because at the end of the day, even if something happens, you still want to make sure you can understand what occurred as much as possible. Um, and then in addition to that, uh QR codes are obviously going to be a little bit tricky, but uh it is something you can still account for. Um, it's the same as any other PDF, right? The PDF still had to reach them if it's coming from an external uh entity, if you know, matching on the things like it's calling out payroll. It has a PDF assigned to it, kind of attaching all those behaviors together in a way that can make things a little bit more robust. Um, but I think a lot of it comes down to response. Uh, one thing, you know, I do want to make sure you call out with us is the organization responded quickly. Um, and it didn't really explode into anything horrific, right? It's still an incident, it's still something, of course, they have to learn from and they'll want to make sure things don't get worse. But the reason it didn't get worse was because they were able to respond. They were able to disable that account very quickly. They were able to identify, you know, what this user was actually accessing and what they did to those SharePoint pages. That type of detail will go a long ways because then you feel much more comfortable about the fact that, yeah, I'm gonna disable this account or we're going to turn off access for this user for a little bit. Um, but we have reasons of why we're doing it. We're not just gonna say we're gonna do it, make them angry, and then cause more strife until we get an actual answer. So to me, it all comes down to visibility, what you can actually see. Um, so you know if something like this were to occur, you know you can find it very quickly and hopefully create detections around it before something like that even happens.

Amy Ciminnisi

Well, I guess that's it. Thanks so much for joining.

Terryn Valikodath

Yeah, thank you so much. It was great talking.

Amy Ciminnisi

Well, everyone, if you do want to hear more stories directly from Talos Incident Responders, um, watch for our next quarterly trends report. Um, every quarter we hold a webinar called Tales from the Frontlines. It is an unrecorded 30-minute session where our incident responders talk about the most high impact cases that they saw in the last quarter and give out useful insights on how you can strengthen your defenses. I will put the link to our latest quarterly trends report below. But if you are more of a podcast learner, the previous Tallowstakes episode covered it as well. Thanks so much for listening and stay safe out there.