What Makes a QR Code Dangerous
A QR code is a link nobody can read before opening it. The threat is not the code but the missing preview: one sticker placed over a legitimate code on a parking meter, a poster, or a printed invoice sends whoever scans it to an attacker's login page, usually on a personal phone that sits outside the organisation's filtering and device controls.
That last detail is what makes this a workplace problem rather than a consumer one. Email links pass through a gateway that can rewrite and check them; a code scanned from a wall does not, and the phone it opens on is frequently unmanaged. Excluded on purpose is any working malicious code: a scannable example, even a screenshot of one, gets reused the moment the video circulates outside the intended audience.
The sequence runs across six scenes: one on why a code cannot be inspected, two on the three places employees actually meet malicious codes, one on the checks that still work before entering credentials, one on what to do after scanning something suspicious, and one on how to report it.

