The usecure Show Episode 7: The Phishing Scam Hiding in a Voicemail

Published on
August 27, 2026
Read time
5 mins

The usecure Show Episode 7: The Phishing Scam Hiding in a Voicemail

Published on
August 27, 2026
Read time
5 mins
Category
5 min read

The usecure Show Episode 7: The Phishing Scam Hiding in a Voicemail

Published on
27 Aug 26

Table of contents

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

KEY TAKEAWAYS

QR code phishing can bypass familiar email checks by hiding malicious destinations inside an image.

MSPs can reduce repetitive onboarding work with default customer settings that apply across new client tenants.

Episode 7 also covers the Gmail Phish Alert Button, new courses and languages, recent usecure content, and the latest Cyberto prize draw.

QR Codes Lie Too: Discover The Phishing Scam Hiding in a Voicemail

Picture this: a voicemail notification lands in your inbox, asking you to scan a QR code to listen in.

No link, just the code.

It looks harmless enough, but it's exactly the kind of scam we're unpacking in Episode 7 of The usecure Show, and it's one every MSP should be watching for right now.

Is It Spam? Three Emails, One Scam

In this episode, Nihil puts three real emails to the test:

  1. A voicemail notification. 42 seconds. Caller withheld. To listen, scan the QR code.
  2. A Pax8 invoice, with a "view invoice" button linking to the genuine Pax8 portal.
  3. A DPD delivery update, with a tracking link to the real DPD website.

Only one of these is a scam, and it's not the one most people expect. The voicemail is the fake. The QR code hides the destination from your filters and from you, and scanning it leads straight to a fake Microsoft login page.

The rule to remember: a real voicemail either attaches the audio file or directs you to the phone system you already use. It never asks you to scan a code and sign in. If a QR code is asking for a login, treat it as a red flag almost every time.

Interestingly, the two "real" emails in this test, the Pax8 invoice and the DPD delivery, are proof that legitimate messages can look just as suspicious as scams. That's exactly why teaching your clients the underlying rule matters more than teaching them to distrust every unfamiliar email.

What Is QR Code Phishing (Quishing)?

QR code phishing, sometimes called "quishing," is a growing tactic where attackers hide a malicious web address inside a QR code instead of a clickable link. It's a simple change with a big impact: most email filters are built to scan links and attachments, not images, so the malicious destination slips through completely undetected.

The scam doesn't stop at your inbox either. Once someone scans the code, they're doing it on their phone, a device that's often far less protected than a company laptop. That one scan jumps straight past your email security, your network security, and lands the user on a fake login page, all in a few seconds.

Reduce Client Onboarding Admin with Default Customer Settings

Beyond phishing, this episode also tackles a common source of MSP admin overhead: repetitive client setup. Sela walks through usecure's default customer settings, which let you configure your preferences once at the MSP tenant level, from preferred domain to default email settings, and have them apply automatically across every client tenant you add from then on.

Instead of repeating the same configuration for every new customer, you set it once and it scales with your client base.

What's New on the usecure Blog

Kerryn also shares a roundup of recent content worth bookmarking, including:

  • a practical guide to human risk intelligence for teams building out their security awareness strategy
  • an explainer on toxic combinations (why stacked risk signals like exposed credentials, weak phishing results and privileged access are more dangerous together than alone)
  • a look at reducing human risk around PCI DSS and card data
  • and a case study on how one MSP partner achieved 99.4% training participation

New Features and Courses

Alex rounds up the latest platform updates, including:

  • A phish alert button, now live for Gmail, so users can report suspicious emails directly from their inbox
  • Two new courses: Passkeys and Physical Workplace Security
  • New language support for Basque and Catalan, expanding gap analysis and auto-enrol training to even more users

Cyberto's Loot: This Month's Winner

Congratulations to Gary Goodson at Grenadier Computing, Nintendo Switch 2 winner.

Didn't win this round? Cyberto's already lined up the next prize, a brand new Xbox.

Every usecure seat you bill keeps you automatically in the running. Enter here.

Watch Episode 7 Now

Whether you're looking to spot the latest phishing tactics, cut down on repetitive onboarding work, or keep your training content current, there's something in this episode you can put to use right away.

Watch Episode 7 here: https://youtu.be/XOu1yWzqrno?si=51eDIouJ9BJ5fauj

BOOK A DEMO

See usecure in action

A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.

Get a Demo

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

QR Codes Lie Too: Discover The Phishing Scam Hiding in a Voicemail

Picture this: a voicemail notification lands in your inbox, asking you to scan a QR code to listen in.

No link, just the code.

It looks harmless enough, but it's exactly the kind of scam we're unpacking in Episode 7 of The usecure Show, and it's one every MSP should be watching for right now.

Is It Spam? Three Emails, One Scam

In this episode, Nihil puts three real emails to the test:

  1. A voicemail notification. 42 seconds. Caller withheld. To listen, scan the QR code.
  2. A Pax8 invoice, with a "view invoice" button linking to the genuine Pax8 portal.
  3. A DPD delivery update, with a tracking link to the real DPD website.

Only one of these is a scam, and it's not the one most people expect. The voicemail is the fake. The QR code hides the destination from your filters and from you, and scanning it leads straight to a fake Microsoft login page.

The rule to remember: a real voicemail either attaches the audio file or directs you to the phone system you already use. It never asks you to scan a code and sign in. If a QR code is asking for a login, treat it as a red flag almost every time.

Interestingly, the two "real" emails in this test, the Pax8 invoice and the DPD delivery, are proof that legitimate messages can look just as suspicious as scams. That's exactly why teaching your clients the underlying rule matters more than teaching them to distrust every unfamiliar email.

What Is QR Code Phishing (Quishing)?

QR code phishing, sometimes called "quishing," is a growing tactic where attackers hide a malicious web address inside a QR code instead of a clickable link. It's a simple change with a big impact: most email filters are built to scan links and attachments, not images, so the malicious destination slips through completely undetected.

The scam doesn't stop at your inbox either. Once someone scans the code, they're doing it on their phone, a device that's often far less protected than a company laptop. That one scan jumps straight past your email security, your network security, and lands the user on a fake login page, all in a few seconds.

Reduce Client Onboarding Admin with Default Customer Settings

Beyond phishing, this episode also tackles a common source of MSP admin overhead: repetitive client setup. Sela walks through usecure's default customer settings, which let you configure your preferences once at the MSP tenant level, from preferred domain to default email settings, and have them apply automatically across every client tenant you add from then on.

Instead of repeating the same configuration for every new customer, you set it once and it scales with your client base.

What's New on the usecure Blog

Kerryn also shares a roundup of recent content worth bookmarking, including:

  • a practical guide to human risk intelligence for teams building out their security awareness strategy
  • an explainer on toxic combinations (why stacked risk signals like exposed credentials, weak phishing results and privileged access are more dangerous together than alone)
  • a look at reducing human risk around PCI DSS and card data
  • and a case study on how one MSP partner achieved 99.4% training participation

New Features and Courses

Alex rounds up the latest platform updates, including:

  • A phish alert button, now live for Gmail, so users can report suspicious emails directly from their inbox
  • Two new courses: Passkeys and Physical Workplace Security
  • New language support for Basque and Catalan, expanding gap analysis and auto-enrol training to even more users

Cyberto's Loot: This Month's Winner

Congratulations to Gary Goodson at Grenadier Computing, Nintendo Switch 2 winner.

Didn't win this round? Cyberto's already lined up the next prize, a brand new Xbox.

Every usecure seat you bill keeps you automatically in the running. Enter here.

Watch Episode 7 Now

Whether you're looking to spot the latest phishing tactics, cut down on repetitive onboarding work, or keep your training content current, there's something in this episode you can put to use right away.

Watch Episode 7 here: https://youtu.be/XOu1yWzqrno?si=51eDIouJ9BJ5fauj

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Discover how professional services firms reduce human risk with usecure

See how IT teams in professional services use usecure to protect sensitive client data, maintain compliance, and safeguard reputation — without disrupting billable work.

Related posts

Explore more insights, updates, and resources from usecure.