Why do users keep clicking phishing links?
End-users frequently ignore explicit security instructions, blindly entering their credentials simply because a message says 'click here'. Attackers exploit this inattention and bypass traditional red flags like poor grammar by using AI, embedding QR codes in Word documents, and spamming Teams messages. This behavior forces administrators to aggressively block even legitimate files containing QR codes just to prevent breaches.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Moving to passwordless authentication using FIDO2/passkeys
- 2Assuming users will always click links and designing security to protect them from themselves
- 3Configuring email filtering software to strip or block QR codes entirely
- 4Using advanced firewalls or email gateways capable of reading the QR code and checking the underlying link
- 5Training end-users to recognize contextual clues of phishing rather than relying strictly on technical safeguards
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“I've had 3 users so far fall for ai phishing emails... but the are 1 not the brightest twinkle in the sky,,, and 2 not native english speaking so strange grammar isn't easily seen by them”source ↗
“I have dumb users... in a phish test, i sent an email stating not to click links or enter passwords from an email... the a link that said "click here to read the rest of the message" nearly 30% clicked and entered their credentials.”source ↗
“lol so true, i've heard "i didn't read it i just saw click here and clicked" so many times”source ↗
“We have been attacked by this same QR shit too, along with teams message spam and phishing attempts.”source ↗
“Yup, seen this method quite a bit in our environment. Usually seen it embedded in Word Doc.”source ↗
“Most gateways are blocking QR codes so aggressively now even legit PDFs that happen to have one are getting blocked”source ↗
Where this came up
People with this problem also raised
- 4Why am I getting WhatsApp scams with my real travel booking details?
- 4Why does IT send fake phishing emails that stress us out?
- 3How to tell if a BEC attack was caught automatically or by a human
- 5Seller gave me a fake tracking number with a thank you card
- 26Why does visiting Egypt feel like constant scams and harassment?
- 7Getting weird scam letters or emails from banks I don't use