I’m sure you’ve heard these basics before – don’t click suspicious links, don’t open weird attachments, use strong passwords, and keep things updated. Well, that advice still holds up.
But scams don’t always look like scams anymore. Sometimes it’s a QR code in an email. Often a Teams message that looks like it’s from a coworker. It could even be a login approval that pops up on your phone at the exact wrong moment.
The FBI reported $16.6 billion in losses from internet crime in 2024, a 33% jump from the year before, with phishing and data breaches topping the list of complaints. And those numbers keep climbing. We’re not sharing those stats to scare you, it just means attackers have gotten good at blending into the stuff we do every day.
Here are three not-so-obvious threats worth keeping an eye on.
1. QR codes aren’t as innocent as they look
QR codes are everywhere: menus, event check-ins, invoices, parking meters, flyers. They’re convenient, and attackers know it.
The problem is you can’t see where a QR code leads until after you scan it. That’s harder to catch than a sketchy link sitting in an email. Researchers looking into “quishing” (QR code phishing) found that convenience is exactly why people scan first and think later. In one study, 67% of participants were willing to log in with their Google or Facebook credentials right after scanning a malicious QR code.
That doesn’t mean every QR code is a trap. It just means you should treat them the same way you’d treat a link: if something feels off, or the code showed up somewhere unexpected, skip it and go straight to the company’s website or app instead.
Simple rule of thumb: if you wouldn’t click a random link, don’t scan a random code either.
2. That login approval you didn’t ask for
Multi-factor authentication (MFA) is one of the best ways to protect your accounts right now. A Microsoft-backed study found it cut the risk of account compromise by 99.22%.
Attackers know this too, so they’ve gotten creative. One trick, sometimes called MFA fatigue, works like this: an attacker who already has your password tries logging in over and over, which sends you approval prompt after approval prompt. Eventually, some people just tap “approve” to make the notifications stop.
This one’s tricky because the prompt itself is real. It’s coming from a legitimate app. The problem isn’t the app, it’s approving something you never actually tried to do.
If a login prompt shows up and you’re not the one logging in, deny it. And don’t just ignore repeat prompts – tell your IT team, because that pattern usually means your password is already out there somewhere.
Easy habit to build: only approve logins you started yourself.
3. Scams are showing up outside your inbox
Most of us have learned to be suspicious of email. Attackers know that too, so they’ve moved into places that feel more casual: chat apps, shared calendars, document notifications, video meeting invites, now even text messages.
Recent reporting found hackers have started increasing attacks across tools like Slack, Teams, and cloud platforms, rather than sticking to email alone. One report tracked a 41% increase in Microsoft Teams-based attacks between October 2025 and March 2026.
It makes sense why this works. A message feels more trustworthy when it shows up in a tool you’re already using all day. A “manager” pinging you on Teams or a shared file notice doesn’t raise the same red flags as a strange email would.
AI is making this trickier too. The messages read more naturally now, less like the clumsy scam emails of a few years ago.
So instead of judging a message by who it’s from, pay attention to what it’s asking. Is it asking for a password? A payment? Gift cards? A file share? An install? A move to your personal phone number? Any of those should make you pause.
The pause is the point
You don’t need to be a tech expert to stay safe here. You just need a few extra seconds.
Before you click, scan, approve, or share anything, ask yourself: “Was I expecting this? Can I check it another way?”
Call the person using a number you already have. Start a fresh message thread. Ask IT before installing something unfamiliar.
That small pause is usually all it takes to stop a much bigger problem before it starts.
If you have any suspicions about a possible threat, be sure to reach out to our team to verify for you.