Phish of the Week
July 13, 2026

Phish of the Week 13th of July

Phish of the Week 13th of July
# Phish of the Week
# Phishing

Bupa Group Healthcare Impersonation - QR & Device Code Phishing

Mette Luntama
Mette Luntama
Phish of the Week 13th of July

Phish of the Week: International Health Clinic Impersonation with QR Code & Device Code Phishing

This Phish of the Week features a fake prescription notice impersonating an international health clinic. The email uses a QR code to launch a device code phishing flow, sent through a legitimate third-party survey tool to slip past filters. The end goal is full access to the recipient's Microsoft account, without the attacker ever seeing or stealing a password.

How the attack works:

The email tells the recipient that their clinician has issued a new prescription and presents a QR code, a technique also known as quishing as the way to view the prescription details. The layout mimics a standard patient notification, complete with a prescription ID field and a note that the prescription can be filled at any pharmacy.
The message is sent through Microsoft's Forms Pro survey tool, a legitimate third-party platform that lets the email inherit a trusted Microsoft sending domain and slip past filters that would otherwise flag an unfamiliar sender.
ďťż
Scanning the QR code opens a page hosted on a domain unrelated to the impersonated health provider. The page displays a "Verify your identity" prompt and a preview of a PDF file.
Next, the page displays a "verification code" and instructs the recipient to open a Microsoft sign-in window, enter the code, and authenticate. In reality, this code is not a security check. It is a genuine Microsoft device authorization code, generated by the attacker to register their own device. When the recipient enters this code on Microsoft's real sign-in page, they unknowingly grant the attacker's device an authorized, logged-in session on their account.
ďťż
Because the sign-in itself happens on Microsoft's real domain, the recipient goes through an authentic-looking flow, including "Pick an account" and "Are you trying to sign in to Microsoft Office?" prompts. The final screen confirms the sign-in was successful and instructs the recipient to close the window. At that point, the attacker's device holds an active, authorized session on the account.
ďťż
ďťż

Why the attack works:

The attack builds legitimacy in layers rather than relying on one convincing detail. Choosing a large, internationally recognized health clinic widens the pool of plausible recipients, since the likelihood of reaching someone who recognizes or has used the service increases with how widely known the brand is. The third-party sending platform avoids obvious sender red flags, and the entire authorization step takes place on Microsoft's actual login infrastructure rather than a spoofed copy of it.
The QR code adds an early hurdle of difficulty, since it is typically scanned on a phone, a device that is often less monitored by corporate security tooling than a managed laptop. This separates the point of compromise from the environment where detection is most likely.
Device code phishing specifically exploits the gap between what a recipient expects a "verification" step to look like and what it actually authorizes. Most people are used to entering codes to confirm their own identity, not to recognize that a code can instead grant a separate device full access to their account.
The absence of urgency also works in the attackers' favor. A calm, administrative-sounding notice about a prescription does not trigger the skepticism that a message demanding immediate action would, making the recipient more likely to follow each step without questioning why a prescription notice requires a Microsoft sign-in at all.

How to spot similar attacks:

  • The sender address does not match the domain of the health provider it claims to represent
  • A prescription or medical notification arrives unexpectedly by email rather than through the provider's own patient portal or app
  • A QR code leads to a site unrelated to the health provider or any official patient portal
  • The flow asks you to copy a code from one page and paste it into a separate Microsoft sign-in window
ďťż
ďťż

What is Phish of the Week?

Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.
Comments (0)
Popular
avatar
ďťż
Dive in

Related

Content
Phish of the Week 06th of July
By Mette Luntama • Jul 6th, 2026 • Views 31
Content
Phish of the Week 15th of June
By Mette Luntama • Jun 15th, 2026 • Views 101
Content
Phish of the Week 29th of June
By Mette Luntama • Jun 29th, 2026 • Views 13
Content
Phish of the Week 22nd of June
By Mette Luntama • Jun 22nd, 2026 • Views 27
Content
Phish of the Week 06th of July
By Mette Luntama • Jul 6th, 2026 • Views 31
Content
Phish of the Week 29th of June
By Mette Luntama • Jun 29th, 2026 • Views 13
Content
Phish of the Week 22nd of June
By Mette Luntama • Jun 22nd, 2026 • Views 27
Content
Phish of the Week 15th of June
By Mette Luntama • Jun 15th, 2026 • Views 101
Privacy Policy
Your Privacy Choices