The email looked completely normal. It came from someone she knew and worked with. Attached was a PDF, and inside the PDF was a QR code. She scanned it. And that was all it took.

The heist nobody saw coming

The action unfolded in seconds. The damage took days to contain. And this was no small target: a substantial business that forms part of a publicly listed global holding group*.

On the employee’s phone, the QR code opened what looked like the company’s network login page. She typed in her username and password. The attackers, watching live on their own server, captured every character in plain text.

Then came the next move. A multifactor authentication (MFA) prompt appeared on her phone. She hesitated and dismissed it. Another prompt followed. Then another. Eventually, worn down, she approved it. The attacker was in.

It didn’t stop there. Within moments, an automated rule was written into her Outlook inbox to mark every incoming email as read and move it straight to Deleted Items.

Meanwhile, the attacker scraped her Sent folder and address book for thousands of contacts, renamed the original PDF, and sent the same malicious email to more than 3 000 people. Replies from recipients who were suspicious were never seen: their emails went straight to her Deleted folder.

The threat spread like Covid-19, says the Cape Town-based cybersecurity practitioner who investigated the breach: one person infected, passing it on to others without knowing the danger. Hundreds of recipients scanned the same QR code. Hundreds more sets of credentials were harvested and put up for sale on the dark web, with a batch of corporate logins fetching around $20 000.

All of it was triggered by one legitimate-looking email from someone she already trusted.

Why it worked, and why you are the target

None of this required a sophisticated technical intrusion. No password was guessed, no firewall forced. The attacker needed only a familiar name in an inbox, and the human habit of trusting it. That is social engineering – and why one of today’s most advanced threats isn’t malware, but a well-crafted message to the right person at the right moment.

Hiding a QR code in a PDF is a growing tactic. Email security tools that scan links often can’t read one inside an attachment. Attackers know this and exploit it.

MFA fatigue is engineered just as deliberately, and it preys on irritation and impatience.

Your three-step verify rule for any suspicious request

This is not an isolated story

Socially engineered cyberattacks are on the rise, even where employees are wary. In 2023, MGM Resorts suffered one of the most expensive attacks on record. Criminals phoned the IT help desk, impersonated an employee and talked their way into the network. The disruption cost an estimated $100 million.

AI is raising the stakes. In 2024, global engineering firm Arup lost $25 million in a single incident. A finance employee queried a transfer request, suspecting a scam. So the criminals set up a video meeting with what appeared to be familiar colleagues and senior executives, all confirming the instruction. Every one of them was an AI-generated deepfake. The money moved across 15 transactions before anyone realised.

The technology is increasingly convincing, but every one of these attacks still depended on a human decision: to scan, to approve, to transfer. That decision point is your most powerful defence.

In 2023, MGM Resorts lost:
$100 million
In 2024, Arup lost:
$25 million

What you can actually do about it

You don’t need to spot a deepfake frame by frame, recognise a cloned login page on sight or have any technical expertise. People who avoid these attacks don’t necessarily have better tools, just better habits – a few simple ones, applied consistently.

The human firewall

Cybercriminals are patient, precise and increasingly automated. They study organisations, map relationships and wait for the right moment. What they can’t plan for is an informed, sceptical employee who pauses before clicking, questions what feels off and acts when something doesn’t add up.

The most sophisticated attack in the world might still need a human to say yes.

• October is Cybersecurity Awareness Month. If you receive any suspicious email or other digital message, please report it at phishing@vodafone.com.

* The names of the individual and the company involved have been withheld for security reasons.