Product1 distinct publisher3 min readPublished
Fast Company's roundup of four working email scams includes three that never show a link worth hovering over, which leaves both the awareness module and the mobile device policy answering a question users no longer face.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Quishing needs one thing from the person reading the mail: a willingness to change devices mid-task. Scanning a code with a phone camera is an ordinary instruction in ordinary work, and the technique borrows that habit rather than defeating a control. According to Fast Company, the protections sit on the laptop in the form of corporate firewalls and link-checkers, and the personal mobile browser has none of them [4]. The moment worth training is the handoff, not the wording of the email.
I counted the four techniques in the piece against the one check awareness decks lean on hardest. Only the cloned login portal puts a suspicious domain in front of the user at the point of compromise [1]. The QR version replaces the clickable link with a graphic [3]. ClickFix's payload is a string the user pastes into the Windows Run prompt after a fake rendering error [6]. The invoice's payload is a phone number inside mail that Intuit or Google genuinely sent [10]. So exactly one of the four remedies Fast Company prints is "verify the domain in the address bar" [2]. The other three are rules about withholding an action rather than judging one: skip scanning a work code on your own device [5], leave browser text out of a terminal [7], and put the phone down instead of dialing the number on the invoice [11].
That is the gap between what a security module teaches and what these four require. The module teaches message judgment. Three of the remedies are rules about physical actions, and a rule about actions needs a mobile device policy behind it, not a slide.
The limits of the evidence are worth naming. This is a single roundup, and it carries no incidence figures and no dated cases [4], so the list describes techniques rather than giving you volumes to budget against. What it does give you is checkable: each named technique implies a control, and you can go and see whether you have it.
The adversary-in-the-middle description is the one for anyone who has just finished a two-factor rollout. The six-digit code was entered correctly, the real site accepted it, and the attacker took the session cookie the site handed back [8]. The prize was the session rather than the credential, which puts the useful control where sessions are validated rather than at the login prompt.
Two axes hold this together. Down the side: does the step happen on a device you manage. Across the top: does the attacker need the credential or the session. Awareness content genuinely covers the managed-device, credential-theft cell, and it is the only cell it covers well. The QR case sits in the unmanaged row, which content cannot reach and policy has to [4]. The cookie case sits in the session column, where no slide helps [8].
The forcing function is cheap to run: matching each bullet in the current module against the technique it actually stops shows which ones have survived only because they have always been there, and matching each login flow against the device expected to finish it shows where the policy contradicts itself. Where that device turns out to be the employee's own phone, "never scan a work code on a personal device" [5] is a rule the login flow itself breaks first, and awareness content cannot fix that on its own.
Ranked by verification strength, evidence, and original report placement.
In the technique Fast Company calls quishing, an email claims a Microsoft 365 password is expiring or an urgent HR DocuSign document needs signing, and instead of a clickable link it shows a QR code asking the recipient to scan it with a phone camera to verify identity.
Fast Company says the work laptop is heavily guarded by corporate firewalls and link-checkers, and that scanning the code with a phone leaves that protected umbrella entirely, loading a malicious page in a personal mobile browser with zero security filters.
Fast Company says that for the last decade corporate IT departments have handed out the same advice: look for bad grammar, hover over links, and turn on two-factor authentication.
Fast Company's remedy for the QR technique: if an unexpected email asks you to scan a code on your personal device to handle workplace credentials, treat it like a live grenade.
In the ClickFix technique, a web page shows an official-looking rendering-error pop-up asking the user to press Win + R, paste a provided verification code into the Windows Run prompt and hit Enter, which executes malicious code the scammer placed on the clipboard.
Fast Company's remedy for ClickFix: never paste text from a browser into the computer's command terminal because a website asked you to, since browsers do not need system-level commands to display a file.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
SPF and DMARC records that pass every free checker and stop nothing1 distinct publisher
build
NovaCookies turns an MFA approval into a live Microsoft 365 session for $3201 distinct publisher
security
NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail2 distinct publishers
product
Socure buys the agents that build the fraud case file before the analyst opens it1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One explainer, no case file
The four mechanisms are described coherently and in enough operational detail to be checkable in principle — the clipboard-to-Run-prompt sequence and the session-cookie theft in particular. What is missing is everything that would make them verifiable: no sample message, no researcher, no platform statement from Intuit or Google, and no second outlet. Fast Company is describing techniques rather than reporting incidents, and the description carries the whole weight.
Nothing here to count
We have no basis for a number. The piece says these scams are hitting inboxes right now and never says how many, where, since when, or how the writer knows. There is no vendor telemetry, no takedown figure, no named victim organisation and no date attached to any of the four techniques, so any adoption reading we produced would be invented rather than measured.
Urgency outruns the arithmetic
The overstatement is in the framing, not the mechanics. "Flooding inboxes right now," "treat it like a live grenade" and the attribution of clean grammar to AI all arrive without a single number behind them. Pull those adjectives off and what remains — QR codes that move the login to an unmanaged phone, a clipboard string run by hand, a stolen session cookie, invoices sent from Intuit's own servers — is sober and plausibly understated in its implications for device policy. So: modestly oversold at the headline, arguably undersold in the one place it matters most.
Nobody's product is being sold
Read the four sections looking for who benefits and you come up empty: no security vendor is quoted, no tool is recommended, no affiliate or sponsor appears, and the named companies — Microsoft, DocuSign, Intuit, PayPal, Google — are all cast as infrastructure being abused rather than as sources or advertisers. What pressure exists is editorial: a general-audience business title gains from immediacy, which is the likeliest reason 'flooding inboxes right now' appears where a figure would have gone.
Solid on how, silent on how much
We are fairly confident about what this story says and about the internal tension we surfaced — the four walkthroughs and the four remedies are right there to be counted against each other. We are not confident about scale, trend or the AI attribution, and with a single publisher there is nothing to triangulate against. Half-marks is the honest place to sit: use the mechanics, hold the prevalence.