- Cyber Safety
- Posts
- The QR Code Might Be the Phishing Link You Never Checked
The QR Code Might Be the Phishing Link You Never Checked
Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:
After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.
The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.
“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”
Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.
Phishing Is Moving Beyond the Traditional Link
Attackers can place malicious destinations behind QR codes in emails, documents, posters, invoices, or fake authentication notices — making the actual URL harder to inspect before clicking.
QR Codes Push Employees Onto Personal Devices
Scanning a code often moves the interaction from a protected corporate computer to a smartphone, where security controls and monitoring may be different or weaker.
The Destination Can Look Completely Legitimate
A malicious page may imitate Microsoft 365, Google Workspace, banking portals, or internal authentication screens to capture credentials and MFA information.
AI can build faster. Can your team decide better?
AI can draft the PRD and prototype the idea. Jira Product Discovery helps teams decide whether it belongs on the roadmap. Bring feedback and ideas together, prioritize as a team, and keep your roadmap connected to delivery in Jira.
Familiar Branding Creates False Confidence
Logos, professional formatting, urgent language, and recognizable login screens can make a malicious QR campaign feel like a normal business request.
Traditional Email Training Needs to Evolve
“Don’t click suspicious links” is no longer enough. Employees should treat unexpected QR codes with the same skepticism as unknown attachments and login requests.
Teach Users to Verify the Destination, Not the Design
Encourage employees to inspect URLs before authenticating, report unexpected QR requests, and access sensitive services through trusted bookmarks or official applications. Attackers keep changing the delivery mechanism — the verification habit must remain constant.
Hire Ava, the AI BDR built for enterprise
Ava is the first AI BDR to run outbound end to end, finding leads or ingesting your CRM accounts, sending personalized emails on your reps' behalf, and booking meetings, autonomously or on copilot. She runs outbound for DoorDash and Grammarly. She's SOC 2 Type II audited, SSO and GDPR ready.



