• About
  • Contact Us
  • Privacy Policy
  • Write for us
Tuesday, August 9, 2022
  • Home
  • Blogging
    • SEO Tips
    • Make Money
    • Affiliate Marketing
    • Social Media
    • Web Hosting
    • Interviews
  • Business
  • Technology
    • Gadgets
    • Mobile
    • Tab
    • Internet
    • Downloads
  • Entertainment
    • Hollywood
    • Bollywood
    • Web Stories
    • Reviews
  • Sports
    • NFL
    • HFL
    • MLB
    • NBA
  • Games
    • Dota 2
    • Valorant
    • Fortnite
    • Among Us
    • Apex Legend
    • Rocket League
  • Featured
    • How to
    • What is
    • When is
    • Who is
  • Lifestyle
    • Fashion
    • Fitness
    • Health
  • Web Series
  • Home
  • Blogging
    • SEO Tips
    • Make Money
    • Affiliate Marketing
    • Social Media
    • Web Hosting
    • Interviews
  • Business
  • Technology
    • Gadgets
    • Mobile
    • Tab
    • Internet
    • Downloads
  • Entertainment
    • Hollywood
    • Bollywood
    • Web Stories
    • Reviews
  • Sports
    • NFL
    • HFL
    • MLB
    • NBA
  • Games
    • Dota 2
    • Valorant
    • Fortnite
    • Among Us
    • Apex Legend
    • Rocket League
  • Featured
    • How to
    • What is
    • When is
    • Who is
  • Lifestyle
    • Fashion
    • Fitness
    • Health
  • Web Series
No Result
View All Result
ONLYLOUDEST
No Result
View All Result

QR code scams are on the rise. Here’s how to avoid getting duped

by Jyoti
January 14, 2022
Reading Time: 6 mins read

READ ALSO

6 Financial Topics That Can Make Others Feel Uncomfortable — and How To Approach Them

How to watch the Bills-Colts preseason game

gettyimages-1293594189

Think before you scan that QR code.


Getty

You see QR codes just about everywhere these days. The square barcodes show up everywhere: real estate listings, TV ads and social media posts touting what look like great deals on must-have items.

The pandemic fueled a surge in the use of QR codes. Seeking to cut down on possible transmission, restaurants replaced physical menus available to all customers with online versions accessible on your own personal phone. Scan that little square and you’ll find out what the house special is.

Get the CNET TVs, Streaming and Audio newsletter

Become a home entertainment expert with our handpicked tips, reviews and deals. Delivered Wednesdays.

Cybercriminals quickly took note and are starting to exploit the technology’s undeniable convenience. Scammers are creating their own malicious QR codes designed to dupe unwitting consumers into handing over their banking or personal information.

“Anytime new technology comes out, cybercriminals try to find a way to exploit it,” said Angel Grant, vice president of security at F5, an app security company. That’s especially true with tech like QR codes, which people know how to use but might not know how they work, she says. “It’s easier to manipulate people if they don’t understand it.”

QR codes — the abbreviation stands for “quick response” — were invented in Japan in the 1990s. They were first used by the automotive industry to manage production but have spread everywhere. Websites and apps have cropped up that let you make your own. 

Now they’re being exploited by cybercriminals in a spin on an email phishing scam. Scanning the bogus QR codes won’t do anything to your phone, such as download malware in the background. But it will take you to scammy websites designed to get bank account, credit card or other personal information. 

Like any other phishing scheme, it’s impossible to know exactly how often QR codes are used for malicious purposes. Experts say they still represent a small percentage of overall phishing, but numerous scams involving QR code have been reported to the Better Business Bureau, especially in the past year. 

Many people know they need to be on the lookout for phishy links and questionable attachments in emails that purport to be from the bank. But thinking twice about scanning a QR code with your smartphone camera isn’t second nature for most people. 

qr-code-screen

A screenshot of the scam website drivers were led to when they used their phones to scan malicious QR code stickers on parking meters in Austin, Texas.


Austin Transportation

Taking advantage of unsuspecting motorists might have been behind the nearly 30 malicious QR code stickers recently found on parking meters in Austin, Texas, which uses QR code technology to let drivers pay for parking online. 

Instead of being taken to the city’s authorized website or app, however, motorists who scanned the scam stickers were led to a fake website that collected their credit card information.

Police don’t know how many people were duped. The department encourages anyone who thinks they may have had their credit card information stolen by the fake website to contact them.

Austin isn’t the only city to experience bogus QR code scams. Officials in San Antonio, Texas, about 80 miles away, issued a warning after spotting similar stickers connected to a fake parking payment website.

QR codes take people from the physical world to the online one. That’s why it makes sense to use them in scam stickers, as well as paper junk mail, said Brad Haas, cyber threat intelligence analyst for Cofense, an email security company. It gets people online that weren’t already.

Haas says scam QR codes are also starting to show up in phishing emails and online ads, a tactic that leaves him scratching his head. “There’s really no reason for someone to pull out their phone and scan a QR code that’s in an email they’re already looking at on their laptop,” Haas said. After all, the recipient is already online with their laptop. Why would a legitimate sender want them to connect with a second device? For that reason, consumers should regard any email containing a QR code with suspicion, he says. 

Still, the phony codes show up in phishing emails, though not as often as tried-and-true tactics, like attachments containing viruses or links to scam websites. Cofense recently spotted a phishing scam targeting German speakers that included a QR code in an attempt to lure mobile banking users.

microsoftteams-image-13.png

A screenshot of a phishing email containing a malicious QR code spotted by Cofense researchers. Note that the QR code has been altered and will not lead to a malicious website.


Cofense

Hackers may like using QR codes in phishing emails because they often aren’t picked up by security software, giving them a better chance to reach their intended targets than attachments or bad links, says Aaron Ansari, vice president for cloud security at the antivirus company Trend Micro.

Even if the success rate is lower, it’s a lot easier to send out millions of phishing emails than it is to physically place stickers on parking meters and bus stops.

What it boils down to is that QR codes are just one more way for cybercriminals to get what they want and yet another threat people need to be on the lookout for. 

“There are so many ways for you to be compromised these days,” Ansari said, “but it only takes one.”

Tips from the experts

Think before you scan. Be especially wary of codes posted in public places. Take a good look. Is it a sticker or part of a bigger sign or display? If the code doesn’t look like it fits in with the background, ask for a paper copy of the document you’re trying to access or type the URL in manually.

When you do scan a QR code, take a good look at the website it led you to, Haas recommends. Does it look like you expected it would? If it asks for login or banking information that doesn’t seem needed, don’t hand it over. 

Codes embedded in emails are almost always a bad idea. Take Haas’ advice and skip these entirely. The same goes for codes you receive in unsolicited paper junk mail, such as those offering help with debt consolidation, Grant says.

Preview the code’s URL. Many smartphone cameras, including iPhones running the latest version of iOS, will give you a preview of a code’s URL as you start to scan it. If the URL looks strange, you might want to move on.

Better yet, Ansari recommends using a secure scanner app, which is designed to spot malicious links before your phone opens them. His company, Trend Micro, offers a free one, as do some of the other big antivirus companies.

But stick to the well-known security companies, he says. Malicious QR scanning apps designed to scrape user information have made it into the app stores in the past.

Use a password manager. As with all kinds of phishing, if a QR code takes you to an especially convincing fake website, a password manager will still know the difference and won’t autofill your passwords, Haas says.

Jyoti

Jyoti

Jyoti Upadhyay is a young digital marketing executive with an avid interest in content writing. She believes that there is something new to learn every day and from everyone. You can find more details about her, here.

Related Posts

How to

6 Financial Topics That Can Make Others Feel Uncomfortable — and How To Approach Them

August 9, 2022
How to

How to watch the Bills-Colts preseason game

August 9, 2022
How to

How to watch Samsung Galaxy Unpacked August 2022

August 8, 2022
How to

‘Vacuuming is actually very healthy’: how to stay active in a wet Covid winter | Fitness

August 8, 2022
How to

How to Naturally Increase Your Breast Milk Supply

August 7, 2022
How to

How to budget realistically for home repairs

August 7, 2022
Next Post

New web series sheds light on the Black experience in Nova Scotia

Nutrisystem

POPULAR POSTS

No Content Available

EDITOR'S PICK

Ransomware attack hits campaign finance firm

Ransomware attack hits campaign finance firm

May 12, 2022

Why you don’t need to like Dungeons and Dragons to love The Legend of Vox Machina

February 25, 2022

Apex Legends season 13 pushes teamwork with a new kind of hero and ranked mode changes

May 6, 2022

Bills’ Josh Allen declines invite to 2022 NFL Pro Bowl: ‘I want to let my body rest and recover’

January 27, 2022

Categories

  • Affiliate Marketing
  • Among Us
  • Apex Legend
  • Blogging
  • Bollywood
  • Business
  • Dota 2
  • Downloads
  • Education
  • Entertainment
  • Fashion
  • Fortnite
  • Games
  • Hollywood
  • How to
  • Internet
  • Interviews
  • Make Money
  • Miscellaneous
  • MLB
  • NFL
  • Reviews
  • Rocket League
  • Search Engine Optimization (SEO)
  • Social Media
  • Tech
  • Valorant
  • Web Hosting
  • Web Series
  • What is
  • When is
  • Who is

About

OnlyLoudest is a Web magazine for Tech Lovers, Bloggers and entrepreneurs. We always share about online marketing and blogging.

ONLYLOUDEST OG

Follow us

Recent Posts

  • 4 Benefits Google Analytics 4 Brings Marketers
  • Hollywood Stargirl, la recensione: un sequel che cresce insieme alla protagonista
  • Valorant patch 5.03 notes: Chamber & Neon changes, Unreal Engine update & more – Dexerto
  • Why I’m Happy to Spend Thousands of Dollars Each Year on Fun
  • Christoph Waltz interpreta la leggenda di Hollywood Billy Wilder nel nuovo film di Stephen Frears
  • About Us
  • Contact Us
  • Privacy Policy
  • Write for Us
  • Advertise With OnlyLoudest

Copyright 2013 - 2021 All Rights Reserved / OnlyLoudest - It's Never been that Simple!

No Result
View All Result
  • Homepages
  • Business
  • Entertainment
  • Tech
  • Downloads
  • Internet
  • Blogging
  • Reviews
  • Education
  • Social Media
  • Tech
  • Make Money
  • Search Engine Optimization (SEO)

Copyright 2013 - 2021 All Rights Reserved / OnlyLoudest - It's Never been that Simple!