The growing menace of QR Code scams - here's how to stay safe

QR Code
(Image credit: Pixabay)

If you haven't been living under a rock over the past 24 months, the chances are that you would have scanned a QR code somewhere. Even the federal Indian government has pushed hard to get citizens to shift to digital payments, which is convenient as also trackable for tax purposes.

Into this milieu came the QR codes or the quick response codes. These codes were invented in Japan back in the 1990s as a means to manage automobile production. Now, the ubiquitous code is everywhere - from the grocery store to fuel stations and airports to parking lots.  

In fact, there are several websites that allow users to create their own QR codes. Even WhatsApp creates one for you on the fly to make it easier to connect to your account via the browser. This is both a tremendous opportunity as well as a raging problem that could be the harbinger of future scams. 

Now, it turns out that cyber criminals too are watching these developments carefully in the hope of exploiting the convenience that this technology offers. Last October, cyber security firm McAfee had warned of such scams, especially in economies that were migrating big time into digital payments - countries such as India. 

While it is normal for cybercriminals to try to exploit every new technology, it is all the easier when people know how to use one but do not understand how they work behind the scenes, says Angel Grant, VP of security at F5 in a report published on CNET. 

Given this scenario, we take a look at the sort of cybercrimes that the QR code can engineer and how we can skirt around them: 

Common scams involving QR codes

An email or phishing scam - Once upon a time we would warn you of the dangers involved in scanning bogus QR codes to your smartphones by downloading malware. Now, cybercriminals have moved. The codes you may find on scam websites are now designed to capture your bank accounts, credit cards and other personal data. 

Automatic toll booths - A recent scam at the US saw the same QR code being used to dupe drivers pay road tolls or parking tickets online. Instead of taking them to the authorized app, the code took motorists to to a fake website that then collected their credit card details. 

QR codes via email - These innocent looking emails could be from your local police asking to pay up for a traffic offence or your electricity company. Without giving any details of the payment due, it may ask you scan a QR code, only to capture all your data and use it later to fleece. 

Social media - Beware of all types of flyer on social media platforms. For it is well within the capabilities of a hacker to replace a legitimate QR code with a phoney one, just as they can in public locations.  

It is worth noting here that there is no way to look at a QR code to determine it's legitimacy. Of course, you could spot a clever misspell or a typo or better still an adaptation of a legitimate URL, you're lucky. 

Also, the QR codes have the capability of accessing other functions and apps on your handset, with hackers usually tracking them to open your payment apps, contacts lists etc. to expand their scam.

QR Codes - How to stay safe 

QR Code scanned via phone

(Image credit: Metapixel)
  • Do not open QR codes from strangers - Unsolicited messages carrying these codes may lead us to a scam site or provide access to the handset that could be used in nefarious ways in the future. 
  • Check the legitimacy of even legitimate sources - Many of the phishing mails originate from sources that appear legitimate. Check them carefully, including their URL. Also go back to the official website and confirm or contact customer care to counter-check. 
  • Seek alternate payment methods - QR code is usually not the only method of payment a company offers. So, if you get a bill with a QR code, check another option with those that are seeking the payment. A quick check will reveal whether the requested payout is legitimate. 
  • Beware of the shortened URLs - Especially when it is part of a payment activity. Usually these are part of unsolicited communication, which means you can simply delete these emails and breathe. Ironically, it could also purport to come from a friend or family who has got her / his device compromised. 
  • Check before scanning codes - But for QR codes kept in public places like stores where the owner will confirm your transaction, be wary of every other QR code that you find at places without human presence, such as a parking lot in a mall. Do confirm the veracity of the code before swiping it. 
  • Be aware of tampering - One tell-tale sign of a tampering is a QR Code stuck over yet another one beneath. If there is a human presence in the vicinity, it makes sense to double check but if there isn't avoid the QR code like the plague. 
  • Preview the QR code URL - Smartphone cameras could give you a preview of a code's URL as you start to scan it. If the URL looks strange, you might want to stay away. You could also use a secure scanner app to spot malicious links. 

Want to know about the latest happenings in tech? Follow TechRadar India on TwitterFacebook and Instagram

Raj Narayan

A media veteran who turned a gadget lover fairly recently. An early adopter of Apple products, Raj has an insatiable curiosity for facts and figures which he puts to use in research. He engages in active sport and retreats to his farm during his spare time. 

Read more
Google Pixel Scam Detection warning
Common internet scams and how to avoid them
A man falling into a mobile phone screen.
Safer Internet Day: how to avoid online scams and stay safe online
Representational image of a hacker
Email scams vs Phishing - is there a difference?
Ransomware
QR codes can be used to crack this vital browser security tool
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike