![]() |
| What is phishing QR code and how to protect yourself from it |
The scannable shortcut from which we almost farewell has made a dramatic comeback, thanks to all the global epidemics. Yes, you guessed it right - I'm talking about the QR code. Trends such as social interaction guidelines and 'contact-everything' have made pixelated mosaics popular and their slow, simple use only makes their case stronger. Introduced only to track product listings in the 1990s, their versatile use has come a long way from them - from scannable restaurant menus, to customer engagement with the brand, and even faster in Hawaii. Until the airport check-in. Perhaps, their widespread use is in the contactless ecosystem - 'scan the QR code below and pay'. A QR (Quick Response) code is a two-dimensional barcode that is easily read by a smartphone - you need a camera and an application to read the code. This is all very well, but from here my anxiety begins - they can be very simple to generate, but identifying what is hidden in them is the hard part. Although they have emerged as a convenient way to promote contactless technology, users lack the necessary knowledge about how to identify a fraudster.
While new forms of payment mean greater scope for confusion while over-the-counter scanning reduces risk, scammers have found new, creative ways of deception. One way to do this is to send people with texts like a QR code like 'Congratulations for winning Rs 5,000'. The message will request you to scan the code, enter the amount, after which you will receive cash from your UPI PIN in your account. In this scam, Bhola people believe that it will deposit money in their account, but it is just the opposite. You do not end up 'receiving', but actually pay the amount to the fraudster. Another strategy is by embedding fake QR codes through phishing emails, text or social media. Upon scanning the fake code, users are directed to websites with realistic-looking landing pages, where the victim may be prompted to login by entering PII (Personally Identifiable Information). A forged QR code has the ability to connect to unsecured Wi-Fi networks or to automatically navigate to a malicious link. Phony codes can also take you to websites where malware can be downloaded automatically and also used to steal sensitive information from your device or transfer spyware or viruses.
Public QR codes (such as fuel stations or kiosks) also pose a problem as cybercriminals can replace their own QR codes in place of real ones to create money flow to their account. The problem is that there is no way to read the information contained inside the code before exposing the device to unsalted code. While defending you, this type of fraud is relatively unconventional, with the technicalities of QR codes having few secrets for most users, making them potentially dangerous. Our predictions for 2021 highlight that hackers will increasingly use these QR schemes and broaden them using social engineering techniques. When making payments or transactions using QR codes, it is also important to pay attention to small details. It is best to pay using them, only in a safe and familiar environment. Remember that the risks of scanning unknown QRs are like clicking on links in unknown messages - treat a QR code like any other link - if you do not fully trust the source then do not follow it. Once you scan the QR, a pop-up should appear to see its embedded URL.

0 Comments