Kaspersky experts warn against hidden risks behind QR codes

In today's digital world, QR codes appear on almost everything, from yogurt containers to restaurant menus, museum exhibits, bills, and parking lots. People use these codes to open websites, download applications, collect loyalty program points, make payments, transfer money, and even make donations. This accessible and practical technology is becoming quite useful for many, including cybercriminals. Indeed, cybercriminals are also implementing various fraud methods through QR codes.

12punto

Kaspersky experts list the primary security risks that can be encountered when scanning QR codes as follows:

Phishing and redirection to malicious sites: QR codes can direct users to fake websites designed to steal personal or financial data, such as passwords and credit card information. Attackers can mimic legitimate-looking sites, such as banks or digital streaming platforms, to trick users into entering their login credentials.

Malicious software downloads: Some QR codes can trigger the download of malicious applications that compromise the security of the user's device. This poses a greater risk, especially if the device is not protected against unauthorized installations.

Payment fraud: During campaign periods such as special events or holiday sales, a fake QR code can lead users to make payments to fraudulent accounts.

Insecure automatic connections: A QR code can automatically connect the user to Wi-Fi networks controlled by cyberattackers, thereby allowing communications to be intercepted.

Seifallah Jedidi, Head of Consumer Channel at Kaspersky META, says, "QR codes create an area highly susceptible to manipulation, especially since they appear in various aspects of daily life such as receipts, brochures, and signs. Attackers have almost unlimited options to misuse these codes. While QR codes have become an integral part of our daily lives, it is of great importance that users know how to use them safely and responsibly."

To avoid falling victim to fraud when scanning a QR code, Kaspersky experts offer the following recommendations:

Verify the source: Only scan QR codes from trusted and known sources. Avoid codes in public areas that may have been tampered with.

Check the URL: If you absolutely must scan a public QR code, ensure that the web address you are directed to is legitimate and be cautious before performing any transactions on that site.

Do not share your personal information: If you are not completely sure of the source of the QR code, avoid entering your sensitive information.

Protect your digital life: Install a cybersecurity solution that provides protection against phishing and fraud, such as Kaspersky Premium, on all your devices; this way, you will be warned in time against potential threats.