These days, QR codes are everywhere, as they are easy to use and fast. The word itself means “quick response.” Scanning the code with your phone’s camera has many functions, such as opening the phone’s browser or even downloading an instant app for services like renting a ride or paying for parking.

However, the popularity they have gained has also attracted many malicious actors.
According to Alex Mosher of MobileIron, QR codes are another gateway for an attacker to enter phone .
MobileIron recently surveyed 2,100 phone users in the United States and the United Kingdom. It found that 40% had scanned at least one QR code in the past week, and 53% would like to scan more QR codes. But 71% admitted they couldn't spot a malicious QR code.
Mark Kraynak, a former technology executive, says he fell victim to a malicious QR code. He used a small business' QR code as part of a contactless equipment rental process.
"He asked for a credit card and I thought maybe it was part of the payment, but it wasn't," Kraynak said.
Instead, a $40 charge appeared from somewhere in Eastern Europe. Fortunately, his credit card company was able to reverse the fraudulent charge.

How does the attack work?
Mosher says thieves create malicious QR codes that are simply pasted over a “real” one and wait for a user. Malicious codes can steal credit card information or even open a device to attackers. So you should check for breaches before you scan.
To protect your phone from potentially harmful, malicious QR codes, experts recommend avoiding blindly scanning QR codes and always being mindful of the source they come from. If you can, check the code itself to see if anyone has had a problem with it. Mosher also recommends adding security software to your phone. Finally, if you discover you’ve been the victim of such an attack, contact your bank immediately to avoid further charges.
