The use of QR codes is on the rise, but so are cyberattacks: phishing, malware, banking heists and more can all come from a single mis-scan. This conclusion was reached after a survey conducted by Ivanti of 4,157 consumers in China, France, Germany, Japan, the UK and the US.
Specifically, the survey found that 57% of respondents had increased their QR code usage since mid-March 2020, largely due to the need for contactless transactions with the COVID-19. Overall, three-quarters of respondents (77%) said they had scanned a QR code before the pandemic, while 43% said they had scanned a QR code in the past week.
Read also: How to quickly create QR codes with Bing
QR (Quick Response) codes are a form of barcodes that originated in the early 1990s in Japan, in the automotive industry. They became very popular due to their large storage capacity and fast readability. Nowadays, QR codes can be found in magazines, various publications, shop cards, buildings, and even t-shirts.

Ivanti reported the following: “At the beginning of the pandemic, restaurants used QR codes as menu or payment options, but as the pandemic continued throughout 2020, consumers used QR codes more often for practical things, such as visiting a doctor’s office or picking up a prescription. Even in offices and workplaces, QR code usage increased from 11% to 14%, highlighting the shift in how they were used during the pandemic.”
Additionally, 83% of respondents said they used a QR code for the first time in the last 12 monthsto make a payment or complete a financial transaction. Of these, more than half (54%) used a QR code for financial reasons in the last three months alone.
See also: How can you easily share your Wi-Fi with a QR code?
The increasing use of QR codes is also attracting the attention of hackers, who see it as a great opportunity to carry out cyberattacks, according to Ivanti. So, although 87% of respondents said they feel safe using QR codes to complete a financial transaction, in reality they should be more hesitant due to the potential threats.
Chris Goettl, senior director of product management and security at Ivanti, said: “In our last survey, 31% of respondents said they had scanned a QR code that did something they didn’t expect or were taken to a suspicious website. This is a slight increase from six months ago, when 25% of respondents said they had scanned a QR code that did the same thing.”

As for how real-world attacks are conducted, Goettl noted that hackers have been known to create stickers with malicious QR codes and paste them onto legitimate QR codes, which allows them to track transactions and record payment information.
"This happened in parking lots and outdoor dining areas," Goettl pointed out.
Additionally, hackers commonly use QR codes for phishing and malware attacks, while malicious QR codes can direct users to websites that appear legitimate but are actually designed to steal credentials, credit card data, corporate logins, and more. They may also take users to websites that automatically download malware to mobile devices. Both types of attacks typically target accounts, corporate applications, and data that may be on a device.
However, the most common form of QRLjacking is when a legitimate QR code designed to facilitate cashless payments is replaced with a malicious QR code that exposes bank or financial account information when scanned. This malicious QR code could allow hackers to transfer money from bank accounts.

Proposal: NSW: QR codes are very effective for COVID-19 contact tracing
The risks are even greater given that 49% of respondents to Ivanti’s survey do not have mobile security software, and there is a general lack of awareness. For example, only 37% knew that a QR code could download an app, while just a fifth (22%) knew that a QR code could provide a physical location. Furthermore, only 39% said they could identify a malicious QR code.
Goettl explained that due to the pandemic, employees are using their mobile devices more than ever to access corporate data and services from any location. As the popularity and use of QR codes continues to grow, they will undoubtedly be increasingly exploited by hackers who aim to break into devices and steal personal or corporate data.
How can you prevent QR code cyberattacks?
- To avoid falling victim to such an attack, you should first adopt good basic security hygiene. For example, you should be wary of QR codes in public places that appear to have been hastily pasted, as they may have replaced a legitimate QR code.
- Don't scan a random QR code.
- Be suspicious if, after scanning a QR code, a password or login information is required
- Do not scan QR codes received in emails unless you are sure they are legitimate.
- Do not scan a QR code if it is printed on a label and has been placed over another QR code. Ask a staff member to verify its legitimacy first. The business may be able to tell you what the original QR code is.

Finally, Goettl emphasized the following: “Awareness about this issue is low. QR codes have become so common that people are casual about scanning them. The greater the reliance on QR codes, the greater the likelihood that malicious QR codes will succeed, as a means to install malicious code, ransomware, or to steal contact or payment information from a mobile device.”
Source of information: threatpost.com
