HomeSecurityFBI: Malicious QR codes can steal your money

FBI: Malicious QR codes can steal your money

The Federal Bureau of Investigation (FBI) has issued a warning to American citizens that cybercriminals are using maliciously crafted QR codes to steal their credentials and financial information.

QR codes

See also: FBI: Links Diavol ransomware to TrickBot developers

"Cybercriminals are exploiting QR codes to redirect victims to malicious websites that steal login credentials and financial information," the federal law enforcement agency said.

The FBI said that scammers are altering legitimate QR codes used by businesses for payment purposes and redirecting potential victims to malicious websites designed to steal their personal and financial information, install malware on their devices or divert their payments to their own accounts.

After victims scan what looks like a legitimate QR code, they are redirected to phishing, where they are asked to enter their login and financial details. Once this is done, they are sent to cybercriminals who can use them to steal money through compromised bank accounts.

See also: New phishing scam in the US: Fraudulent QR codes on parking meters

While QR codes are not inherently malicious, it is important to exercise caution when entering financial information or making a payment through a website you navigate to via a QR code ,” the FBI added . “ Law enforcement cannot guarantee the recovery of lost funds after they have been transferred.

FBI

The FBI advised Americans to be careful of the URL sent to them after scanning QR codes, to always be cautious when entering their data after scanning a QR code, and to make sure that physical QR codes have not been replaced with malicious ones.

You should also avoid installing apps via QR codes or installing QR code scanners and use the one that comes with your phone's operating system.

See also: Phishing attacks use QR codes to steal banking credentials

Last but not least, always enter URLs manually when making payments, rather than scanning a QR code that could be set up to redirect you to malicious websites.

As demonstrated by a recent phishing campaign targeting German e-banking users, threat actors are using QR codes instead of buttons in spam emails to make their attacks harder to detect by security software and to successfully redirect victims to phishing websites.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS