QR code scams up in India, over 20K cases registered since 2017; here’s how to avoid it

India has witnessed a surge in QR code scams as digital payments have gained rapid adoption, according to a report released on Tuesday. Between 2017 and May 31, 2023, Bengaluru alone registered approximately 20,662 cases, accounting for 41 per cent of cases related to QR codes, malicious links, or debit/credit card fraud.

According to Palo Alto Networks, most QR codes appear visually similar, making it challenging to distinguish between genuine and fraudulent ones. Attackers take advantage of this by replacing legitimate QR codes with their own, potentially compromising a business’s website. When unsuspecting individuals scan these altered codes, they are automatically redirected to phishing URLs where cybercriminals can request user credentials, potentially gaining access to email or social media accounts.

Alternatively, these altered QR codes can lead users to untrustworthy app stores, encouraging them to download malicious applications that may contain viruses, spyware, trojans, or other malware. This can lead to data theft, privacy breaches, ransomware attacks, and even cryptocurrency mining.

The report also highlighted another common tactic among cybercriminals, known as the “evil twin” or hotspot honeypots. In this scheme, threat actors establish insecure Wi-Fi networks and entice users with the promise of free internet access upon scanning their QR codes. Once connected, hackers intercept and eavesdrop on transmitted data, stealing personal or confidential business information, online banking credentials, and credit card details.

Avoiding QR code scams involves being vigilant and taking precautions when scanning QR codes. Here are some tips to help you stay safe:

Use Official Apps: Whenever possible, use official or trusted apps to scan QR codes. These apps often have built-in security features and are less likely to lead you to malicious websites or apps.

Check the Source: Be cautious when scanning QR codes from unknown sources, especially if you receive them via email, text message, or social media. Verify the sender’s identity before scanning.

Inspect the QR Code: Take a close look at the QR code itself. If it looks damaged, altered, or suspicious in any way, avoid scanning it.

Be Wary of Unsolicited QR Codes: If you didn’t initiate the QR code scanning process, be cautious. Don’t scan QR codes that appear unexpectedly or are sent by unknown sources.

Hover Before Scanning: Instead of immediately scanning a QR code, hover your smartphone’s camera over it without scanning. This allows you to see the URL or information associated with the code. If it looks suspicious, refrain from scanning.

Use a QR Code Reader with Preview: Some QR code scanner apps provide a preview of the URL or content before taking you to the destination. This can help you verify that it’s safe to proceed.

Update Your Smartphone’s Software: Keep your smartphone’s operating system and apps up to date. Updates often include security patches that can protect you from known vulnerabilities.

Educate Yourself: Stay informed about QR code scams and the latest phishing tactics. Awareness is key to avoiding scams.

Use a Secure Network: Avoid scanning QR codes on public Wi-Fi networks, which may be less secure. Use a trusted and secure network for online transactions.

Report Suspicious QR Codes: If you encounter a suspicious QR code, report it to the appropriate authorities or the platform where you found it. This can help prevent others from falling victim to the same scam.

source by : Business Today

