Quishing, or QR code phishing, is a cybercrime tactic where individuals are duped into scanning a QR code with their mobile phones. This seemingly innocent action can redirect them to fraudulent websites, leading to malware installation or the theft of sensitive personal information.
QR codes, by themselves, are harmless data storage tools. However, the risks arise when they are used to store URLs, akin to the dangers of clicking on links in emails. The URL in a QR code might redirect you to a phishing site designed to steal your login credentials. Alternatively, it could lead you to a legitimate site, exploiting a vulnerability to enable unauthorized access to your account.
Another risk is being directed to a malicious website that interacts with other websites you're logged into on the same device, performing unauthorized actions. Additionally, a QR code could open an application on your device, triggering it to execute certain actions. This is similar to clicking a Zoom link that automatically opens the app and joins a meeting. While usually harmless, this feature can be manipulated to expose your data.
Therefore, it's crucial to verify the safety and source of a QR code's URL before proceeding. Don't be misled by a familiar logo on the QR code; always ensure the URL is from a trusted source for your online safety.
Creating and deploying malicious QR codes is relatively easy and requires minimal resources. The lack of oversight in QR code creation and the ease of placing these codes in public spaces make them an attractive tool for fraudsters.