TechnologyQR codes can be phishing scams in disguise, warns...

QR codes can be phishing scams in disguise, warns the FTC


The Federal Trade Commission (FTC) warned the public against scanning any old QR code in a consumer alerts blog last week. Naturally, the warning comes down to security and privacy — bad actors can put QR codes in inconspicuous places or send them via text or email, then just sit back and wait for a payday in the form of money, logins, or other sensitive information.

The New York Times reported that John Fokker, who heads threat intelligence at cybersecurity company Trellix, says Trellix found over “60,000 samples of QR code attacks” in the third quarter this year alone. The Times wrote that the most popular scams involved payroll and HR personnel impersonators and postal scams, among others. Early last year, police in several Texas cities said they’d found fraudulent QR codes placed on parking meters, directing people to a false payment site.

To avoid being victimized by a bad code, the FTC suggests ignoring unexpected emails or other messages you weren’t expecting that come with some sort of urgent request. It’s also good to check the URL that shows up on your screen when scanning to make sure it’s a site you trust. Then again, even a legitimate QR code can show you a garbled and meaningless shortened web address, so if you know what site you want to visit, it’s best to go there directly.

The Commission also recommends the old standby of updating your devices and ensuring you have good, strong passwords and multi-factor authentication in place for sensitive accounts. If you’re unsure how to do that second part, check out our two-factor authentication guide, which has instructions for several of the most popular sites and services.

Beyond the FTC’s recommendation, there are other things you can do. Don’t download a QR code scanning app, for one — built-in camera apps for Android and iOS already do that, and apps can sometimes be made for nefarious purposes themselves. The FBI also has a list of recommendations in a similar blog it published in September, but in general, if you aren’t sure about a code, don’t scan it.



Original Source Link

Latest News

Rock found by a 6-year-old on a beach is actually a 50,000-year-old Neanderthal ax

Three years ago, a then-6-year-old boy named Ben discovered a strange rock on a beach in Sussex, England....

AI startups snatch San Francisco offices, use Zoom fatigue to recruit

Mithrl is among a wave of startups coming back to San Francisco and working in person four days...

How Notre Dame Cathedral’s Reopening Will Unfold

PARIS (AP) — The reopening this weekend of Notre Dame is a succession of ceremonies to breathe life...

Was CEO Brian Thompson Getting a Divorce From Wife Paulette? – Hollywood Life

After UnitedHealthcare CEO Brian Thompson was fatally shot in early December 2024, his professional and personal lives became...

UniCredit’s Orcel could still sweeten his bid and take on a double M&A offensive

Andrea Orcel, chief executive officer of Unicredit, in London, UK, on Thursday, Nov. 23, 2023. Bloomberg | Bloomberg |...

How to swap tokens between Base and Solana: A step-by-step guide

Discover how to swap tokens between Base and Solana using crosschain bridges or centralized exchanges for secure and...

Must Read

- Advertisement -

You might also likeRELATED
Recommended to you