Back to blog

Phishing: QR Codes Hijacked in Parking Lots and Restaurants!

B
BlueSecure
Équipe BlueSecure
November 20, 20223 min read
Phishing: QR Codes Hijacked in Parking Lots and Restaurants!

The QR Code, or “Quick Response Code,” was born in Japan in 1994. It was invented by an engineer at Denso Wave, then a manufacturer of automotive parts for Toyota. Originally created to track automotive parts during the assembly process, it is now an integral part of our lives. We use it to view restaurant menus, pay a bill, check bus schedules, or even board a plane. The everyday use of this technology has attracted the attention of cybercriminals, who use it maliciously, particularly to collect sensitive information or infect a device with malware.

A look back at the latest QR code phishing attacks

QR Code phishing, or QRishing, is increasingly used because simply replacing an existing QR Code is enough to deceive a user. Furthermore, there is currently no protection or detection system for malicious QR Codes. This makes the use of QR Codes particularly dangerous and awareness of the risks associated with their use essential.

In the United States, hackers placed QR Codes on dozens of parking meters at the beginning of the year. Their goal was to steal money from motorists. Indeed, when scanning the QR Code, they were redirected to a parking payment page that looked remarkably like the official one. Many motorists were scammed and had their banking information stolen.

This summer, restaurants in tourist areas in Southern France were targeted by these QR Code phishing attacks. Hackers placed QR Codes on menus handed out to customers or directly on tables. These QR Codes redirected customers to a payment page that transferred the money directly to the attackers’ bank account.

QR Code phishing attacks do not only target individuals. Cyberattackers also target organizations. For example, you may be asked to scan QR Codes to access a company parking lot or book a meeting room. Hackers take advantage of the use of personal devices for professional purposes, or vice versa, to gain access to the IT systems of targeted organizations. It is therefore necessary to protect against these attacks.

QRishing awareness code

How can you protect yourself against QRishing attacks?

QR Code phishing attacks are becoming increasingly common. Here are a few tips to protect yourself against them:

Before scanning one, remember that scanning a QR Code is equivalent to clicking on a link in a spam email. Visually check that a sticker has not been placed over another one.

When you scan a QR Code using your camera, the URL is displayed. Before clicking to access it, make sure the URL matches what you want to view, or check the URL by searching for it in a search engine. The URL used in the Texas parking meter scams, for example, was “passportlab.xyz.” It did not match an official website for the city of Austin, San Antonio, or Houston.

The BlueSecure solution

BlueSecure offers QRishing awareness programs through e-learning training and QR Code phishing campaigns. This combines theory and practice to raise your employees’ awareness of the risks associated with this type of attack as effectively as possible.

Contact us for more information:

CONTACT US

By

B

BlueSecure

Équipe BlueSecure

The BlueSecure team specializes in cybersecurity awareness training and employee security education. With over 10 years of experience, we help organizations protect their most valuable asset: their people.

Share this article