Skip to content
NOWCAST WXII 12 News at 12 pm
Watch on Demand
Advertisement

FBI, cybersecurity experts warn about QR code privacy and security concerns

"They could install malware in our devices or add contacts to our contact lists. They could send emails."

FBI, cybersecurity experts warn about QR code privacy and security concerns

"They could install malware in our devices or add contacts to our contact lists. They could send emails."

IN 12 INVESTIGATES A TROUBLING CYBERSECURITY TREND. THE FBI IS CALLING MALICIOUS AND YOU MAY NOT EVEN KNOW YOU’VE BEEN ATTACKED FORT HATCHET DETAILS HOW SIMPLY ORDERING FOOD FROM A RESTAURANT COULD GIVE ATTACKERS ACCESS TO YOUR BANK ACCOUNT AND WHAT YOU CAN DO TO PROTECT YOURSELF. QR CODE SEEM TO BE EVERYWHERE USED FOR MARKETING TRACKING SHIPPING LABELS AND SINCE THE START OF THE PANDEMICO T ACCESS MENUS AT RESTAURANTS THE QR CODE. QUICK RESPONSE CODE WHICH IS SIMILAR TO THE BARCODE. WE SEE USUALLYN OPRODUCTS THE DIFFERENCE IS QR CODES CAN CONTAIN MUCH MORE DATA THAN A BARCODE. AND BECAUSE HUMAN EYES CAN’T DISTINGUISH THE DIFFERENCE BETWEEN INDIVIDUAL QR CODES CYBER CRIMINALS ARE USING MALICIOUS CODES TO STEAL YOUR DATA AND ENVE FINANCIAL INFORMATION SOME USERS. YOU COULD JUST A SCAN THE CODE AND ENTH ASK YOUO T OPEN MAYBE YOUR BANKING APP AND ASK YOU TO ENRTE YOUR USERNAME AND PASSWORD BUT REALITY. IT’S A FAKE APP. IT’S TNO SO THEY’RE GOING TO STEAL YOUR INFORMATION YOUR CREDENTIALS. THE FBI WARNED CYBER CRIMINALS CAN INSTALL MALICIOUS LINKS OVER LEGIMATITE QR CODES LIKE ON MENUS WAKE FOREST UNIVERSITY COMPUTER SCIENCE ASSISTANT PROFESSOR, SIR. I'L’ CATANI SAYS ATTACKERS USE OURWN O CURIOSITY AGAINST US JUST PUTTI ONGR PASTING THEIR CODE ON TOP OF ANY AVAILABLE COMPUTER SCIENCE DEGREE TO PULL OFF THIS SCAM. IT’S EASY YOU CANUS J IF YOU GOOGLE QR CODEND A JUST FIRST LINK HOW TO BUILD. IT’S GONNA GIVE YOU INFORMATION. WHAT IS THE WEBSITE THAT YOU WANT TOUT P IN YOUR QR CODE? AND THAT’S IT. THE SITE’SHE T CODES OPEN MAY LOOK AUTHEIC.NT SOMETIMES YOU MAY NOT EVEN REALIZE YOU’VE OPENED A MALICIOUS LINK FOR INSTANCE. THE ATTACKER MAY STILL TAKE YOU TO THE RESTAURANTS MENU ALL THE WHILE TRACKING AND STEALING YOUR DATA IN THE BAGRCKOUND FOR TO COME THEY COULD INSLLTA MALWARED CONTACTS TO OUR CONTACT LIST. THEY COULD SEND EMAILS THE FBI HAS SEOM TIPS ON HOW TO AVOID BECOMING A VICTIM IN A QR CODE CYBER ATTACK FOR STARTERS. MAKE SURE ANY CODE YOU SCAN HASN’T BEEN TAMPERED WITH BE SURE TO USE HESITATN.IO WHEN ASKED TO SREHA PERSONAL OR FINANCIAL INFORMATION FROM A QR CODE SITE AND MAKE SURE TO ALWAYS CHECK THE LINK THE QR CODE PROVIDEE CLICKING ON IT AND MATCH IT TO A LEGITIMATE BSWEITE THIS CAN WITH THE BUILT-IN. CAMERA AND YOUR SMARTPHONE BECAUSEHE T CAMERA WILL SHOW YOU THE LINK THIRD PARTY APPLICATIONS. USUALL JUST IMMEDIATELY OPEN THE BROWSER FOR YOU IF THE CODE ASKS ASKSOU Y TO OPEN AN APPLICATION IN YOUR DEVICE. DON’T DO THAT. THEY ARE NOT SUPPOSED TOO D THAT. BUT BOTH T FHEBI AND ALCATANI SAY IF YOU’RE GIVEN THE CHOICE AVOID SCAINNNG THE QR CODE ALTOGETHER AND TYPE IN THE WEB ADDRESS YOURSELF F
Advertisement
FBI, cybersecurity experts warn about QR code privacy and security concerns

"They could install malware in our devices or add contacts to our contact lists. They could send emails."

QR codes seem to be everywhere. They're used for marketing and advertisements, tracking shipping labels and, since the start of the pandemic, to access menus at restaurants."The QR code is a 'quick response' code which is similar usually to the bar codes we see on products," Wake Forest University computer science assistant professor Sarra Alqahtani told us.The difference is, QR codes can contain much more data than a bar code. Because human eyes cannot distinguish the difference between individual QR codes, some cybercriminals have been using malicious codes to steal users' personal data and even financial information."Some users you could just scan the code and it will ask you to open your banking app and ask you to enter your username and password," Alqahtani said. "But in reality, it’s a fake app. It’s not your real app so they are going to steal your information and credentials.”The FBI issued a warning in January about cybercriminals installing malicious links over legitimate QR codes like on menus. Hackers simply make their own QR code and delicately place it on top of legitimate codes, with most users unable to spot any maleficence. And Alqahtani says it doesn’t take a computer science degree to pull off this scam."It’s very easy," she said. "If you Google 'QR code' and just click the first link ‘how to build,' it’s going to ask 'what is the information you want to put in your QR code' and that’s it.”She says some hackers may prey on our curiosity and post plain codes without any accompanying description in public, hoping we will scan them to find out more.No matter how they find their way to our phones, the sites the hackers' codes open may look authentic. Sometimes you may not even realize you’ve opened a malicious link.For instance, the attacker may still take you to a restaurant's menu, all the while tracking and stealing your data in the background for weeks to come."They could install malware in our devices, add contacts to our contact lists. They could send emails," Alqahtani said.In their January warning, the FBI provided tips on how to avoid becoming a victim in a QR code cyberattack:Once you scan a QR code, check the URL to make sure it is the intended site and looks authentic. A malicious domain name may be similar to the intended URL but with typos or a misplaced letter.Practice caution when entering login, personal, or financial information from a site navigated to from a QR code.If scanning a physical QR code, ensure the code has not been tampered with, such as with a sticker placed on top of the original code.Do not download an app from a QR code. Use your phone's app store for a safer download.If you receive an email stating a payment failed from a company you recently made a purchase with and the company states you can only complete the payment through a QR code, call the company to verify. Locate the company's phone number through a trusted site rather than a number provided in the email.Do not download a QR code scanner app. This increases your risk of downloading malware onto your device. Most phones have a built-in scanner through the camera app.If you receive a QR code that you believe to be from someone you know, reach out to them through a known number or address to verify that the code is from them.Avoid making payments through a site navigated to from a QR code. Instead, manually enter a known and trusted URL to complete the payment."Scan with the built in camera in your phone because the camera will show you the link," Alqahtani adds. "Third party applications usually just open the browser for you. If the code asks you to open an application in your device, do not do that. They are not supposed to do that.”But both the FBI and Alqahtani said if you’re given the choice, you should avoid scanning the QR code altogether and type in the web address yourself.

QR codes seem to be everywhere. They're used for marketing and advertisements, tracking shipping labels and, since the start of the pandemic, to access menus at restaurants.

"The QR code is a 'quick response' code which is similar usually to the bar codes we see on products," Wake Forest University computer science assistant professor Sarra Alqahtani told us.

Advertisement

The difference is, QR codes can contain much more data than a bar code. Because human eyes cannot distinguish the difference between individual QR codes, some cybercriminals have been using malicious codes to steal users' personal data and even financial information.

"Some users you could just scan the code and it will ask you to open your banking app and ask you to enter your username and password," Alqahtani said. "But in reality, it’s a fake app. It’s not your real app so they are going to steal your information and credentials.”

The FBI issued a warning in January about cybercriminals installing malicious links over legitimate QR codes like on menus. Hackers simply make their own QR code and delicately place it on top of legitimate codes, with most users unable to spot any maleficence.

And Alqahtani says it doesn’t take a computer science degree to pull off this scam.

"It’s very easy," she said. "If you Google 'QR code' and just click the first link ‘how to build,' it’s going to ask 'what is the information you want to put in your QR code' and that’s it.”

She says some hackers may prey on our curiosity and post plain codes without any accompanying description in public, hoping we will scan them to find out more.

No matter how they find their way to our phones, the sites the hackers' codes open may look authentic. Sometimes you may not even realize you’ve opened a malicious link.

For instance, the attacker may still take you to a restaurant's menu, all the while tracking and stealing your data in the background for weeks to come.

"They could install malware in our devices, add contacts to our contact lists. They could send emails," Alqahtani said.

In their January warning, the FBI provided tips on how to avoid becoming a victim in a QR code cyberattack:

  • Once you scan a QR code, check the URL to make sure it is the intended site and looks authentic. A malicious domain name may be similar to the intended URL but with typos or a misplaced letter.
  • Practice caution when entering login, personal, or financial information from a site navigated to from a QR code.
  • If scanning a physical QR code, ensure the code has not been tampered with, such as with a sticker placed on top of the original code.
  • Do not download an app from a QR code. Use your phone's app store for a safer download.
  • If you receive an email stating a payment failed from a company you recently made a purchase with and the company states you can only complete the payment through a QR code, call the company to verify. Locate the company's phone number through a trusted site rather than a number provided in the email.
  • Do not download a QR code scanner app. This increases your risk of downloading malware onto your device. Most phones have a built-in scanner through the camera app.
  • If you receive a QR code that you believe to be from someone you know, reach out to them through a known number or address to verify that the code is from them.
  • Avoid making payments through a site navigated to from a QR code. Instead, manually enter a known and trusted URL to complete the payment.

"Scan with the built in camera in your phone because the camera will show you the link," Alqahtani adds. "Third party applications usually just open the browser for you. If the code asks you to open an application in your device, do not do that. They are not supposed to do that.”

But both the FBI and Alqahtani said if you’re given the choice, you should avoid scanning the QR code altogether and type in the web address yourself.