Think before you scan – QR codes are a potential cyber risk
This article has been supplied.
By Simeon Tassev, MD and QSA at Galix
QR codes are nothing new – they have been around since 2004 – but with the increased availability of smartphones, which can scan these two-dimensional barcodes with their built-in cameras, QR codes have become increasingly popular. They can be used to make payments, download menus in restaurants, for general marketing purposes and a multitude of other applications. They can also be used by cybercriminals and malicious actors to steal personal and payment-related information, so it pays to be a little more aware.
Convenience is the killer
QR codes are, by design, incredibly user-friendly. These days, we see them everywhere. They are on the back of consumer products, and we can scan them to get more information. They are in restaurants so we can scan them to view the menu without touching a physical menu card. They are used to enter competitions, in children’s books to access online content. They are also used by various apps to allow small business vendors to accept credit card payments.
The risk is that, while smartphones can read the QR code, humans cannot, so we have no idea where the code will direct us to. We could easily be clicking on an infected link, a spoof website, or even just paying the wrong vendor. Opening a QR code could trigger an executable file or potentially malicious code, which can then be used by cybercriminals to steal personal information, including payment data.
Think before you scan
The issue here is not with the QR codes themselves, or with the payment apps, because these are both secure and mature technologies. The trouble is that QR codes are easy to generate – this can be done for free online – which means that genuine codes can easily be replaced by fake ones, leading people to links that look legitimate, or that are legitimate but send payment to the wrong vendor.
For example, at a market, vendors will have QR codes to scan and pay, but they often have strange names, or multiple businesses use the same payment application code. This makes it very easy for a malicious actor to replace the real code with their own, effectively stealing money from these vendors. Similarly, QR codes for downloading menus, entering competitions or other marketing exercises, can easily be replaced by fake codes that look real, but lead people to infected links or spoof sites where personal information is voluntarily entered and then stolen.
Be aware of the risk
The biggest risk around QR codes is that we use them in scenarios where we are not necessarily paying attention to, or thinking about, cybersecurity. They are easy and convenient, and even children can use them. However, they can also be abused, so we need to be aware of the risk.
If possible, verify the payment before you process it – check with the vendor that you are paying the right person, visit links directly through your browser, or use an alternate method where possible. Have endpoint security on your devices to protect you from malicious content. Most of all, be mindful. QR codes are fun, easy and convenient, but they are vulnerable to abuse, and we need to be aware. You wouldn’t just click a link in an email without checking, so why scan a QR code without verifying it first.
Article Enquiry
Email Article
Save Article
Feedback
To advertise email advertising@creamermedia.co.za or click here
Announcements
What's On
Subscribe to improve your user experience...
Option 1 (equivalent of R125 a month):
Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine
(print copy for those in South Africa and e-magazine for those outside of South Africa)
Receive daily email newsletters
Access to full search results
Access archive of magazine back copies
Access to Projects in Progress
Access to ONE Research Report of your choice in PDF format
Option 2 (equivalent of R375 a month):
All benefits from Option 1
PLUS
Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors
including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.
Already a subscriber?
Forgotten your password?
Receive weekly copy of Creamer Media's Engineering News & Mining Weekly magazine (print copy for those in South Africa and e-magazine for those outside of South Africa)
➕
Recieve daily email newsletters
➕
Access to full search results
➕
Access archive of magazine back copies
➕
Access to Projects in Progress
➕
Access to ONE Research Report of your choice in PDF format
RESEARCH CHANNEL AFRICA
R4500 (equivalent of R375 a month)
SUBSCRIBEAll benefits from Option 1
➕
Access to Creamer Media's Research Channel Africa for ALL Research Reports on various industrial and mining sectors, in PDF format, including on:
Electricity
➕
Water
➕
Energy Transition
➕
Hydrogen
➕
Roads, Rail and Ports
➕
Coal
➕
Gold
➕
Platinum
➕
Battery Metals
➕
etc.
Receive all benefits from Option 1 or Option 2 delivered to numerous people at your company
➕
Multiple User names and Passwords for simultaneous log-ins
➕
Intranet integration access to all in your organisation















