spot_img

Date:

Share:

Scan or Scam? Kaspersky experts warn of the risks hidden behind QR codes

 In today’s digital world, QR codes are placed on almost everything – from yogurt containers and restaurant menus to museum exhibits, and even utility bills and parking lots. People use them to open websites, download apps, collect loyalty programme points, make payments and transfer money, and even for charity donations. The accessible and practical technology is convenient for many, including cybercriminals, who have already rolled out a variety of QR-based schemes.

Kaspersky experts have identified the top  security risks when scanning QR codes:

Phishing and redirection to malicious sites: QR codes can direct users to fraudulent websites designed to steal personal or financial information, such as passwords and credit card numbers. Attackers can impersonate legitimate sites, such as banks or streaming services, and trick users into entering their credentials.

Malware download: Some QR codes can trigger the download of malicious applications that compromise the security of the user’s device, especially if it is not protected against unauthorised installation.

Payment fraud: During special events or sales periods like holiday sales, a fake QR code can redirect users to make payments to fraudulent accounts.

Unsafe automatic connections: A QR code can also automatically connect the user to Wi-Fi networks controlled by cyber attackers, allowing them to intercept their communications.

“QR codes are a fertile ground for potential manipulation, especially as they appear in various everyday contexts such as receipts, flyers, and signage. Attackers have nearly endless possibilities to exploit them. As these codes have already become an integral part of our daily lives, it is essential for users to know how to use them safely and responsibly,” says Seifallah Jedidi, Head of Consumer Channel for META at Kaspersky.

In order to not fall for a scam when scanning a QR code, Kaspersky experts recommend:

Verify the source: Scan QR codes only from trusted and known sources. Avoid scanning codes in public places that may have been tampered with.

Check the URL: If you really need to scan a publicly available code, verify that the web address it directed you to is legitimate before taking any action on this website.

Don’t share personal information: Avoid entering sensitive information if you’re not completely sure of the origin of the QR code.

Protect your digital life: Install a cybersecurity solution with anti-phishing and anti-fraud protection, such as Kaspersky Premium, on all your devices; it will alert you to any danger timely.

spot_img
spot_img

━ More like this

South African banking leaders see AI agents as industry’s greatest vulnerability in next year

Artificial intelligence is rapidly reshaping the fraud landscape, and South African banking leaders appear among the most concerned globally. In a new survey of 1,440 fraud...

The cybersecurity reset: Why last year’s playbook is obsolete

For South African IT teams in 2026, cyber defence is akin to defending a goal line with an outdated playbook. The formations are familiar, the...

Kaspersky has discovered a new corporate phishing technique using a popular AI web development platform

Kaspersky has discovered that attackers have begun exploiting another legitimate service for malicious purposes – this time it is Tencent EdgeOne Pages, a platform...

Kaspersky warns of “grey” scam websites exploiting user trust

Recent research by Kaspersky has shown that the so-called “grey” websites repeatedly target all world regions, and this may be driving both financial loss...

Kaspersky ICS CERT: The beginning of 2026 showed an increase in cyberattacks on the manufacturing sector

According to a new Kaspersky ICS CERT report, in Q1 2026 the percentage of industrial control systems (ICS) on which malicious objects were blocked...
spot_img