QR codes can eat your lunch, FBI warns
Full article554 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The bureau's Internet Crime Complaint Center (IC3), issued a general alert Tuesday about "malicious" QR codes that reroute unsuspecting consumers.
QR codes are among the few “winners” of the coronavirus pandemic, the joke goes, because restaurants and other businesses have deployed them in far greater numbers over the past few years, in an effort to make more interactions contactless.
The FBI is warning, however, that scammers love them, too.
The bureau’s Internet Crime Complaint Center (IC3), issued a general alert Tuesday about “malicious” QR codes that reroute unsuspecting consumers to the world of cybercrime.
“[C]ybercriminals are taking advantage of this technology by directing QR code scans to malicious sites to steal victim data, embedding malware to gain access to the victim’s device, and redirecting payment for cybercriminal use,” the announcement says.
The FBI’s warning is the latest in a long string of advisories from cybersecurity researchers or government agencies about the threat posed by QR codes. Last week, Ars Technica reported on fake QR codes that were stuck on parking meters in Texas cities, with the goal of intercepting payments.
In October 2021, scammers were spotted using them as part of a phishing campaign. Earlier last year, the U.S. Army issued a warning. Other alerts pointed to bitcoin scams, And at least one barcode scanner app became notorious for carrying malware itself.
The FBI’s release didn’t cite any examples of such activity, but said the trickery usually comes through QR codes that have been altered, either onscreen or on a printed page.
“A victim scans what they think to be a legitimate code but the tampered code directs victims to a malicious site, which prompts them to enter login and financial information,” the FBI said. The bureau did not respond to a request from CyberScoop to provide more detail.
The bureau is warning consumers to double-check any URL generated by a QR code, and to be cautious about using them in general, especially for making payments.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/mailicous-qr-codes-fbi-ic3-alert/