Quishing: When QR codes become a data trap

QR codes are convenient and ubiquitous, but cybercriminals are increasingly using them for a new scam called "quishing." In this scam, they manipulate QR codes to steal sensitive data or spread malware. Alina Gedde from Ergo explains how the scam works and how to protect yourself from it.

Electronic device, Gadget, Communication Device
Source: Ergo Group

QR codes are practical, fast and have long been commonplace, whether in a restaurant, in digital outdoor advertising or on a flyer. But what many people don't know: The seemingly harmless square pattern can conceal a new scam. "Quishing" is the name of the method used by cyber criminals to manipulate QR codes in order to obtain personal data or infiltrate malware.

What is quishing?

Most people are now familiar with phishing emails or fake messages that supposedly come from the bank. However, a new scam has been circulating for some time, known as quishing. Cyber criminals use fake or manipulated QR codes to obtain sensitive personal data or spread malware. The term is a portmanteau of "QR" (Quick Response Code) and "phishing" and thus describes a form of phishing attack using QR codes.

"The perfidious thing about quishing is that, unlike malicious links such as those in an email, QR codes cannot be automatically scanned by antivirus software," explains Alina Gedde, digital expert at Ergo.

How quishing works - and why it's so dangerous

Quishing always starts with a seemingly harmless QR code. Fraudsters place it on posters, in emails, in letters or in public places. "Scanning the code does not take you to a legitimate website, but to a deceptively genuine fake. There, the page asks you to enter passwords, payment information or personal details," says the digital expert. "In some cases, a malicious download that infects the smartphone even starts immediately after the scan."

Access data for online banking or email accounts, credit card information, bank details or personal data such as name, address, date of birth or telephone number are particularly popular. Fake QR codes promise, for example, access to parcel tracking, listening to a voice message or quick payment, for example at a parking machine.

Recognize quishing

Unexpected QR codes on stickers, slips of paper or posters, especially in unusual places or stuck over existing codes, should immediately make you suspicious. Emails or text messages with QR codes that have a questionable sender or require urgent action are also typical warning signs. After scanning, a lack of HTTPS encryption or an unusual Internet address with typos or unknown domains are indications of fraud. If a website directly asks for passwords, payment information or personal data, there is an acute risk.

Protect sensitive data

It is safest to scan QR codes from trustworthy sources such as official websites or well-known companies. Many scanners offer a preview of the target address. If it looks unusual, those affected should be careful. It is worth taking a close look at the address in the browser before entering it: Only a correct domain with HTTPS encryption is trustworthy. Personal data such as logins or payment details should never be entered on sites where there is any doubt. "If you also use up-to-date security software on your smartphone and prefer to enter important websites manually, you significantly reduce the risk," advises Gedde.

React correctly in case of suspicion

If you have a bad feeling when scanning, stop immediately and do not enter any more data. Anyone who has already disclosed sensitive information should change passwords immediately and inform the bank or the service concerned. A report to the police or consumer advice center also offers protection against further damage. It is then worth carrying out a thorough check of the smartphone to find and remove malware or unwanted apps.

More articles on the topic