Fraudsters may rely on what is known as QR code phishing, where a fake code is placed on top of a genuine code or distributed via emails, text messages, posts and websites. When scanning the code, the user may be taken to a fake web page that appears to belong to a well-known bank, company or service.
In some cases, the user does not notice the deception, especially if the link that appears after scanning is long or unfamiliar, so he enters his login data or bank card information, and it reaches the scammers directly.
The risks are not limited to theft of passwords or financial data. Some malicious code may lead to downloading applications or files containing malware, which may give attackers access to sensitive information on the device.
Fraudsters also exploit the element of trust, as the user often does not treat the QR code as a link that could be malicious, but rather sees it as a fast and safe way to access the required service.
Therefore, cybersecurity experts advise against scanning any QR code of unknown origin, especially if it appears in an unexpected message or is stuck on top of another code in a public place. After scanning, the website address should be verified before entering any personal or banking information.
It is also preferable to access sensitive services, such as banking services, through its official application or manually writing the website address instead of relying on a QR code that arrived from an unreliable source. (Erm News)