0% found this document useful (0 votes)
579 views5 pages

QR Code Scam Awareness Guide

The document outlines various scams involving QR codes, where fraudsters trick victims into scanning fake codes that lead to unauthorized payments or phishing sites. It emphasizes the importance of vigilance when using QR codes, advising users to verify the source and check for embedded URLs before proceeding. Additionally, it suggests immediate actions to take if one falls victim to such scams, including contacting banks and reporting to authorities.

Uploaded by

Scamcheck India
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
579 views5 pages

QR Code Scam Awareness Guide

The document outlines various scams involving QR codes, where fraudsters trick victims into scanning fake codes that lead to unauthorized payments or phishing sites. It emphasizes the importance of vigilance when using QR codes, advising users to verify the source and check for embedded URLs before proceeding. Additionally, it suggests immediate actions to take if one falls victim to such scams, including contacting banks and reporting to authorities.

Uploaded by

Scamcheck India
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
  • Scam through QR Code Scan
  • How QR Code Scams Work
  • Phishing with QR Codes
  • What to Do If Scammed
  • Conclusion

Scam through QR Code Scan

 The scam starts with someone putting an item on an online sale website. That’s when the
fraudsters pose as buyers and share the QR code to pay an advance or token amount. They
then create a QR code and share it with the intended victim through WhatsApp or email.

Perhaps, their widest use is in the contactless payment ecosystem – ‘Scan the QR code
below and pay’. A QR (Quick Response) code is a two-dimensional barcode that is easily
read by smartphones – all you need is a camera and an app to read the code. While over-the-
counter scanning poses less of a risk, scammers have found new, creative ways of deception.
One way of doing this is by sending people texts like – ‘Congrats on winning Rs 20,000’
along with the picture of a QR code. The message will urge you to scan the code, enter the
amount, followed by your UPI PIN to ‘receive’ the cash in your account. In this scam,
gullible people believe that this will credit money in their account, but this does just the
opposite. You don’t end up ‘receiving’ but actually ‘paying’ the fraudster the amount.
 Another tactic is by embedding fake QR codes into a phishing email, text, or via social
media. Upon scanning the bogus code, users are directed to websites with realistic-looking
landing pages, where the victim may be prompted to log in by entering PII (personally
identifiable information).

 Public QR codes (like at fuel stations or kiosks) also pose a problem as cybercriminals may
swap them by replacing their own QR codes over genuine ones to make money flow into
their account. The problem is, there is no way of reading the information contained inside
the code before exposing the device to the unsuspecting fraud. It’s critical to pay close
attention, even to small details while making payments or transactions using QR codes. It is
best to pay using these, only insecure and familiar environments. Remember that the risks of
scanning an unknown QR are like clicking on links in unknown messages – treat a QR code
like any other link – don’t follow it if you don’t fully trust the source. Once you scan the
QR, a pop-up to view its embedded URL must emerge. If there is no URL, or if it seems like
a shortened one (like [Link]) – be cautious. It’s best to install a QR scanner that checks or
displays the URL before it follows the link.
 Immediately contact your bank and have them change your login credentials. You may also
consider contacting the police and registering a formal complaint with the cyber cell or even
an online complaint on the National Cybercrime Reporting Portal – [Link].
 Although the QR codes themselves are a secure and convenient mechanism, we expect them
to be misused by cybercriminals in 2021 and beyond. Knowledge of QR code fraud may lag
significantly today, but vigilance on our part will ensure the difference between the QR code
being scanned and us being scammed.
Thankyou

Common questions

Powered by AI

Vigilance is crucial when using QR codes for transactions as it is a frontline defense against scams. Awareness of the risks allows individuals to differentiate between a legitimate QR code use and a scam attempt. Being vigilant means scrutinizing unfamiliar QR codes, recognizing phishing attempts, and understanding that QR codes can be tampered with, which helps prevent unauthorized payments and data breaches .

QR codes may continue to be widely misused by cybercriminals due to their increasing integration into everyday digital transactions and their inherent opacity, which makes it difficult for users to verify authenticity without scanning. As knowledge about QR code scams remains insufficient among the general population, cybercriminals find it easier to employ deceptive tactics that exploit trust in QR code technology .

Scammers typically initiate a QR code scam by posing as buyers on online sales platforms. They send a QR code to the seller, proposing that they use it to receive an advance payment. However, the key deception lies in the seller actually scanning the QR code and entering a payment amount and UPI PIN under the belief that they will receive money. In reality, this action authorizes a payment from the seller to the scammer, effectively scamming the seller out of money .

The lack of visible information in a QR code contributes to its misuse by cybercriminals because users cannot discern the encoded data without scanning it. This opacity allows scammers to replace legitimate QR codes with malicious ones or embed harmful links in communications. Users often cannot verify the authenticity of the QR code beforehand, making it easier for scammers to exploit their trust and execute fraudulent activities .

If individuals suspect they have been a victim of a QR code scam, they should immediately contact their bank to change their login credentials. They may also consider contacting the police to register a formal complaint with the cyber cell or submit a report on the National Cybercrime Reporting Portal at cybercrime.gov.in .

Following a QR code link that leads to a malicious website can have severe consequences. Users may unknowingly enter personal information into phishing sites, resulting in identity theft, unauthorized access to bank accounts, and financial loss. Malicious websites can also deliver malware to the user's device, compromising its security and potentially facilitating further cyber attacks .

It is important to be cautious of QR codes received through email, text, or social media because they can be a part of phishing scams. Scammers embed fake QR codes in these communications that direct users to lookalike websites where they may be prompted to enter personal information, potentially leading to identity theft or unauthorized access to personal accounts .

A key security feature to use when scanning QR codes is a QR scanner app that checks or displays the URL before allowing the user to follow the link. This helps users avoid being redirected to malicious websites and ensures safer transactions .

Preventive measures to reduce the risk of QR code scams include developing and using QR code scanner apps that reveal the URL before proceeding, increasing public awareness about QR code fraud risks, and educating users on the importance of only using QR codes in trusted environments. Additionally, organizations can implement QR code verification systems and enhance the digital literacy of users to recognize and avoid scams .

Scanning QR codes in public places, like fuel stations or kiosks, poses risks because cybercriminals can swap the genuine QR codes with fraudulent ones that divert payments into their accounts. To protect themselves, users should treat unknown QR codes like suspicious links, only scanning in secure and familiar environments. Additionally, they should use QR scanners that display the URL before proceeding, and be cautious with shortened URLs .

You might also like