Beware of unknown QR codes—they could contain malware

Thanks to the pandemic, QR codes have popped up on ad posters, restaurant tables, and billboards around the world, inviting people to scan them in order to view menus and marketing information without having to type a web address into their phones. But clicking QR codes too hastily can risk bringing malware to your smartphone, cautions Albert Fox Cahn, founder and executive director of the Surveillance Technology Oversight Project (S.T.O.P.). “If someone just walked up to you on a street corner, you wouldn’t just take a thumb drive from them and plug it into your laptop,” he says. [Photo: S.T.O.P.]S.T.O.P. has been placing flyers and signs advertising fake events like comedy shows, venue openings, and trivia nights around New York City, where S.T.O.P. is based, with each bearing a QR code. Hundreds of people have scanned the QR codes and visited associated websites, which S.T.O.P. set up to bear warnings about the dangers of loading unknown QR codes, Cahn says. Now, the group is encouraging its supporters around the country to put up their own flyers with the codes to educate people in their communities. “What we were able to find was that just by putting these generic QR codes around the city, we were able to get hundreds and hundreds of people to click through in a very short amount of time,” Cahn says. Merchants and advertisers often like using QR codes because they get people seeing real-world ads or visiting their brick and mortar locations to visit their websites, where they can be shown additional information and also potentially targeted for special offers if they return. If the codes are from a trusted source, they’re not inherently any more risky than visiting a company’s website directly or through a search engine. But, Cahn argues, it’s very easy for anyone to put up bogus QR codes in public, whether they’re posting flyers for nonexistent events on telephone poles or slipping fake codes for viewing a menu on tables outside a restaurant. He recommends people use a search engine to find a trusted link, when possible, and says he generally asks for a paper menu when dining out. “You’re never going to be able to verify [QR codes] as easily as you can verify a URL you visit,” he says. [Photo: S.T.O.P.]Luckily, he says, many restaurants have found that QR code menus are discouraging to customers, so while these were used to facilitate contactless ordering during the height of the coronavirus pandemic, many eateries are already switching back to traditional menus.

        if(typeof(jQuery)=="function"){(function($){$.fn.fitVids=function(){}})(jQuery)};
            jwplayer('jwplayer_JOBQAEDN_G2hQKLvX_div').setup(
            {"playlist":"https:\/\/content.jwplatform.com\/feeds\/JOBQAEDN.json","ph":2}
        );

It’s also a good idea to be wary of QR codes used for payment that often show up for street vendor tables and food trucks, Cahn says. That’s because someone could surreptitiously cover up a QR code sticker with a fake one, pointing to a similarly named payment account. Cahn says he thinks QR codes will prove to be largely a fad. But however long they stay prominent, it’s a good idea to think twice before you scan them, unless you’re sure you know they’re created by someone you trust.

https://www.fastcompany.com/90690912/qr-codes-malware-problem?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 4y | Oct 28, 2021, 3:21:18 PM


Login to add comment

Other posts in this group

Why Apple iOS 26 might make you want to make phone calls again

Almost every article you’re going to read about Apple’s just-announced iOS 26 operating system f

Jun 9, 2025, 10:50:01 PM | Fast company - tech
Whole Foods’ primary distributor goes offline amid rising corporate cyberattacks

Major food wholesaler United Natural Foods (UNFI) announced Monday that it experienced “unauthorized

Jun 9, 2025, 8:30:05 PM | Fast company - tech
Apple is stuck in neutral when it comes to personal AI

“At long last, Apple has finally entered the AI race.”

That was the first line i

Jun 9, 2025, 8:30:04 PM | Fast company - tech
How Waymo got caught in the crossfire of Los Angeles ICE protests

Waymo vehicles, the self-driving taxis from Google parent company Alphabet, have emerged as a literal flashpoint

Jun 9, 2025, 8:30:03 PM | Fast company - tech
Why your phone habits leave you feeling so bad

For those who’ve been in the situation where we unlock our phone and start futzing around on our home screen, only to find ourselves looking up at the clock an hour later with a sense of shame and

Jun 9, 2025, 6:10:08 PM | Fast company - tech
The missing key for defense innovation? A good coworking space 

As the director of commercial engagement for the Defense Innovation Unit (DIU), a Department of Defense (DOD) organization that funds startups developing cutting-edge weapons technology for the mi

Jun 9, 2025, 1:30:10 PM | Fast company - tech