Beware of unknown QR codes—they could contain malware

Thanks to the pandemic, QR codes have popped up on ad posters, restaurant tables, and billboards around the world, inviting people to scan them in order to view menus and marketing information without having to type a web address into their phones. But clicking QR codes too hastily can risk bringing malware to your smartphone, cautions Albert Fox Cahn, founder and executive director of the Surveillance Technology Oversight Project (S.T.O.P.). “If someone just walked up to you on a street corner, you wouldn’t just take a thumb drive from them and plug it into your laptop,” he says. [Photo: S.T.O.P.]S.T.O.P. has been placing flyers and signs advertising fake events like comedy shows, venue openings, and trivia nights around New York City, where S.T.O.P. is based, with each bearing a QR code. Hundreds of people have scanned the QR codes and visited associated websites, which S.T.O.P. set up to bear warnings about the dangers of loading unknown QR codes, Cahn says. Now, the group is encouraging its supporters around the country to put up their own flyers with the codes to educate people in their communities. “What we were able to find was that just by putting these generic QR codes around the city, we were able to get hundreds and hundreds of people to click through in a very short amount of time,” Cahn says. Merchants and advertisers often like using QR codes because they get people seeing real-world ads or visiting their brick and mortar locations to visit their websites, where they can be shown additional information and also potentially targeted for special offers if they return. If the codes are from a trusted source, they’re not inherently any more risky than visiting a company’s website directly or through a search engine. But, Cahn argues, it’s very easy for anyone to put up bogus QR codes in public, whether they’re posting flyers for nonexistent events on telephone poles or slipping fake codes for viewing a menu on tables outside a restaurant. He recommends people use a search engine to find a trusted link, when possible, and says he generally asks for a paper menu when dining out. “You’re never going to be able to verify [QR codes] as easily as you can verify a URL you visit,” he says. [Photo: S.T.O.P.]Luckily, he says, many restaurants have found that QR code menus are discouraging to customers, so while these were used to facilitate contactless ordering during the height of the coronavirus pandemic, many eateries are already switching back to traditional menus.

        if(typeof(jQuery)=="function"){(function($){$.fn.fitVids=function(){}})(jQuery)};
            jwplayer('jwplayer_JOBQAEDN_G2hQKLvX_div').setup(
            {"playlist":"https:\/\/content.jwplatform.com\/feeds\/JOBQAEDN.json","ph":2}
        );

It’s also a good idea to be wary of QR codes used for payment that often show up for street vendor tables and food trucks, Cahn says. That’s because someone could surreptitiously cover up a QR code sticker with a fake one, pointing to a similarly named payment account. Cahn says he thinks QR codes will prove to be largely a fad. But however long they stay prominent, it’s a good idea to think twice before you scan them, unless you’re sure you know they’re created by someone you trust.

https://www.fastcompany.com/90690912/qr-codes-malware-problem?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 4y | Oct 28, 2021, 3:21:18 PM


Login to add comment

Other posts in this group

‘Democratizing space’ requires addressing questions of sustainability and sovereignty

India is on the moon,” S. Somanath, chairman of the Indian Space Research Organization, announced in

Jul 25, 2025, 10:30:06 AM | Fast company - tech
iPadOS 26 is way more Mac-like. Where does that lead?

Greetings, everyone, and welcome back to Fast Company’s Plugged In.

It was one of the best-received pieces of Apple news I can recall. At the company’s

Jul 25, 2025, 8:20:03 AM | Fast company - tech
Elon Musk says he’s bringing back Vine in AI form. Here’s what that could mean

Good news: Vine might be coming back. Bad news: in AI form, courtesy o

Jul 24, 2025, 10:50:08 PM | Fast company - tech
Apple’s iOS 26 public beta is out. Here’s how to install it safely

A stable “release” version of Apple’s iOS 26 is due in September, but you can now try an in-progress version, called the public beta. It previews a revamped interface and new fea

Jul 24, 2025, 8:40:06 PM | Fast company - tech
Apple iOS 26 is now available to the public. Here’s how to get it—and 5 useful new features to try

In June, Apple previewed the iPhone’s next operating system, iOS 26. Without a doubt, the headline feature of iOS 26 (yes, the iPhone’s OS

Jul 24, 2025, 8:40:04 PM | Fast company - tech
Hulk Hogan changed media forever with his ‘Gawker’ lawsuit

">Tear a tanktop in half today for Terry Bollea, the entertainer better known as Hulk Hogan, who has died at age 71.

Though he was

Jul 24, 2025, 8:40:03 PM | Fast company - tech
Trump’s ‘AI Action Plan’ smoothes the way for a bulked-up electrical grid

Welcome to AI DecodedFast Company’s weekly newsletter that breaks down the most important news in

Jul 24, 2025, 6:20:06 PM | Fast company - tech