By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
IndebtaIndebta
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Notification Show More
Aa
IndebtaIndebta
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
Indebta > News > Banks and regulators warn of rise in ‘quishing’ QR code scams
News

Banks and regulators warn of rise in ‘quishing’ QR code scams

News Room
Last updated: 2024/10/27 at 12:16 PM
By News Room
Share
5 Min Read
SHARE

Stay informed with free updates

Simply sign up to the Cyber Security myFT Digest — delivered directly to your inbox.

Banks and regulators are warning that QR code phishing scams — also known as “quishing” — are slipping through corporate cyber defences and increasingly tricking customers into giving up their financial details.

Lenders including Santander, HSBC, and TSB have joined the UK National Cyber Security Centre and US Federal Trade Commission among others to raise concerns about a rise in fraudulent QR codes being deployed for sophisticated fraud campaigns.

The new type of email scam often involves criminals sending QR codes in attached PDFs. Experts said the strategy is effective because the messages frequently get through corporate cyber security filters — software that typically flags malicious website links, but often does not scan images within attachments.

“The appeal for criminals is that it’s bypassing all of the [cyber security] training and it’s also bypassing our products,” said Chester Wisniewski, a senior adviser at security software company Sophos.

Researchers and fraud managers said it was hard to estimate the costs of “quishing” as cyber security companies and banks do not typically log the format of malicious links and because such emails may be just one element in a broader cyber attack.

But research by IBM found that “phishing” attacks — which involve scammers send targeted emails with malicious links — are increasingly expensive to companies, with the global average cost of a data breach rising nearly 10 per cent to $4.9mn in 2024.

QR codes contain data, such as URLs or payment information, in binary code. Invented by Japanese company Denso Wave in 1994 as a tool for tracking auto parts, these codes are designed to be quickly readable by machines, particularly smartphones, but are generally illegible to humans.

Although most smartphones display a short preview of the URL contained in a scanned QR code, researchers have said that this pop-up is generally not sufficient for users to be able to detect that a link might be fraudulent.

“These attacks take advantage of the fact that QR codes, by nature, are difficult to interpret visually, so victims often don’t know where they are being directed to until it’s too late,” said Amir Sadon, director of research at cyber security consultancy Sygnia.

Banks said that the prevalence of this kind of scam has accelerated since QR codes surged in popularity during the Covid-19 pandemic, when they were used to display everything from vaccine passports to restaurant menus. “It’s definitely a growing trend in terms of the number of reports we’re seeing,” said Steph Harrison, a senior fraud operations manager at TSB.

A survey by security software company McAfee in May found that more than a fifth of all online scams in the UK probably originated from QR codes. Reports of QR code scams in the UK more than doubled in the year to August 2024, according to Action Fraud.

The US Federal Trade Commission, as well as multiple local authorities across the UK, also warned this year about a specific kind of “quishing” scam targeting drivers, including cases where stickers directing users to fraudulent sites have been placed on top of legitimate QR codes used to pay for parking.

These links may direct users to an incorrect website and ask them to enter their details, or lead them to download malware. Worse still, said Harrison, “you could also get fined for not actually having a parking ticket”.

Victims have also reported fraudulent QR codes being placed over legitimate ones at EV charging points, train stations and restaurant tables.

But researchers said that “quishing” scams are most commonly deployed in emails — a threat that has put corporate security vendors under pressure to adapt their online defences.

“Today almost no [cyber security] products are looking through attachments,” said Wisniewski. “If this continues to be a problem, I suppose the industry will have to move there — but it will slow down the delivery of emails, and it will also make things more expensive.”

Read the full article here

News Room October 27, 2024 October 27, 2024
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
Mark Rutte, Europe’s Trump whisperer-in-chief

The morning after striking a deal with Donald Trump over Greenland that…

Ukraine must give up territory for war to end, Russia insists ahead of talks

Unlock the White House Watch newsletter for freeYour guide to what Trump’s…

Revolut scraps US merger plans in favour of push for standalone licence

Stay informed with free updatesSimply sign up to the Fintech myFT Digest…

US stocks end winning streak, bitcoin sell off continues, the rise of prediction markets and risks

Watch full video on YouTube

Who Will Be The Next JPMorgan Chase CEO?

Watch full video on YouTube

- Advertisement -
Ad imageAd image

You Might Also Like

News

Mark Rutte, Europe’s Trump whisperer-in-chief

By News Room
News

Ukraine must give up territory for war to end, Russia insists ahead of talks

By News Room
News

Revolut scraps US merger plans in favour of push for standalone licence

By News Room
News

Pathward Financial, Inc. (CASH) Q1 2026 Earnings Call Transcript

By News Room
News

Flatter Trump or fight him? Smart billionaires do both

By News Room
News

Intel shares slide as chipmaker says supply chain constraints will limit growth

By News Room
News

Venezuela’s lawmakers back oil sector reforms

By News Room
News

French supertax on wealthy raises only a quarter of planned revenue

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?