Beware of unknown QR codes—they could contain malware

Thanks to the pandemic, QR codes have popped up on ad posters, restaurant tables, and billboards around the world, inviting people to scan them in order to view menus and marketing information without having to type a web address into their phones. But clicking QR codes too hastily can risk bringing malware to your smartphone, cautions Albert Fox Cahn, founder and executive director of the Surveillance Technology Oversight Project (S.T.O.P.). “If someone just walked up to you on a street corner, you wouldn’t just take a thumb drive from them and plug it into your laptop,” he says. [Photo: S.T.O.P.]S.T.O.P. has been placing flyers and signs advertising fake events like comedy shows, venue openings, and trivia nights around New York City, where S.T.O.P. is based, with each bearing a QR code. Hundreds of people have scanned the QR codes and visited associated websites, which S.T.O.P. set up to bear warnings about the dangers of loading unknown QR codes, Cahn says. Now, the group is encouraging its supporters around the country to put up their own flyers with the codes to educate people in their communities. “What we were able to find was that just by putting these generic QR codes around the city, we were able to get hundreds and hundreds of people to click through in a very short amount of time,” Cahn says. Merchants and advertisers often like using QR codes because they get people seeing real-world ads or visiting their brick and mortar locations to visit their websites, where they can be shown additional information and also potentially targeted for special offers if they return. If the codes are from a trusted source, they’re not inherently any more risky than visiting a company’s website directly or through a search engine. But, Cahn argues, it’s very easy for anyone to put up bogus QR codes in public, whether they’re posting flyers for nonexistent events on telephone poles or slipping fake codes for viewing a menu on tables outside a restaurant. He recommends people use a search engine to find a trusted link, when possible, and says he generally asks for a paper menu when dining out. “You’re never going to be able to verify [QR codes] as easily as you can verify a URL you visit,” he says. [Photo: S.T.O.P.]Luckily, he says, many restaurants have found that QR code menus are discouraging to customers, so while these were used to facilitate contactless ordering during the height of the coronavirus pandemic, many eateries are already switching back to traditional menus.

        if(typeof(jQuery)=="function"){(function($){$.fn.fitVids=function(){}})(jQuery)};
            jwplayer('jwplayer_JOBQAEDN_G2hQKLvX_div').setup(
            {"playlist":"https:\/\/content.jwplatform.com\/feeds\/JOBQAEDN.json","ph":2}
        );

It’s also a good idea to be wary of QR codes used for payment that often show up for street vendor tables and food trucks, Cahn says. That’s because someone could surreptitiously cover up a QR code sticker with a fake one, pointing to a similarly named payment account. Cahn says he thinks QR codes will prove to be largely a fad. But however long they stay prominent, it’s a good idea to think twice before you scan them, unless you’re sure you know they’re created by someone you trust.

https://www.fastcompany.com/90690912/qr-codes-malware-problem?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Created 4y | Oct 28, 2021, 3:21:18 PM


Login to add comment

Other posts in this group

When will Elon Musk admit he’s bad at gaming?

Elon Musk loves to project strength. He flexes loudly—hyping Tesla and xAI, bashing the federal government, even parenting like a drill sergeant. Lately, he’s been trying to flex in gaming.

Apr 15, 2025, 12:10:04 PM | Fast company - tech
What ‘Ex Machina’ got right (and wrong) about AI, 10 years later

Before media outlets began comparing OpenAI’s Sam Altman with the father of the atomic

Apr 15, 2025, 12:10:04 PM | Fast company - tech
5 under-the-radar Kindle tricks to elevate your e-reading

At first glance, your Kindle might seem like a no-frills reading device: straightforward, minimal, and focused on the basics. Kind of like an actual book, huh?

But beneath its simple exterior lie

Apr 15, 2025, 5:10:05 AM | Fast company - tech
Elon Musk and Jack Dorsey want to kill IP law. That would be a huge mistake

Few statements communicate a sentiment more directly than the four words Jack Dorsey, a cofounder of Twitter, posted over the weekend o

Apr 14, 2025, 10:10:09 PM | Fast company - tech
Uber and Lyft drivers in California could get the right to unionize under this bill

Two California Democrats have introduced a bill that would allow rideshare drivers to bargain with gig companies, including Uber and Lyft, for better pay and certain benefits.

The measur

Apr 14, 2025, 10:10:08 PM | Fast company - tech
OpenAI launches new GPT-4.1 models with improved coding

OpenAI on Monday launched its new AI model GPT-4.1, along with smaller versions GPT-4.1 mini and GPT-4.1 nano, touting major improvements i

Apr 14, 2025, 10:10:07 PM | Fast company - tech
Why you should update your old dating app profile photos ASAP

Daters: It might be time to spring clean your dating app profile.

More than 50% of young Americans have gone on a date with someone who looked different from their profile photos, accord

Apr 14, 2025, 7:50:02 PM | Fast company - tech