- Professional Risks Insurance
- Private Clients
- Farms & Estates
- Commercial Clients
- Wholesale Insurance Broking
- Claims
- About
- Contact
- Log in
21.02.24
Quick response (QR) codes are a popular marketing, sales, payment and customer service tool for several businesses. However, as QR codes have become more prevalent, malicious actors have found ways to use them in phishing attacks and to spread malware.
These vulnerabilities can lead to significant financial and reputational damage, so it is essential for organisations to be aware of and mitigate these risks. This article provides more information on Quick Response codes and their risks and offers tips on addressing the hazards they present.
QR codes are a series of pixels arranged to form a large square that contains a long string of data. They function similarly to a barcode. They can be scanned by code readers or smartphones and often contain URLs so individuals can access websites without having to type in a specific web address. Once scanned, Quick Response codes allow a quick and convenient way for clients to access a business’s information or leave a review. They can also be used to prompt users to take certain actions, such as making a payment or downloading an app.
QR codes can be placed on various items such as posters, leaflets, menus or billboards. They can also be included as images in digital communications sent through email or messaging apps.
Although they can be a useful tool, the nature of QR codes allows them to be exploited by cyber-criminals. Since legitimate Quick Response codes appear as a random scramble of pixels within a larger square, it can be difficult for users to differentiate between the safe and malicious ones. Additionally, QR codes may be standalone images, so they may not be accompanied by tell tale signs of malicious activity, as is often the case with fraudulent emails (e.g. misspellings, suspicious links). Organisations encounter risks from QR codes in a couple of ways: They are exposed to cyber-security threats if an employee scans a malicious QR code, and if a company utilises QR codes for business purposes, their legitimate codes can be manipulated by cyber-criminals, potentially impacting their customers and their business’s reputation.
Examples of how cyber-criminals can exploit Quick Response codes include:
Once the fraudulent QR code is scanned, a user may be vulnerable to various security issues, including:
As cyber-criminals increase their use of Quick Response codes, it is essential for organisations to mitigate the risks associated with them. Strategies include the following:
Organisations wishing to use QR codes can also take steps to protect their customers. Techniques to consider include:
QR codes provide a useful function, but they can also serve as an entry point for malicious individuals to steal credentials, insert harmful software, and compromise the security of an organisation and its customers. This can lead to significant financial losses and reputational damage. By implementing risk reduction strategies, companies can protect their business, employees and clients. Contact us today for information relating to insurance to guard against the risk of cyber-crime.
Information provided by Zywave and contributed by Lisa Langley, Cert CII, Team Leader, Professional Risks, Cox Mahon Ltd.