Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Are QR Codes Convenient or Risky? What Your Business Needs to Know

Author: Scarinci Hollenbeck, LLC

Date: March 29, 2022

Key Contacts

Back
Are QR Codes Convenient or Risky? What Your Business Needs to Know

Should businesses and consumers be wary of QR codes?

Quick Response bar codes (better known as QR codes) are everywhere, from restaurant menus to product packaging. One company even floated one across fans’ television screens during the Super Bowl this year. But should businesses and consumers be wary of QR codes?

QR Code Use Increased During the Pandemic

Essentially, a QR code is a square barcode that a smartphone camera can scan and read to provide quick access to a website, prompt the download of an application, and direct payment to an intended recipient. The use of QR codes grew exponentially during the COVID-19 pandemic as they allowed businesses to provide “touch-free” services to customers and eliminate the need for paper items, such as menus and bills.

FBI Bulletin Warns Cybercriminals Are Targeting QR Codes

Unfortunately, cybercriminals have taken notice of our increased reliance on QR codes and stepped up their attacks. The increased cyber risks of using QR codes recently prompted the Federal Bureau of Investigation to issue an alert to both businesses and consumers.

“Businesses use QR codes legitimately to provide convenient contactless access and have used them more frequently during the COVID-19 pandemic,” the FBI bulletin stated. “However, cybercriminals are taking advantage of this technology by directing QR code scans to malicious sites to steal victim data, embedding malware to gain access to the victim’s device, and redirecting payment for cybercriminal use.”

Cybercriminals are targeting both digital and physical QR codes by replacing legitimate codes with malicious codes. According to the FBI, in a typical QR code scam, a victim scans what they think to be a legitimate code but the tampered code directs victims to a malicious site, which prompts them to enter login and financial information. Access to this victim information allows the hacker to potentially steal funds through victim accounts. Malicious QR codes may also contain embedded malware, which provides access to the victim’s mobile device and allows hackers to steal the victim’s location, along with personal and financial information.

Another version of the scam involves QR codes used by businesses to facilitate payment. When a business provides customers with a QR code directing them to a site where they can complete a payment transaction, cybercriminals can replace the intended code with a tampered QR code and redirect the sender’s payment for cybercriminal use.

The FBI offers the following tips to lower the risk of falling victim to QR code fraud:

  • Once you scan a QR code, check the URL to make sure it is the intended site and looks authentic. A malicious domain name may be similar to the intended URL but with typos or a misplaced letter.
  • Practice caution when entering login, personal, or financial information from a site navigated to from a QR code.
  • If scanning a physical QR code, ensure the code has not been tampered with, such as with a sticker placed on top of the original code.
  • Do not download an app from a QR code. Use your phone’s app store for a safer download.
  • If you receive an email stating a payment failed from a company you recently made a purchase with and the company states you can only complete the payment through a QR code, call the company to verify. Locate the company’s phone number through a trusted site rather than a number provided in the email.
  • Do not download a QR code scanner app. This increases your risk of downloading malware onto your device. Most phones have a built-in scanner through the camera app.
  • If you receive a QR code that you believe to be from someone you know, reach out to them through a known number or address to verify that the code is from them.
  • Avoid making payments through a site navigated to from a QR code. Instead, manually enter a known and trusted URL to complete the payment.

For businesses, there are also steps you can take to deter QR code fraud. Examples include generating dynamic QR codes at checkout, regularly policing QR codes for tampering, and not placing physical QR codes where they can easily be tampered with. While you likely will not be held liable if a customer is scammed, because QR fraud can’t erode trust and damage your brand, it is important to be vigilant.

If you have questions, please contact us

If you have any questions or if you would like to discuss the matter further, please contact me, Maryam Meseha, or the Scarinci Hollenbeck attorney with whom you work, at 201-896-4100.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Dissolving Your Business: Essential Legal Steps to Protect Your Interests post image

Dissolving Your Business: Essential Legal Steps to Protect Your Interests

If you’re considering closing your business, it’s crucial to understand that simply shutting your doors does not end your legal obligations. Unless you formally dissolve your business, it continues to exist in the eyes of the law—leaving you exposed to ongoing liabilities such as taxes, compliance violations, and potential lawsuits. Dissolving a business can seem […]

Author: Christopher D. Warren

Link to post with title - "Dissolving Your Business: Essential Legal Steps to Protect Your Interests"
The Role of Corporate Restructuring in Mergers & Acquisitions post image

The Role of Corporate Restructuring in Mergers & Acquisitions

Contrary to what many people think, corporate restructuring isn’t all doom and gloom. Revamping a company’s organizational structure, corporate hierarchy, or operations procedures can help keep your business competitive. This is particularly true during challenging times. Corporate restructuring plays a critical role in modern business strategy. It helps companies adapt quickly to market changes. Following […]

Author: Dan Brecher

Link to post with title - "The Role of Corporate Restructuring in Mergers & Acquisitions"
Crypto Enforcement: A Former Prosecutor’s Warning to Criminals and the Public post image

Crypto Enforcement: A Former Prosecutor’s Warning to Criminals and the Public

Cryptocurrency intimidates most people. The reason is straightforward. People fear what they do not understand. When confusion sets in, the common reaction is either to ignore the subject entirely or to mistrust it. For years, that is exactly how most of the public and even many in law enforcement treated cryptocurrency. However, such apprehension changed […]

Author: Bryce S. Robins

Link to post with title - "Crypto Enforcement: A Former Prosecutor’s Warning to Criminals and the Public"
Understanding Chattel Paper: A Key Component in Secured Transactions post image

Understanding Chattel Paper: A Key Component in Secured Transactions

Using chattel paper to obtain a security interest in personal property is a powerful tool. It can ensure lenders have a legal claim on collateral ranging from inventory to intellectual property. To reduce risk and protect your legal rights, businesses and lenders should understand the legal framework. This framework governs the creation, sale, and enforcement […]

Author: Dan Brecher

Link to post with title - "Understanding Chattel Paper: A Key Component in Secured Transactions"
Crypto Compliance: A Comprehensive Guide post image

Crypto Compliance: A Comprehensive Guide

For years, digital assets operated in a legal gray area, a frontier where innovation outpaced the reach of regulators and law enforcement. In this early “Wild West” phase of finance, crypto startups thrived under minimal oversight. That era, however, is coming to an end. The importance of crypto compliance has become paramount as cryptocurrency has […]

Author: Bryce S. Robins

Link to post with title - "Crypto Compliance: A Comprehensive Guide"
Supreme Court and Title VII: Implications for Reverse Discrimination post image

Supreme Court and Title VII: Implications for Reverse Discrimination

Earlier this month, the U.S. Supreme Court issued a decision in Ames v. Ohio Department of Youth Services vitiating the so-called “background circumstances” test required by half of federal circuit courts.1 The background circumstances test required majority group plaintiffs pleading discrimination under Title VII of the Civil Rights Act to meet a heightened pleading standard […]

Author: Matthew F. Mimnaugh

Link to post with title - "Supreme Court and Title VII: Implications for Reverse Discrimination"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!