Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Are QR Codes Convenient or Risky? What Your Business Needs to Know

Author: Scarinci Hollenbeck, LLC

Date: March 29, 2022

Key Contacts

Back
Are QR Codes Convenient or Risky? What Your Business Needs to Know

Should businesses and consumers be wary of QR codes?

Quick Response bar codes (better known as QR codes) are everywhere, from restaurant menus to product packaging. One company even floated one across fans’ television screens during the Super Bowl this year. But should businesses and consumers be wary of QR codes?

QR Code Use Increased During the Pandemic

Essentially, a QR code is a square barcode that a smartphone camera can scan and read to provide quick access to a website, prompt the download of an application, and direct payment to an intended recipient. The use of QR codes grew exponentially during the COVID-19 pandemic as they allowed businesses to provide “touch-free” services to customers and eliminate the need for paper items, such as menus and bills.

FBI Bulletin Warns Cybercriminals Are Targeting QR Codes

Unfortunately, cybercriminals have taken notice of our increased reliance on QR codes and stepped up their attacks. The increased cyber risks of using QR codes recently prompted the Federal Bureau of Investigation to issue an alert to both businesses and consumers.

“Businesses use QR codes legitimately to provide convenient contactless access and have used them more frequently during the COVID-19 pandemic,” the FBI bulletin stated. “However, cybercriminals are taking advantage of this technology by directing QR code scans to malicious sites to steal victim data, embedding malware to gain access to the victim’s device, and redirecting payment for cybercriminal use.”

Cybercriminals are targeting both digital and physical QR codes by replacing legitimate codes with malicious codes. According to the FBI, in a typical QR code scam, a victim scans what they think to be a legitimate code but the tampered code directs victims to a malicious site, which prompts them to enter login and financial information. Access to this victim information allows the hacker to potentially steal funds through victim accounts. Malicious QR codes may also contain embedded malware, which provides access to the victim’s mobile device and allows hackers to steal the victim’s location, along with personal and financial information.

Another version of the scam involves QR codes used by businesses to facilitate payment. When a business provides customers with a QR code directing them to a site where they can complete a payment transaction, cybercriminals can replace the intended code with a tampered QR code and redirect the sender’s payment for cybercriminal use.

The FBI offers the following tips to lower the risk of falling victim to QR code fraud:

  • Once you scan a QR code, check the URL to make sure it is the intended site and looks authentic. A malicious domain name may be similar to the intended URL but with typos or a misplaced letter.
  • Practice caution when entering login, personal, or financial information from a site navigated to from a QR code.
  • If scanning a physical QR code, ensure the code has not been tampered with, such as with a sticker placed on top of the original code.
  • Do not download an app from a QR code. Use your phone’s app store for a safer download.
  • If you receive an email stating a payment failed from a company you recently made a purchase with and the company states you can only complete the payment through a QR code, call the company to verify. Locate the company’s phone number through a trusted site rather than a number provided in the email.
  • Do not download a QR code scanner app. This increases your risk of downloading malware onto your device. Most phones have a built-in scanner through the camera app.
  • If you receive a QR code that you believe to be from someone you know, reach out to them through a known number or address to verify that the code is from them.
  • Avoid making payments through a site navigated to from a QR code. Instead, manually enter a known and trusted URL to complete the payment.

For businesses, there are also steps you can take to deter QR code fraud. Examples include generating dynamic QR codes at checkout, regularly policing QR codes for tampering, and not placing physical QR codes where they can easily be tampered with. While you likely will not be held liable if a customer is scammed, because QR fraud can’t erode trust and damage your brand, it is important to be vigilant.

If you have questions, please contact us

If you have any questions or if you would like to discuss the matter further, please contact me, Maryam Meseha, or the Scarinci Hollenbeck attorney with whom you work, at 201-896-4100.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What? post image

You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What?

Receiving a federal grand jury subpoena is not something most businesses or individuals anticipate. While it can be concerning, a federal grand jury subpoena does not necessarily mean that you are being accused of wrongdoing. It does, however, mean that a federal criminal investigation is underway and that federal prosecutors believe you may possess information […]

Author: George McGowan

Link to post with title - "You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What?"
Why Every Business Should Conduct an Annual Insurance Coverage Review post image

Why Every Business Should Conduct an Annual Insurance Coverage Review

Most New Jersey business owners purchase insurance policies, file them away, and assume they are protected if a claim arises. Without a regular insurance coverage review, many companies discover gaps only after a lawsuit, cyberattack, property loss, or other significant event occurs. An annual insurance coverage review can help businesses identify potential risks, ensure their […]

Author: George McGowan

Link to post with title - "Why Every Business Should Conduct an Annual Insurance Coverage Review"
Demand Letters & Cease and Desist Letters: When to Send One (and When Not To) post image

Demand Letters & Cease and Desist Letters: When to Send One (and When Not To)

Businesses and individuals often encounter situations where another party breaches a contract, fails to pay a debt, or continues harmful conduct. In many such disputes, a precisely drafted demand letter or cease-and-desist letter serves as a powerful legal tool. It can frequently resolve the dispute and avoid litigation. While demand or cease-and-desist letters can resolve […]

Author: George McGowan

Link to post with title - "Demand Letters & Cease and Desist Letters: When to Send One (and When Not To)"
How to Effectively Use Contracts to Manage Risk post image

How to Effectively Use Contracts to Manage Risk

Key provisions in your contracts, including those relating to indemnification, insurance, and defense, are essential to contract risk management. While sometimes considered “boilerplate,” these provisions play a pivotal role when determining which party is responsible for certain costs and liabilities. They must always be negotiated and drafted carefully. Indemnification Clauses Businesses should never overlook the […]

Author: George McGowan

Link to post with title - "How to Effectively Use Contracts to Manage Risk"
Understanding Portability for Estate and Gift Tax post image

Understanding Portability for Estate and Gift Tax

Portability of estate and gift tax enables a surviving spouse to inherit any unused portion of their deceased spouse’s federal estate and gift tax exemption. So, if one spouse doesn’t utilize their full exemption, the surviving spouse can effectively double their exemption amount with regard to estate tax liability. For married couples, portability offers a […]

Author: Marc J. Comer

Link to post with title - "Understanding Portability for Estate and Gift Tax"
Pet Trusts in New Jersey and New York: A Practical Estate Planning Tool post image

Pet Trusts in New Jersey and New York: A Practical Estate Planning Tool

For many of us, pets are more than companions—they are members of the family. Yet they are often overlooked or inadequately provided for when it comes to estate planning. A pet trust offers a legally enforceable way to ensure that your animal continues to receive proper care if you become incapacitated or pass away. As […]

Author: Marc J. Comer

Link to post with title - "Pet Trusts in New Jersey and New York: A Practical Estate Planning Tool"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
“If you would like to submit a file, please email it directly to info@sh-law.com.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!