logo
QR code scams rise as 73% of Americans scan without checking

QR code scams rise as 73% of Americans scan without checking

Fox News07-08-2025
By now, many of us have used QR codes as a way to quickly access menus, check into places, and make payments. But now, these convenient and contactless methods have become an easy target for cybercriminals. There has been a recent surge in "quishing" attacks, which are a form of phishing that uses QR codes instead of traditional methods like emails, text messages, and phone calls.
Quishing is proving effective, too, with millions of people unknowingly opening malicious websites. In fact, 73% of Americans admit to scanning QR codes without checking if the source is legitimate. As experts warn, this growing trend could put people's personal information and money at risk.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM/NEWSLETTER.
NordVPN's security researchers report that fake QR codes have tricked over 26 million people into visiting malicious websites. These codes hide in plain sight, too. In one case, they were stuck on top of payment portals, sending unsuspecting individuals to sites meant to steal their personal and financial data (e.g., passwords and credit card information). Some even installed malware on people's phones.
Even government agencies have taken notice. The FTC warned the public earlier this year that cybercriminals are now attaching harmful QR codes to packages and sending them to people. The New York City Department of Transportation issued warnings about fake QR codes appearing on parking meters of all places. Even Hawaii Electric chimed in, as they noticed scammers are using QR codes to steal payments.
These tactics mirror the ATM skimmer scam, where criminals place keypads designed to log keystrokes over an ATM to steal card information. But with QR codes, this tampering is harder to spot and easier to implement.
The original purpose of QR codes was to track auto parts, so making them secure wasn't part of the plan. Their widespread use today has made them irresistible to scammers. Unlike traditional phishing methods, they make it easy for cybercriminals to hide their destination until scanned, removing an important layer of user scrutiny.
Hackers are leveraging this ambiguity to deploy Remote Access Trojans (RATs) and infiltrate personal devices, including military networks. More than 26% of malicious links now come via QR codes, according to KeepNet Labs, a cybersecurity company specializing in AI-driven phishing simulation and human risk management. Soon, quishing will outpace conventional phishing.
If you scan QR codes regularly, you might be panicking. But don't be, since the same tricks for avoiding phishing scams can also work here.
Pause and consider the origin of every QR code before you pull out your phone. Quishing thrives on people scanning codes found on public signage, restaurant tables, packages, or payment terminals without questioning their authenticity. Cybercriminals often cover genuine QR codes with malicious ones that redirect users to fake websites meant to steal personal and financial information. Always ask yourself: Do I trust this location or the person who provided this QR code? If in doubt, don't scan.
Consider using a reputable personal data removal service. These services routinely scan the web for your personal details (like addresses, phone numbers, and emails), removing them from public databases where cybercriminals might collect information to personalize their quishing lures.
While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com/Delete.Get a free scan to find out if your personal information is already out on the web: Cyberguy.com/FreeScan.
Inspect the QR code's placement. Sophisticated scammers physically overlay fake QR codes on legitimate signs, especially on payment kiosks, parking meters, and package labels. If the QR code looks tampered with or is a sticker poorly placed over another code, avoid scanning it, as this is a common quishing tactic to redirect you to a malicious site.
After scanning any QR code, double-check the URL before clicking through. One of quishing's dangers is that QR codes obscure their destination until scanned. If the web address looks suspicious, misspelled, unusually long, or filled with random characters, close the browser immediately. Never enter sensitive details like passwords or credit card information on a site you weren't expecting to visit.
Install strong antivirus software across all your devices. Look for a solution that offers real-time protection, regularly updated threat databases, and built-in web protection. These tools can help detect malicious content hidden in QR codes and block dangerous websites that might automatically open after scanning. Since QR codes are increasingly used by cybercriminals to spread malware like Remote Access Trojans (RATs), having strong antivirus software in place is essential. To stay fully protected, make sure the software is set to update automatically and scan regularly.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices CyberGuy.com/LockUpYourTech.
Even if attackers capture your credentials via a fake QR code, two-factor authentication creates an extra barrier. Always activate 2FA on your accounts, especially for email, banking, and other sensitive services. It thwarts many of the most damaging results of phishing, including those initiated by QR code scans.
Whenever possible, manually navigate to websites instead of using a QR code, especially for payments, reservations, or account access. Searching for an event, restaurant, or service online reduces the chance of being tricked by a malicious redirect or fraudulent site.
Frequently update your phone's operating system and apps. Criminals often exploit software vulnerabilities, and manufacturers regularly issue security patches. Up-to-date devices are less susceptible to malware installed via malicious QR codes.
If you encounter what you believe to be a fraudulent QR code or fall victim to a quishing attempt, report it immediately to the organization involved and your local authorities or consumer protection agency. Your report helps others avoid similar attacks and keeps organizations alert to evolving scam tactics.
By applying these steps, you make it significantly harder for cybercriminals to use QR codes as a gateway to your personal or financial information. In a world where 73% of Americans scan QR codes without checking the source, increased caution is your first and best line of defense against the quishing surge.
QR codes are super convenient, but the risks they bring are becoming impossible to ignore. And you can count on scammers getting more creative as time goes on. That doesn't mean you have to stop using QR codes altogether, it just means staying informed and cautious is a must, because QR codes aren't going anywhere anytime soon.
Will you avoid QR codes from now on, or will you be extra cautious moving forward? Let us know by writing to us at Cyberguy.com/Contact.
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM/NEWSLETTER.
Copyright 2025 CyberGuy.com. All rights reserved.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

JD Vance 'directly' convinced UK to drop Apple backdoor data demand, protecting Americans' rights: US official
JD Vance 'directly' convinced UK to drop Apple backdoor data demand, protecting Americans' rights: US official

Fox News

time3 hours ago

  • Fox News

JD Vance 'directly' convinced UK to drop Apple backdoor data demand, protecting Americans' rights: US official

Vice President JD Vance – who eviscerated European leaders earlier this year for allegedly retreating on free speech, essentially threatening fundamental democratic values – recently played a commanding role in convincing the United Kingdom to drop its demands that Apple provide the British government a "backdoor" to personal user data, Fox News Digital has learned. A U.S. official told Fox News Digital that Vance "was in charge and was personally involved in negotiating a deal, including having direct conversations with the British government." Working with U.K. partners, the vice president "negotiated a mutually beneficial understanding" that the British government "will withdraw the current backdoor order to Apple," the U.S. official said, adding that the "agreement between our two governments maintains each country's sovereignty while ensuring close cooperation on data sharing." The U.S. official further told Fox News Digital that the vice president "took a strong interest in this issue because of his background in technology, his concern for privacy, and his [sincere] commitment to maintain a strong U.S.-U.K. relationship." Director of National Intelligence (DNI) Tulsi Gabbard said in an X post on Monday that she, alongside President Donald Trump and Vance, had been working "closely with our partners in the U.K." over the past several months "to ensure Americans' private data remains private and our Constitutional rights and civil liberties are protected." "As a result, the UK has agreed to drop its mandate for Apple to provide a 'back door' that would have enabled access to the protected encrypted data of American citizens and encroached on our civil liberties," Gabbard wrote. Fox News Digital reached out to Apple and the British Home Office for comment but did not immediately hear back. In February, Sen. Ron Wyden, D-Ore., and Rep. Andy Biggs, R-Ariz., penned a letter to the then-newly confirmed DNI, informing Gabbard of recent press reports that the U.K.'s home secretary "served Apple with a secret order" at the start of the year, "directing the company to weaken the security of its iCloud backup service to facilitate government spying." The directive reportedly required Apple to weaken the encryption of its iCloud backup service, giving the British government "blanket capability" to access customers' encrypted files. Reports further stated that the order was issued under the U.K.'s Investigatory Powers Act 2016, commonly known as the "Snoopers' Charter," which does not require a judge's approval, according to the letter previously obtained by Fox News Digital. Wyden, who sits on the Senate Intelligence Committee, and Biggs, who chairs a House Judiciary subcommittee on Crime and Federal Government Surveillance, informed Gabbard that Apple "is reportedly gagged from acknowledging that it received such an order, and the company faces criminal penalties that prevent it from even confirming to the U.S. Congress the accuracy of these press reports." The letter focused on the threat of China, Russia and other adversaries spying on Americans. At the Munich Security Conference in February, Vance, meanwhile, said that the threat he worried about the most when it comes to Europe was not China, Russia or "any other external actor," but rather "the threat from within the retreat of Europe from some of its most fundamental values, values shared with the United States of America." Vance specifically cited the case of Adam Smith-Connor, a British Army veteran and physiotherapist, who was prosecuted under the U.K.'s "buffer zone" or "safe access zone" laws around abortion clinics. British police confronted him for silently praying outside the clinic. The vice president also called out Europe more broadly for stifling opposition speech. "To many of us on the other side of the Atlantic, it looks more and more like old, entrenched interests hiding behind ugly Soviet-era words like misinformation and disinformation, who simply don't like the idea that somebody with an alternative viewpoint might express a different opinion or, God forbid, vote a different way, or even worse, win an election," Vance said at the time. More recently, Vance made a diplomatic visit to the U.K. earlier this month, meeting with the British foreign secretary for talks centered on the Ukraine-Russia and Israel-Hamas wars. Last week, the State Department, meanwhile, released its 2024 annual country report on "human rights practices." In the report on the United Kingdom, the Trump administration cited "credible reports of serious restrictions on freedom of expression," including "enforcement of or threat of criminal or civil laws in order to limit expression; and crimes, violence, or threats of violence motivated by antisemitism." The State Department asserted that the British government "sometimes took credible steps to identify and punish officials who committed human rights abuses, but prosecution and punishment for such abuses was inconsistent." The report said British authorities, including the U.K. Office of Communications (Ofcom), are legally authorized to monitor all forms of communication for speech they deemed "illegal." The U.K. Online Safety Act of 2023, which came into force in 2024, "defined the category of 'online harm' and expressly expanded Ofcom's authority to include American media and technology firms with a substantial number of British users, regardless of whether they had a corporate presence in the UK," according to the State Department. Under the law, the report said, companies were required to engage in proactive "illegal content risk assessment" to mitigate the risk of users encountering speech deemed illegal by Ofcom. "Experts warned that one effect of the bill could be government regulation to reduce or eliminate effective encryption (and therefore user privacy) on platforms," the report said. The U.K. has been increasingly cracking down on British citizens for opposition commentary, especially online posts and memes opposing mass migration. In August 2024, as riots broke out in the U.K. after a mass stabbing at a Taylor Swift-themed dance event left three girls dead and others wounded, London's Metropolitan Police chief warned that officials could also extradite and jail U.S. citizens for online posts about the unrest. In its report, the State Department noted that the local and national government officials in the wake of the Southport attack "repeatedly intervened to chill speech as to the identity and motives of the attacker," who was later identified as Axel Rudakubana, a British citizen of Rwandan origins. The British government "called on companies, including U.S. firms, to censor speech deemed misinformation or 'hate speech,'" according to the State Department, which also noted that Director of Public Prosecutions Stephen Parkinson threatened to prosecute and seek the extradition of those who "repost, repeat, or amplify a message which is false, threatening, or stirs up racial/religious hatred." The report noted that numerous individuals were arrested for online speech about the attack and its motivations, though in some cases charges were later dropped. "Numerous nongovernment organizations (NGOs) and media outlets criticized the government's approach to censoring speech, both in principle and in the perceived weaponization of law enforcement against political views disfavored by authorities."

Real-Time KYC And Agentic AI: The New Standard In Fraud Prevention
Real-Time KYC And Agentic AI: The New Standard In Fraud Prevention

Forbes

time4 hours ago

  • Forbes

Real-Time KYC And Agentic AI: The New Standard In Fraud Prevention

Atal Bansal is the Founder and CEO at Chetu, a global U.S.-based custom software solutions and support services provider. In an era when identity theft is flourishing, there is a growing need for everyone to verify who someone really is—fast and securely. The issue is particularly acute in the business arena, where hospitals, banks, retailers and government agencies have a burning need for a seamless identity verification process that detects fraud without making life difficult for genuine customers. Indeed, the identity theft protection market is booming, with an expected value of over $23 billion by 2029. Still, in 2024, according to the FTC, fraud drained $12.5 billion out of the pockets of hard-working people. That figure was up 25% from the previous year—with investment scams alone accounting for $5.7 billion. That huge jump emphasizes just how urgent it is to get smarter with real-time identity checks powered by artificial intelligence (AI) and agentic AI. Real-Time Know Your Customer And Instant Document Processing Technology has allowed criminals to develop sophisticated identity theft fraud. But if human innovation has helped them develop more complex scams, it also creates ways to catch them. Real-time AI-based know-your-customer (KYC) technology is becoming huge in the payment sector. This method of streamlining the digital identity verification process for merchants and end users not only prevents fraud but also ensures regulatory compliance. Working in coordination with KYC is instant document processing (IDP) because it automates information extraction, validates the data and analyzes the customer-submitted documents. AI-driven IDP relies more often on biometric authentication—such as facial and voice recognition, fingerprint scans and liveness detection—to verify people. There is already evidence that AI tools are working. IBM reports that AI fraud detection jumped by 6% at American Express and 10% at PayPal. One recently published paper claimed that AI algorithms reduced investigation durations by 70% and achieved stunning detection rates of nearly 97% for specific fraud categories. Google Cloud, after a successful pilot program with HSBC, one of the world's largest banks, has released its anti-money laundering AI (AML AI) platform. This system 'provides risk scores based on transaction data, accounts, know-your-customer (KYC) information and previous suspicious activity, which analysts review in a case management system.' During the trial program, HSBC saw a 60% decrease in false positives and a two to four times increase in positive alerts. Mastercard uses its AI-powered decision intelligence system to analyze in real time 1 trillion data points to determine if a 'transaction is likely to be genuine or not.' This advanced technology verifies transaction risk in less than 50 milliseconds. AI And Agentic AI Raise KYC And IDP To A New Level While in-person verification, checking driver's licenses, security questions or utility bills to determine addresses are not going away any time soon, they are no longer adequate. In the modern world, AI algorithms instantly analyze documents, identify possible fraudulent behavior and calculate risk scores. The next step is incorporating agentic AI technology, which automates systems so they can operate independently of humans. It can pause a process if a fingerprint or geolocation seems off, triggering the need for additional verification. These self-directed actions accelerate the verification process, thereby preventing bad actors from engaging in illicit trades. Oracle just launched its agentic AI system to fight fraud. Buy Vs. Build Vs. Hybrid Approach Businesses usually have three choices when it comes to deploying these solutions: Buy a ready-made solution, build a customized proprietary platform or do a little of both. Getting an out-of-the-box system is generally the least expensive and fastest option, which makes it a favorite for smaller enterprises or startups. Plus, it should meet compliance standards. However, some companies are looking for greater customization. Building a system gives you total control to accommodate your specific business model. Although this approach has higher upfront costs, there should be lower ongoing expenses because it does not require a monthly subscription fee. The third way is also worth consideration. Using a hybrid approach gives businesses access to fast and trusted vendor tools along with the added benefits from customized improvements done by expert software solution providers. For the latter two options, companies need highly skilled IT members or a software development partner with AI and payment software expertise. Challenges And Advantages Of AI Automation Of course, organizations can rely too heavily on AI automation, which could result in false positives and negatives if there is no one in the control booth double-checking the work periodically. Companies must also commit to ongoing maintenance of their systems, and AI systems are particularly data-hungry, as they require current information to stay up to date. KYC systems also need to be transparent, enabling them to explain a rejected application. However, even with these challenges, investing in strong identity protection is essential to building a secure, competitive and scalable digital future. By adopting real-time KYC and IDP systems—powered by AI and agentic AI—the payment sector gains valuable tools that allow for faster and more accurate identity verification. Ultimately, this helps create an environment that makes everyone a little happier and more secure. Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

‘I thought I was going to die there': Voices of migrants deported to a Salvadoran prison
‘I thought I was going to die there': Voices of migrants deported to a Salvadoran prison

Los Angeles Times

time5 hours ago

  • Los Angeles Times

‘I thought I was going to die there': Voices of migrants deported to a Salvadoran prison

CARACAS, Venezuela — In March, President Trump invoked the 1798 Alien Enemies Act to declare Venezuela's Tren de Aragua gang a foreign terrorist group. Shortly after, the U.S. sent more than 250 Venezuelans who it said were a part of the gang to El Salvador, where they were jailed for months in one of the country's most notorious prisons, the Terrorism Confinement Center, also known as CECOT. Many of the men insist that they have no ties to the gang and were denied due process. After enduring months in detention, the men were sent home in July as part of a prisoner exchange deal that included Venezuela's release of several detained Americans. Venezuela's attorney general said interviews with the men revealed 'systemic torture' in the Salvadoran prison, including daily beatings, rancid food and sexual abuse. The men have been adjusting to life back in Venezuela, which most fled because of their home country's political and economic instability. The Times photographed four of the Venezuelans — Arturo Suárez, Angelo Escalona, Frizgeralth Cornejo and Ángelo Bolívar — as they got reacquainted with their families and life outside prison. Suárez, a musician, was detained in North Carolina while gathered with friends to record a music video. Ten people were arrested that day. Inside the Salvadoran prison, he said, music was forbidden and guards beat him repeatedly for singing. But he refused to stay silent. From his cell, he wrote a song that spread from cell to cell, becoming an anthem of hope for the Venezuelans imprisoned with him. 'From Cell 31, God spoke to me,' the lyrics go in part. 'He said, son, be patient, your blessing is coming soon…. Let nothing kill your faith, let nothing make you doubt because it won't be long before you return home.' Escalona had turned 18 just three months before Immigration and Customs Enforcement agents detained him in the same raid that swept up his friend Suárez, the musician. His dream was to become a DJ, and Escalona had saved up to buy equipment that he showed Suárez just before they were arrested. He had no tattoos, no criminal record and was just at the wrong place at the wrong time, he said. When the deportation flight landed in El Salvador, he and the other Venezuelans tried to resist being taken off the plane. 'We all fastened our seat belts because we're Venezuelans — we weren't supposed to be there' in El Salvador, he said. 'But the Salvadoran police boarded the plane and started beating the people in the front.' In mid-2024, Frizgeralth Cornejo made the long trek through the Darién Gap, the dangerous jungle separating Central and South America and made his way north with three friends. Hoping to obtain asylum in the United States, he had applied for an appointment with immigration officials through Customs and Border Protection's CBP One app. But when Cornejo, 26, presented himself at the border, officials accused him of gang affiliation because of his tattoos. Everyone else in his group was allowed through, but not him. Bolívar was living in Texas when he was arrested by ICE agents and sent to El Salvador's CECOT prison. His many tattoos are part of a family legacy, one he shares with his mother, Silvia Cruz. His late father was a tattoo artist. His tattoos led to his imprisonment, he said, because authorities saw them as proof of membership in the Tren de Aragua gang. He is now back in the city of Valencia, about 80 miles east of Caracas.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store