
'Quishing' scams dupe millions of Americans as cybercriminals exploit QR codes
'As with many technological advances that start with good intentions, QR codes have increasingly become targets for malicious use. Because they are everywhere — from gas pumps and yard signs to television commercials — they're simultaneously useful and dangerous,' said Dustin Brewer, senior director of proactive cybersecurity services at BlueVoyant.
Brewer says that attackers exploit these seemingly harmless symbols to trick people into visiting malicious websites or unknowingly share private information, a scam that has become known as 'quishing.'
The increasing prevalence of QR code scams prompted a warning from the Federal Trade Commission earlier this year about unwanted or unexpected packages showing up with a QR code that when scanned 'could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords. It could also download malware onto your phone and give hackers access to your device.'
State and local advisories this summer have reached across the U.S., with the New York Department of Transportation and Hawaii Electric warning customers about avoiding QR code scams.
The appeal to cybercriminals lies in the relative ease with which the scam operates: slap a fake QR code sticker on a parking meter or a utility bill payment warning and rely on urgency to do the rest.
'The crooks are relying on you being in a hurry and you needing to do something,' said Gaurav Sharma, a professor in the department of electrical and computer engineering at the University of Rochester.
On the rise as traditional phishing fails
Sharma expects QR scams to increase as the use of QR codes spreads. Another reason QR codes have increased in popularity with scammers is that more safeguards have been put into place to tamp down on traditional email phishing campaigns. A study this year from cybersecurity platform KeepNet Labs found that 26 percent of all malicious links are now sent via QR code. According to cybersecurity company, NordVPN, 73% of Americans scan QR codes without verification, and more than 26 million have already been directed to malicious sites.
'The cat and mouse game of security will continue and that people will figure out solutions and the crooks will either figure out a way around or look at other places where the grass is greener,' Sharma said.
Sharma is working to develop a 'smart' QR code called a SDMQR (Self-Authenticating Dual-Modulated QR) that has built-in security to prevent scams. But first, he needs buy-in from Google and Microsoft, the companies that build the cameras and control the camera infrastructure. Companies putting their logos into QR codes isn't a fix because it can cause a false sense of security, and that criminals can usually simply copy the logos, he said.
Some Americans are wary of the increasing reliance on QR codes.
'I'm in my 60s and don't like using QR codes,' said Denise Joyal of Cedar Rapids, Iowa. 'I definitely worry about security issues. I really don't like it when one is forced to use a QR code to participate in a promotion with no other way to connect. I don't use them for entertainment-type information.'
Institutions are also trying to fortify their QR codes against intrusion.
Natalie Piggush, spokeswoman for the Children's Museum of Indianapolis, which welcomes over one million visitors a year, said their IT staff began upgrading their QR codes a couple of years ago to protect against what has become an increasingly significant threat.
'At the museum, we use stylized QR codes with our logo and colors as opposed to the standard monochrome codes. We also detail what users can expect to see when scanning one of our QR codes, and we regularly inspect our existing QR codes for tampering or for out-of-place codes,' Piggush said.
Museums are usually less vulnerable than places like train stations or parking lots because scammers are looking to collect cash from people expecting to pay for something. A patron at a museum is less likely to expect to pay, although Sharma said even in those settings, fake QR codes can be deployed to install malware on someone's phone.
Apple, Android user trust is an issue
QR code scams are likely to hit both Apple and Android devices, but iPhone users may be slightly more likely to fall victim to the crime, according to a study completed earlier this year by Malwarebytes. Users of iPhones expressed more trust in their devices than Android owners and that, researchers say, could cause them to let down their guard. For example, 70% of iPhone users have scanned a QR code to begin or complete a purchase versus 63% of Android users who have done the same.
Malwarebytes researcher David Ruiz wrote that trust could have an adverse effect, in that iPhone users do not feel the need to change their behavior when making online purchases, and they have less interest in (or may simply not know about) using additional cybersecurity measures, like antivirus. Fifty-five percent of iPhone users trust their device to keep them safe, versus 50 percent of Android users expressing the same sentiment.
Low investment, high return hacking tactic
A QR code is more dangerous than a traditional phishing email because users typically can't read or verify the encoded web address. Even though QR codes normally include human-readable text, attackers can modify this text to deceive users into trusting the link and the website it directs to. The best defense against them is to not scan unwanted or unexpected QR codes and look for ones that display the URL address when you scan it.
Brewer says cybercriminals have also been leveraging QR codes to infiltrate critical networks.
'There are also credible reports that nation-state intelligence agencies have used QR codes to compromise messaging accounts of military personnel, sometimes using software like Signal that is also open to consumers,' Brewer said. Nation-state attackers have even used QR codes to distribute remote access trojans (RATs) — a type of malware designed to operate without a device owner's consent or knowledge — enabling hackers to gain full access to targeted devices and networks.
Still, one of the most dangerous aspects of QR codes is how they are part of the fabric of everyday life, a cyberthreat hiding in plain sight.
'What's especially concerning is that legitimate flyers, posters, billboards, or official documents can be easily compromised. Attackers can simply print their own QR code and paste it physically or digitally over a genuine one, making it nearly impossible for the average user to detect the deception,' Brewer said.
Rob Lee, chief of research, AI, and emerging threats at the cybersecurity training focused SANS Institute, says that QR code compromise is just another tactic in a long line of similar strategies in the cybercriminal playbook.
'QR codes weren't built with security in mind, they were built to make life easier, which also makes them perfect for scammers,' Lee said. 'We've seen this playbook before with phishing emails; now it just comes with a smiley pixelated square. It's not panic-worthy yet, but it's exactly the kind of low-effort, high-return tactic attackers love to scale.'
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Chicago Tribune
an hour ago
- Chicago Tribune
Gainfront replaces guesswork with data-driven supplier discovery for risk-averse corporations
Global procurement executives must lie awake at night contemplating this troubling business scenario: Their companies spend billions on sophisticated enterprise systems that track every dollar once it's committed yet rely on what amounts to educated guesswork when selecting the suppliers who receive those dollars. The most critical decision in the procurement life cycle — which vendors to trust with components, materials and services essential to operations — remains startlingly primitive at most Fortune 1000 companies. However, this scenario is starting to be a tale of the past with the rise of the AI/ML supplier life cycle management platform Gainfront. Here's how Gainfront's proprietary EfficiencyAI tool changes the game in supplier selection and identification. This scenario plays out daily across corporate America: Procurement teams tasked with finding and vetting new suppliers rely on a mix of Google searches, LinkedIn browsing, industry directories and word-of-mouth recommendations. It's a surprisingly analog approach in a world where artificial intelligence has transformed nearly every other aspect of business operations. The cost of getting it wrong can be daunting. A supplier that fails to deliver, violates compliance requirements or faces financial instability can trigger a cascade of disruptions that ripple through global supply chains. In the most severe cases, these disruptions can halt production lines, compromise product quality, damage brand reputation and even lead to regulatory penalties. 'There's literally nothing more important in a CEO's mind right now than managing their supplier life cycles and supply chain and making sure that they are positioned well, to kind of compete in a market that is fluctuating very, very rapidly,' explains Srikant Sharma from Gainfront. The traditional approach to supplier discovery isn't just inefficient — it's fundamentally broken. Legacy systems, which dominate the procurement software market, were designed for a different era. They excel at transactional processes but offer limited capabilities for the complex task of identifying and evaluating new suppliers. 'They are built on an existing solution structure that is platform-based,' Sharma argues. 'That structure is very inflexible and requires massive amounts of services, professional services and contractor work to configure it.' What makes Gainfront's approach a game changer is the recognition that supplier discovery isn't just a search problem, it's an intelligence problem. The company's proprietary EfficiencyAI suite leverages domain-trained large language models to transform how corporations identify potential suppliers. Rather than simply matching keywords, its sophisticated AI systems analyze supplier information the way an experienced procurement professional would. They evaluate websites, marketing materials and other documents across multiple languages, extracting meaningful insights from unstructured data that would take human analysts weeks to process. Gainfront can identify 'hidden gem' suppliers who might be overlooked due to language barriers or formatting limitations. Through its AI-powered supplier discovery database, businesses have access to new, qualified suppliers across 16,000-plus categories. This capability is particularly valuable for global corporations changing their business model or expanding into new markets. Gainfront's use of AI addresses a fundamental challenge in supplier discovery: the information asymmetry between buyers and potential vendors. In Gainfront, suppliers present themselves in the best possible light, with profile visibility by 95%, highlighting strengths while obscuring weaknesses. Without this ability to verify claims and identify risks, procurement teams are left making decisions based on incomplete or misleading information. Sharma explains, 'The system doesn't just find suppliers — it evaluates them, flagging potential risks related to financial stability, compliance history and operational capabilities. This innovative technology and data-driven insights ensure you can trust your choices.' For business operations that heavily rely on dependable supply chain management, Gainfront's approach can compress what traditionally takes months into minutes. Instead of assigning junior staff to compile lists of potential suppliers through manual searches, the AI-powered platform can scan millions of supplier profiles, evaluating them against specific criteria and generating concise reports for decision-makers. The company maintains a massive database of global suppliers — both diverse and nondiverse, traditional and green — that procurement teams can tap into immediately. This database isn't static; it's continuously updated and enhanced with new information, ensuring that recommendations reflect current market realities. 'It's really important to build something that's modular, that is an end-to-end solution in something that is super critical, which is managing the supply chain and managing supplier life cycles across the operations,' Sharma explains. The modular nature of Gainfront's platform allows companies to implement just the supplier discovery component if that's their most pressing need or deploy it as part of a comprehensive supplier lifecycle management solution. This flexibility has proven attractive to Fortune 1000 companies looking to modernize their procurement operations without disrupting existing systems. Data-driven supplier discovery may be just a small portion of the whole business operation, but its impact extends beyond efficiency gains. By applying AI to the evaluation process, companies can identify suppliers that not only meet basic requirements but also align with broader strategic objectives. For organizations with diversity spending targets, the platform can highlight qualified minority-owned or women-owned businesses. For those focusing on sustainability, it can identify suppliers with strong environmental credentials. And for companies concerned about geopolitical risks, it can flag potential vulnerabilities in global supply networks. For instance, one manufacturing company discovered that 43% of their tier-two suppliers — the suppliers to their direct suppliers — were concentrated in a single region with escalating political tensions. This hidden risk exposure might have gone undetected without AI-powered analysis of supplier networks. Hetal Mehta, CEO of Gainfront, shares, 'In today's complex global market, business leaders can no longer afford the luxury of uncertainty. The stakes are simply too high to make critical supplier decisions based on incomplete information or intuition alone. At Gainfront, we're committed to transforming procurement from a guesswork into a science of data-driven certainty, providing our partners with the intelligence they need to navigate increasingly unpredictable business scenarios.'


Miami Herald
an hour ago
- Miami Herald
Veteran fund manager raises eyebrows with Palantir review ahead of earnings
If you're planning to raise Hell in Gotham, you're gonna have to go through Batman first. The Caped Crusader looms large over the crime-ridden comic book city and he's said to be a significant presence in the New York office of Palantir Technologies (PLTR) in the form of a statue and prints. Don't miss the move: Subscribe to TheStreet's free daily newsletter And just to keep the superhero imagery going, the company's Manhattan location is called Gotham, which is also the name of Palantir's core government product. The company provides AI-driven data analytics software, and Gotham, released in 2008, is used widely by government agencies, including intelligence, defense, law enforcement, and national security organizations, for threat analysis, operational, intelligence gathering and other tasks. "Gotham's targeting offering supports soldiers with an Al-powered kill chain, seamlessly and responsibly integrating target identification and target effector pairing," Palantir said on its website. "Operators experience enhanced situational awareness and effectiveness as Gotham streamlines critical decision-making in the modern battlespace." Bloomberg/Getty Images The company encourages users to "harness the full power of the platform from operations centers to the edge, transforming any bunker or outpost into an instant command center with mixed reality capabilities." "We are making America more lethal, making our adversaries increasingly afraid of acting against the interest of America and especially Americans," Alex Karp, Palantir's outspoken CEO and co-founder, has said. In a letter to shareholders, Karp said in May that the company's U.S. government revenue increased 45% year-over-year to $373 million in the first three months the year. "Our software systems for planning and executing special forces and other military operations, and for assessing and selecting targets, has been embraced by the American defense sector," he said. More Palantir Veteran trader surprises with Palantir price target and commentsMusk moves xAI, Grok onto Palantir turfVeteran analyst sends bold message on Palantir stock targetPalantir makes surprise move into weather Palantir has been criticized for its involvement with agencies like U.S. Immigration and Customs Enforcement for enabling mass deportation programs. In response to a May 30 New York Times article, the company said in a blog post that it was "committed to providing transparency around who we are and what we do." "Since our founding, we have always placed the preservation of privacy and civil liberties at the center of our mission," the post said. Palantir has fared well in the Trump administration's efforts to streamline the government. The Denver company's stock more than doubled (up 112%) this year and has skyrocketed 550% from this time in 2024. Piper Sandler recently initiated coverage of Palantir with an overweight rating and $170 price target, according to The Fly. The shares are richly valued but the company offers "one-of-a-kind" growth and margin potential, the firm said. Piper Sandler said Palantir could grow to a $24 billion revenue run rate by 2032 due to market-share gains in two trillion-dollar total addressable markets - government and U.S. commercial. The firm told investors to be patient and buy the shares on weakness, as it sees Palantir as a winner in the artificial intelligence revolution. Palantir is scheduled to report second-quarter earnings after the market closes on Aug. 4. Related: Analyst revamps Palantir stock forecast before earnings The company is forecasting quarterly revenue of $934 million to $938 million, surpassing the consensus estimate of $899.1 million. On Aug. 1, Palantir said that it had signed a contract with the U.S. Army valued at up to $10 billion over the next decade. The deal consolidates multiple contracts into a single enterprise agreement, giving the Army more flexibility in purchasing software and services and reduces procurement delays and contract-related fees. Chris Versace, TheStreet Pro portfolio's lead manager, says the contract will be a hot topic on the company's earnings call, but reminded investors that "Palantir shares have run." "We're mindful that we're going to have to likely bump up our price target again, yet again, especially after this multiyear, very, very large Army contract," he said. "But because of the sharp run in Palantir shares, remember that they will need to deliver a beat and raise quarter," he added. "This contract likely gives them the room to do that. " However, Versace said, given the size of the move, some investors out there might not impressed by what the company puts up. "We, of course, are going to take a longer term view, he said. "If we see Palantir shares sell off in the next couple of days, that could give us an opportunity to bulk up that position, which is not on the larger size for the portfolio. And we continue to believe that we are in the early days of AI adoption." Related: The stock market is being led by a new group of winners The Arena Media Brands, LLC THESTREET is a registered trademark of TheStreet, Inc.

Politico
2 hours ago
- Politico
The global AI contest hits the UN
With help from Aaron Mak The rivalry between the United States and China over who will dominate artificial intelligence has moved to an obscure battlefield: A Geneva-based United Nations agency most people have never heard of. The Trump administration announced in June — a full year early — that it will push for a second term for American diplomat Doreen Bogdan-Martin as secretary general of the International Telecommunication Union, the organization that sets voluntary international standards for technology ranging from radio frequencies and broadband to 6G mobile phones. This is the earliest the State Department has ever made this kind of push at the ITU, an indication of the growing urgency of the U.S.-China technological rivalry. The Trump AI Action Plan, released earlier this month, specifically names the ITU as key to America's global tech dominance. But some observers worry that Trump's tough-minded foreign policy approach may already be hurting the U.S. in its quest to keep Bogdan-Martin in office. The ITU has been a great-power battleground before. In 2022, with Huawei turning telecom into a global contest, America and China waged a proxy battle for control over the agency. The Chinese backed Russian candidate Rashid Ismailov, a former Russian telecom minister who lost decisively to Bogdan. Government and tech insiders say the stakes are even higher now because the ITU is setting standards for AI —more than 150 to date — for how governments and countries integrate the technology across existing operations. That's included standards for testing and evaluation of AI systems in areas like conversational AI tools and computer network diagnostics. So whoever controls the ITU will shape the global standards for AI development and integration. Founded more than 150 years ago to standardize telegraph systems, the ITU today includes the U.N.'s 193 members along with representatives of corporations including AT&T, China Unicom, Nokia and Sony. Over the years, the agency has become central to the growth of telecom technology, negotiating international agreements on everything from radio spectrum allocations to the orbital paths of satellites in outer space. ITU added AI to its suite of technologies with the launch of its AI For Good program in 2017. U.N. members vote every four years to select the agency's secretary general, and that vote has grown more loaded each election. Bogdan-Martin's predecessor, China's Houlin Zhao, developed a reputation among Americans of using his position to bend the ITU toward Beijing. 'What you saw over and over again was him trying to align the ITU with endorsing Chinese technology and downplaying U.S. complaints about the potential for security breaches by using ZTE or Huawei technology, or endorsing Chinese Belt and Road Initiative telecommunications projects in developing countries,' said Brett Schaefer, an expert on the U.N. at the American Enterprise Institute, and a former member of U.N. General Assembly's Committee on Contributions. The U.S. blacklisted Huawei and ZTE in 2020 as 'companies posing a national security threat'. China's Washington embassy and New York U.N. mission did not answer DFD's questions. Nor did the State Department or Bogdan-Martin. Beijing hasn't announced if it will contest Bogdan-Martin's renomination. In some respects, the U.S. is at the apex of its technological prowess. Nvidia and Microsoft both reached valuations above $4 trillion, making them the wealthiest companies in world history. Trump's AI Action Plan, released in July, is in part a call to keep the U.S. dominant by exporting American technology around the world. Notably, for a White House that rejects much of the world order, it calls for the U.S. to leverage its positions in international bodies, including the ITU. 'Everyone in the world should be using our technology, and we should make it easy for the world to use it,' White House Office of Science and Technology Policy Director Michael Kratsios said last week in Washington. Observers say Bogdan-Martin's early re-entry into the race shows American officials are wary of China's growing influence. Bogdan-Martin easily defeated her rival in 2022, but Mark Lambert, a State Department veteran of the Biden and first Trump administrations, anticipated Bogdan-Martin's rivals would start their campaign ahead of time as well. 'If the Chinese and Russians are crafty, they'll find a like-minded candidate from Africa or Latin America to put forward to line up lesser developed country votes,' said Lambert. Mark Beall, who directed AI strategy in the Pentagon in the first Trump administration, said the U.S. would likely contest China's influence by appealing to the same voters from the lesser developed world, with the early announcement giving 'time to counter potential infrastructure-for-votes deals that some competitors might offer.' Recent signals in the wonky world of global telecom diplomacy may give the U.S. some cause for concern. Daniel Baer, who served as ambassador to the Organization for Security and Cooperation in Europe under former President Barack Obama, said Trump's tariffs and slashing of foreign aid might be alienating potential ITU votes. 'In much of the world, there's probably less interest in doing favors for the United States than there might have been a year ago,' he said. In June, the ITU voted on the location of the agency's World Radio Conference, planned for 2027. Although Commerce Secretary Howard Lutnick pitched Washington to host the confab, members voted instead to hold the event in Shanghai. 'That's not the outcome that the United States wanted,' said Fiona Alexander, a senior telecoms official in the Commerce Department from 2008 to 2019, during both the Obama and Trump administrations. 'We need to get serious. We need to get organized. There's a long-term play in all of these institutions because it's all about coalition building'. Privacy hawks hound the TSA over facial recognition Privacy-minded Senate Republicans are accusing the Transportation Security Administration of interfering with a bill to make airport screenings less intrusive, POLITICO's Benjamin Guggenheim reported Sunday. Senate Commerce Chair Ted Cruz (R-Texas) said he'd delay consideration of the bill last Tuesday, which would have required the TSA to notify passengers of their ability to opt-out of facial recognition scans and put checks on the storage of biometric data collected in the process. The bill was subject to intense opposition from the travel industry, but Republicans also grumbled about the TSA's involvement. When asked if the TSA raised concerns about the bill, co-sponsor Sen. John Kennedy (R-La.) said, 'The short answer is yes; the long answer is hell yes.' He added, 'They're working like an ugly stripper to kill this bill, which tells me we're doing the right thing.' A senior Senate GOP aide also told POLITICO that the 'smears against [the] bill have TSA's fingerprints all over it.' The TSA did not respond to POLITICO's inquiries on the matter. Delta says its AI is not using our data to set prices Delta Air Lines is denying that it uses personal data to set 'individualized' airfares, POLITICO's Alfred Ng reports. The airline made the claims in a letter that the company sent on Friday to Sens. Ruben Gallego (D-Ariz.), Richard Blumenthal (D-Conn.) and Mark Warner (D-Va.), in response to their questions about its pricing practices. Peter Carter, Delta's chief external affairs officer, wrote in the letter, 'Our AI-powered pricing functionality is designed to enhance our existing fare pricing processes using aggregated data.' This response doesn't seem to have allayed the senators' concerns. 'If Delta is in fact using aggregated instead of individualized data, that is welcome news,' Gallego said in a statement. 'But it still begs the question: why did their president brag to their investors about their desire to 'get you the right offer in your hand at the right time'?' Warner wrote in an X post on Friday that 'many questions remain.' post of the day THE FUTURE IN 5 LINKS Stay in touch with the whole team: Aaron Mak (amak@ Mohar Chatterjee (mchatterjee@ Steve Heuser (sheuser@ Nate Robson (nrobson@ and Daniella Cheslow (dcheslow@