logo
'Quishing' scams dupe millions of Americans as cybercriminals turn the QR code bad

'Quishing' scams dupe millions of Americans as cybercriminals turn the QR code bad

CNBC2 days ago
QR codes were once a quirky novelty that prompted a fun scan with the phone. Early on, you might have seen a QR code on a museum exhibit and scanned it to learn more about the eating habits of the woolly mammoth or military strategies of Genghis Khan. During the pandemic, QR codes became the default restaurant menu. However, as QR codes became a mainstay in more urgent aspects of American life, from boarding passes to parking payments, hackers have exploited their ubiquity.
"As with many technological advances that start with good intentions, QR codes have increasingly become targets for malicious use. Because they are everywhere — from gas pumps and yard signs to television commercials — they're simultaneously useful and dangerous," said Dustin Brewer, senior director of proactive cybersecurity services at BlueVoyant.
Brewer says that attackers exploit these seemingly harmless symbols to trick people into visiting malicious websites or unknowingly share private information, a scam that has become known as "quishing."
The increasing prevalence of QR code scams prompted a warning from the Federal Trade Commission earlier this year about unwanted or unexpected packages showing up with a QR code that when scanned "could take you to a phishing website that steals your personal information, like credit card numbers or usernames and passwords. It could also download malware onto your phone and give hackers access to your device."
State and local advisories this summer have reached across the U.S., with the New York Department of Transportation and Hawaii Electric warning customers about avoiding QR code scams.
The appeal to cybercriminals lies in the relative ease with which the scam operates: slap a fake QR code sticker on a parking meter or a utility bill payment warning and rely on urgency to do the rest.
"The crooks are relying on you being in a hurry and you needing to do something," said Gaurav Sharma, a professor in the department of electrical and computer engineering at the University of Rochester.
Sharma expects QR scams to increase as the use of QR codes spreads. Another reason QR codes have increased in popularity with scammers is that more safeguards have been put into place to tamp down on traditional email phishing campaigns. A study this year from cybersecurity platform KeepNet Labs found that 26 percent of all malicious links are now sent via QR code. According to cybersecurity company, NordVPN, 73% of Americans scan QR codes without verification, and more than 26 million have already been directed to malicious sites.
"The cat and mouse game of security will continue and that people will figure out solutions and the crooks will either figure out a way around or look at other places where the grass is greener," Sharma said.
Sharma is working to develop a "smart" QR code called a SDMQR (Self-Authenticating Dual-Modulated QR) that has built-in security to prevent scams. But first, he needs buy-in from Google and Microsoft, the companies that build the cameras and control the camera infrastructure. Companies putting their logos into QR codes isn't a fix because it can cause a false sense of security, and that criminals can usually simply copy the logos, he said.
Some Americans are wary of the increasing reliance on QR codes.
"I'm in my 60s and don't like using QR codes," said Denise Joyal of Cedar Rapids, Iowa. "I definitely worry about security issues. I really don't like it when one is forced to use a QR code to participate in a promotion with no other way to connect. I don't use them for entertainment-type information."
Institutions are also trying to fortify their QR codes against intrusion.
Natalie Piggush, spokeswoman for the Children's Museum of Indianapolis, which welcomes over one million visitors a year, said their IT staff began upgrading their QR codes a couple of years ago to protect against what has become an increasingly significant threat.
"At the museum, we use stylized QR codes with our logo and colors as opposed to the standard monochrome codes. We also detail what users can expect to see when scanning one of our QR codes, and we regularly inspect our existing QR codes for tampering or for out-of-place codes," Piggush said.
Museums are usually less vulnerable than places like train stations or parking lots because scammers are looking to collect cash from people expecting to pay for something. A patron at a museum is less likely to expect to pay, although Sharma said even in those settings, fake QR codes can be deployed to install malware on someone's phone.
QR code scams are likely to hit both Apple and Android devices, but iPhone users may be slightly more likely to fall victim to the crime, according to a study completed earlier this year by Malwarebytes. Users of iPhones expressed more trust in their devices than Android owners and that, researchers say, could cause them to let down their guard. For example, 70% of iPhone users have scanned a QR code to begin or complete a purchase versus 63% of Android users who have done the same.
Malwarebytes researcher David Ruiz wrote that trust could have an adverse effect, in that iPhone users do not feel the need to change their behavior when making online purchases, and they have less interest in (or may simply not know about) using additional cybersecurity measures, like antivirus. Fifty-five percent of iPhone users trust their device to keep them safe, versus 50 percent of Android users expressing the same sentiment.
A QR code is more dangerous than a traditional phishing email because users typically can't read or verify the encoded web address. Even though QR codes normally include human-readable text, attackers can modify this text to deceive users into trusting the link and the website it directs to. The best defense against them is to not scan unwanted or unexpected QR codes and look for ones that display the URL address when you scan it.
Brewer says cybercriminals have also been leveraging QR codes to infiltrate critical networks.
"There are also credible reports that nation-state intelligence agencies have used QR codes to compromise messaging accounts of military personnel, sometimes using software like Signal that is also open to consumers," Brewer said. Nation-state attackers have even used QR codes to distribute remote access trojans (RATs) — a type of malware designed to operate without a device owner's consent or knowledge — enabling hackers to gain full access to targeted devices and networks.
Still, one of the most dangerous aspects of QR codes is how they are part of the fabric of everyday life, a cyberthreat hiding in plain sight.
"What's especially concerning is that legitimate flyers, posters, billboards, or official documents can be easily compromised. Attackers can simply print their own QR code and paste it physically or digitally over a genuine one, making it nearly impossible for the average user to detect the deception," Brewer said.
Rob Lee, chief of research, AI, and emerging threats at the cybersecurity training focused SANS Institute, says that QR code compromise is just another tactic in a long line of similar strategies in the cybercriminal playbook.
"QR codes weren't built with security in mind, they were built to make life easier, which also makes them perfect for scammers," Lee said. "We've seen this playbook before with phishing emails; now it just comes with a smiley pixelated square. It's not panic-worthy yet, but it's exactly the kind of low-effort, high-return tactic attackers love to scale."
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

OpenAI launches Study Mode in ChatGPT
OpenAI launches Study Mode in ChatGPT

TechCrunch

time12 minutes ago

  • TechCrunch

OpenAI launches Study Mode in ChatGPT

OpenAI announced Tuesday the launch of Study Mode, a new feature within ChatGPT that aims to help students develop their own critical thinking skills, rather than simply obtain answers to questions. With Study Mode enabled, ChatGPT will ask users questions to test their understanding, and in some cases, refuse to offer direct answers unless students engage with the material. OpenAI says Study Mode is rolling out to logged in users on ChatGPT's Free, Plus, Pro, and Team plans starting Tuesday. The company expects to roll Study Mode out to its Edu subscribers — which largely consists of young people whose school administrator's have purchased a plan for the entire student body — in the coming weeks. Study Mode is OpenAI's attempt to address the millions of students that use ChatGPT in school. Studies have shown that using ChatGPT can be a helpful tutor for young people, but it also may harm their critical thinking skills. A research paper released in June found that people who use ChatGPT to write essays exhibit lower brain activity during the process compared to those who use Google Search or nothing at all. When ChatGPT first launched in 2022, its widespread use in school settings sparked fear among educators, leading to generative AI bans in many American school districts. By 2023, some of those schools repealed their ChatGPT bans, and teachers around the country came to terms with the fact that ChatGPT would be a part of young people's lives from now on. Now with the launch of Study Mode, OpenAI hopes to improve ChatGPT as a learning tool, and not just an answer engine. Anthropic launched a similar tool for its AI chatbot Claude, called Learning Mode, in April. Of course, there are limitations to how effective Study Mode truly is. Students can easily switch into the regular mode of ChatGPT if they just want an answer to a question. OpenAI's VP of Education, Leah Belsky, told TechCrunch in a briefing that the company is not offering tools for parents or administrators to lock students into Study Mode. However, Belsky said OpenAI may explore administrative or parental controls in the future. That means it will take a committed student to use Study Mode — the kids have to really want to learn, not just finish their assignment. Techcrunch event Tech and VC heavyweights join the Disrupt 2025 agenda Netflix, ElevenLabs, Wayve, Sequoia Capital — just a few of the heavy hitters joining the Disrupt 2025 agenda. They're here to deliver the insights that fuel startup growth and sharpen your edge. Don't miss the 20th anniversary of TechCrunch Disrupt, and a chance to learn from the top voices in tech — grab your ticket now and save up to $675 before prices rise. Tech and VC heavyweights join the Disrupt 2025 agenda Netflix, ElevenLabs, Wayve, Sequoia Capital — just a few of the heavy hitters joining the Disrupt 2025 agenda. They're here to deliver the insights that fuel startup growth and sharpen your edge. Don't miss the 20th anniversary of TechCrunch Disrupt, and a chance to learn from the top voices in tech — grab your ticket now and save up to $675 before prices rise. San Francisco | REGISTER NOW OpenAI says Study Mode is the company's first step to improving learning in ChatGPT, and aims to publish more information in the future about how students use generative AI throughout their education.

What critics don't understand about Trump's energy policies
What critics don't understand about Trump's energy policies

The Hill

time12 minutes ago

  • The Hill

What critics don't understand about Trump's energy policies

A recent New York Times article made some alarming claims: China is racing ahead in clean energy, while America under Trump clings to fossil fuels. Beijing is supposedly building wind turbines, solar panels and electric vehicles for a decarbonized world, while Washington is instead doubling down on obsolete oil, gas and coal. The contrast is stark and seemingly damning — the U.S., the article suggests, is losing the future. But this story is misleading. What the article misses is the deeper logic shaping the Trump administration's energy policy. It has little to do with nostalgia or climate skepticism, and everything to do with the demands of artificial intelligence. Trump's energy agenda is being guided by a different kind of technological revolution. Massive AI models, sprawling data centers and next-generation chip foundries demand vast, uninterrupted flows of energy. However clean or cheap they may be, wind and solar, by their intermittent nature, cannot deliver the stable, high-density power these systems require. That distinction, between intermittent and dispatchable energy, is the real dividing line in global energy strategy today. And it's why Trump's policy may be more forward-looking than critics realize. If you want to understand the real rationale, look to Secretary of Energy Chris Wright. In a recent interview, he stated, 'To achieve Nvidia's and America's dream to win the AI race, we've got to produce a lot more electricity.' Wright's position is blunt but accurate. Natural gas, followed by nuclear and coal, is what now powers most of America's electricity, and it is these sources that will fuel the AI boom. 'Expanded natural gas electricity production … that'll be the workhorse of winning the AI race,' Wright explained. Thus, in Wright's view, the Trump administration policy isn't to reject the future but rather to win it by unleashing American energy production to support the backbone of tomorrow's economy: AI chips, training clusters and data centers. Contrast that with the Biden administration's approach. The Inflation Reduction Act was a landmark in climate legislation, pouring hundreds of billions into renewables, clean tech and place-based development incentives. It was designed to build solar farms, wind capacity and green manufacturing hubs, especially in disadvantaged communities. But for all its strengths, the law was designed in a pre-ChatGPT world. A 2023 Treasury Department fact sheet on the law goes on at length about electric heat pumps, rooftop solar and tax credits for underserved areas. It says nothing about AI, chip fabrication or crypto foundries. The Biden plan focused on equity and emissions, while Trump's plan focuses on watts and AI's electricity demands. That contrast became even sharper with Trump's second-term executive orders. Within days of taking office, Trump moved to dismantle the regulatory infrastructure supporting Biden's climate agenda. He ordered agencies to fast-track fossil fuel development and streamline the permitting of pipelines and power stations. Biden-era climate councils and carbon accounting models were scrapped. Electric vehicle mandates were rolled back. Furthermore, Trump's executive orders on nuclear power called for 300 new gigawatts of nuclear capacity by 2050. Advanced reactors are to be deployed at AI data centers and military bases within two years. Uranium enrichment, the revival of shuttered nuclear plants and fuel recycling are all being ramped up under the banner of national security. From liquefied natural gas exports to uranium enrichment, the Trump message is consistent: deregulate, drill, and build. Trump's coalition is not anti-technology — in fact, it is aggressively trying to corner the energy inputs required for technological supremacy, even if it means tearing up climate policy to get there. That brings us back to the New York Times's climate article's core claims. The piece frames the global energy race as a contest between a clean-energy China and a fossil-fueled America, casting the U.S. as the laggard. But that reading confuses the form of energy with its function. The future won't be won by whoever builds the most solar panels. It will be won by the country best positioned to power the technologies that drive tomorrow's economy. And right now, that technology is artificial intelligence. AI isn't just another app layer. It's a foundational shift in computing, manufacturing, defense and global finance. It demands enormous, stable, always-on energy loads. That means natural gas, nuclear and dispatchable capacity, not just wind and sun. By this logic, it may be China — not the U.S. — that's making the bigger strategic misstep. Beijing is doubling down on renewables, but those technologies weren't built to power the AI revolution. Meanwhile, Washington, under Trump, is retooling its energy policy to meet precisely that demand.

One Third of Americans Are Now Heavy AI Users
One Third of Americans Are Now Heavy AI Users

Newsweek

time13 minutes ago

  • Newsweek

One Third of Americans Are Now Heavy AI Users

Based on facts, either observed and verified firsthand by the reporter, or reported and verified from knowledgeable sources. Newsweek AI is in beta. Translations may contain inaccuracies—please refer to the original content. A new survey has revealed that roughly one-third of Americans are now considered 'heavy AI users.' In a poll of more than 1,000 U.S. adults by SEO and digital marketing consultant Joe Youngblood, 75 percent of American consumers said they used an artificial intelligence system in the last six months. Seventeen percent of respondents said they used an AI system multiple times a day, and 16 percent said they use it at least once a day. Why It Matters The rapid adoption of artificial intelligence systems is leading to major changes in how Americans interact with technology, information and everyday services. As AI becomes increasingly integrated into web searches, workplace tasks and personal routines, data from multiple recent studies have indicated a sizable shift in user behavior, digital literacy and the broader impact on work and social structures. Understanding the prevalence and patterns of AI usage could be crucial for policymakers and businesses alike, as gaps in adoption persist across age groups, education and socioeconomic backgrounds. A close-up of a smartphone displaying the ChatGPT logo on a white screen, with the same ChatGPT logo shown on a laptop screen on February 19, 2025, in Chongqing, China. A close-up of a smartphone displaying the ChatGPT logo on a white screen, with the same ChatGPT logo shown on a laptop screen on February 19, 2025, in Chongqing, To Know According to Youngblood's nationwide survey of 1,151 American adults, approximately 33 percent now qualify as "heavy AI users," defined as using large language model-based artificial intelligence systems at least once per day or more frequently. Overall, 75.16 percent of respondents had used an AI system in some capacity over the past six months, with 17.12 percent reporting usage multiple times per day and 15.90 percent indicating daily use. Another 42.14 percent identified as "casual users," employing AI between once a week and once every six months. Only about 16.50 percent said they never use AI, earning the label "AI haters" in the study's terminology. When asked about their preferred AI platforms, 46.13 percent cited ChatGPT, followed by Google Gemini (22.76 percent), Meta AI on Facebook (19.29 percent), Google AI Overviews (18.94 percent), and Microsoft Copilot (15.81 percent). Google accounted for three of the top six systems in use, while ChatGPT remained the single most popular individual platform. Searching the web ranked as the most common application for AI, with 29.28 percent of Americans saying they use such tools for this purpose. Additional popular uses included learning new topics (24.76 percent), correcting grammar and spelling (19.80 percent), generating new ideas (19.64 percent), entertainment (16.59 percent), and exploring complex concepts (15.12 percent). Recent polling by the Associated Press and NORC echoed this trend, indicating that 60 percent of Americans use AI to find information at least occasionally, rising to 74 percent among those under the age of 30. However, the AP-NORC data also found that only four in ten Americans use AI for work or brainstorming, with younger adults showing greater engagement than their older counterparts. Despite the accelerated pace of adoption, other sources caution that actual daily AI engagement may fall below perceived hype. A July AmeriSpeak report estimated that just 14 percent of Americans use AI daily for personal activities, and 15 percent do so for work tasks. What People Are Saying Grant McDonald, the CEO and founder of AI parenting app Bobo, told Newsweek: "This surge in AI adoption proves that Americans are drowning in information overload and becoming increasingly comfortable with turning to AI as a practical solution for cutting through the noise. We're seeing this across every sector, from health care to parenting, where AI helps people make better decisions faster." What Happens Next As AI use expands, its influence on work, education, and information consumption is expected to grow, especially among younger and more digitally literate Americans. "We're heading toward a future where AI becomes as essential as smartphones, not replacing human judgment, but augmenting it intelligently - and people are starting to embrace that," McDonald said. "The key will be ensuring these tools remain accessible and ethical while truly serving human needs."

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store