Be skeptical about QR codes, warns the FTC


The Federal Trade Commission (FTC) warned the public against scanning any old QR code in a consumer alerts blog last week. Naturally, the warning comes down to security and privacy — bad actors can put QR codes in inconspicuous places or send them via text or email, then just sit back and wait for a payday in the form of money, logins, or other sensitive information.
The New York Times reported that John Fokker, who heads threat intelligence at cybersecurity company Trellix, says Trellix found over “60,000 samples of QR code attacks” in the third quarter this year alone. The Times wrote that the most popular scams involved payroll and HR personnel impersonators and postal scams, among others. Early last year, police in several Texas cities said they’d found fraudulent QR codes placed on parking meters, directing people to a false payment site.
To avoid being victimized by a bad code, the FTC suggests ignoring unexpected emails or other messages you weren’t expecting that come with some sort of urgent request. It’s also good to check the URL that shows up on your screen when scanning to make sure it’s a site you trust. Then again, even a legitimate QR code can show you a garbled and meaningless shortened web address, so if you know what site you want to visit, it’s best to go there directly.
The Commission also recommends the old standby of updating your devices and ensuring you have good, strong passwords and multi-factor authentication in place for sensitive accounts. If you’re unsure how to do that second part, check out our two-factor authentication guide, which has instructions for several of the most popular sites and services.
Beyond the FTC’s recommendation, there are other things you can do. Don’t download a QR code scanning app, for one — built-in camera apps for Android and iOS already do that, and apps can sometimes be made for nefarious purposes themselves. The FBI also has a list of recommendations in a similar blog it published in September, but in general, if you aren’t sure about a code, don’t scan it.
The Federal Trade Commission (FTC) warned the public against scanning any old QR code in a consumer alerts blog last week. Naturally, the warning comes down to security and privacy — bad actors can put QR codes in inconspicuous places or send them via text or email, then just sit…
Recent Posts
- Samsung’s midrange Galaxy A56 has AI photo editing and a bump for its buttons
- Samsung reveals Galaxy A56 with more AI and a modest spec bump
- DJI launches a vehicle-mounted drone dock station that seemingly comes straight from a sci-fi movie
- Ikea registered a Matter-over-Thread temperature sensor with the FCC
- Company that reportedly supplied DOGE and Elon Musk with sleeping solutions found to have huge vulnerability in its…beds??
Archives
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010