9 Tips To Spot A Fake QR Code Scam | With Examples (2024)

QR codes have become a popular tool used by businesses and individuals alike for activities such as redeeming coupons or sharing contact information.

However, due to their nature, these codes are also capable of being faked by malicious agents seeking to take advantage of unsuspecting users.

To avoid becoming a victim, it’s important to know how to spot a fake QR code so that you can identify any that may come your way in order to protect your data from cyber criminals.

In this blog post, we'll discuss what you need to look out for when verifying if a QR code is legitimate before using it.

What is Fake QR Code and How Does it Work?

In simple terms, fake QR codes are being used in a scam that fraudsters use to trick people into visiting malicious websites or downloading malware and harmful software.

These QR codes might look similar to legitimate QR codes, however they actually direct you to a fraudulent website or download.

QR code scams work by tricking users into scanning the malicious QR code with their device’s camera.

Once scanned, the code will direct the user to a website that is designed to look legitimate but is controlled by cybercriminals.

The website may contain malware or other malicious software that can steal your personal details such as credit card information or any sensitive information from the device.

9 Tips To Spot A Fake QR Code Scam | With Examples (1)The best way to protect yourself against a QR code scam is to always double-check the source of the QR code before scanning it, as malicious actors replace legitimate QR codes with the fake ones, especially if it's in a public place or from an unknown sender.

QR Code Scam Statistics - UK 2023

The number of QR code scams in the United Kingdom is expected to rise significantly in 2023.

According to a report by the National Fraud Intelligence Bureau, there were over 3,000 reported cases of QR code scams in the UK in 2020.

This figure is expected to reach around 10,000 cases by the end of 2023 as criminals become more sophisticated in their methods and technology advances.

In fact, it's projected that by 2023, the number of victims falling for the QR code scam will increase by over 16%.

Due to COVID-19, the UK’s hospitality sector introduced QR codes and self-ordering technology across restaurants nationally to minimise customer contact.

Source: 7NEWS

Although these measures have been in place for a few years now, a staggering 53% of UK consumers are struggling to identify malicious QR codes, as per ChronicleLive.

Recent Examples of Fake QR Code Scam in UK

There are many QR code scams to watch out for. Some recent examples of QR scams in the UK includes:

Fake QR code parking meters scams

One of the most common QR code scams in the UK recently is parking payment scams.

Various car parking lots on the Isle of Wight, UK have been identified as using QR code payment scams for parking payment machines.

According to the Isle of Wight Council, several individuals have encountered a problem when contacting the designated when scanning a fake QR code and sticker displayed on the parking machines.

This code prompted users to input their credit card information before money was taken out of their account.

9 Tips To Spot A Fake QR Code Scam | With Examples (2)Source: Isle of Wight CountyPress

Recently, the popular method of paying for car parks and on-street parking has become even more prevalent.

As we move away from traditional coin machines, QR codes have become increasingly common.

However, this increased usage has also exposed people to QR code scammers, resulting in a recent surge of QR tricks at UK car parks, as reported by ChronicleLive.

Fake QR Code Ticket Scams

Malicious QR code ticket scams have also been on the rise in the UK recently and is one of the most common QR code scams to exist currently.

Scammers use fake tickets to gain access to events such as concerts, sports matches, and festivals.

9 Tips To Spot A Fake QR Code Scam | With Examples (3)

Source: https://www.mirror.co.uk/money/fake-concert-ticket-warning-expert-29680624

They do this by using sophisticated technology to generate counterfeit tickets with a QR code link that appears identical to legitimate tickets.

These fake tickets are then sold online or through social media platforms, often at significantly discounted prices.

Phishing Emails Containing Fake QR Codes

Phishing QR code scams are increasing significantly across all industries in the UK.

This deceptive method is also known as Quishing or QR phishing. Cyber criminals masquerade as trustworthy companies to send phishing emails embedded with fake QR codes.

9 Tips To Spot A Fake QR Code Scam | With Examples (4)

Source: https://securelist.com/qr-codes-in-phishing/110676/

An example of information within these emailscould be a claim that your online banking payment did not process therefore, prompting you to resubmit your credit card details by scanning the QR code.

Unfortunately, unsuspecting victims fall into the trap and, unknowingly providing their financial information with login details onto the phishing website.

9 Tips To Spot A Fake QR Code Scam | With Examples (5)

Source: https://itservices.wp.st-andrews.ac.uk/2023/09/21/qr-code-scams-and-how-to-avoid-them/

Consequently, the cybercriminal will then gain access to these credit card details.

If you receive any HMRC related phishing QR codes that look like legitimate ones, simply forward the suspicious emails with QR codes to phishing@hmrc.gov.uk and then promptly delete them.

Coupons as Fake QR Codes

Fake coupon QR codes are another way scammers are using fake QR codes in order to steal money from unsuspecting victims in the UK.

9 Tips To Spot A Fake QR Code Scam | With Examples (6)

Source: https://malwaretips.com/blogs/the-you-have-won-2-years-subscription-to-netflix-scam/

The scammer will create fake coupon QR codes claiming to give a discount or special offer,instructing to be scanned using a smartphone camera to then be applied at a checkout, when making an online purchase from an authentic online retailer.

9 Tips To Spot A Fake QR Code Scam | With Examples (7)Source: https://www.thesun.co.uk/news/3367435/fake-supermarket-vouchers-scam-tesco-waitrose-anniversary/

Once scanned, the code redirects customers to a fraudulent website where their credit card information can be stolen by the scammer.

You may have seen this on social media platforms such as, Facebook with an Argos sale that direct users to a phishing websites.

9 Tips To Spot A Fake QR Code Scam | With Examples (8)Source: https://www.edp24.co.uk/news/20768905.dont-tempted-scam-warning-issued-1-000-argos-voucher-giveaway/

Fake QR Code Text Message Scams

Text message QR scams involving fake QR codes have become increasingly common in recent years also.

9 Tips To Spot A Fake QR Code Scam | With Examples (9)

Source: https://www.ncsc.gov.uk/guidance/avoiding-banking-malware

Scammers send text messages containing malicious links or QR codes to lead users directly to malware-laden websites or downloads without them knowing it.

9 Tips To Spot A Fake QR Code Scam | With Examples (10)

Source: https://malwaretips.com/blogs/remove-scan-the-qr-code-to-claim-your-prize-virus/

Individuals in Newcastle, UK received a fake site link offering an opportunity to "win" the new iPhone 14.

If the link was clicked or QR code was scanned the user would be directed to a phishing website that asks for payment information.

To help fight phishing scams, you should send any suspicious text messages to 60599 (network charges apply) or email phishing@hmrc.gov.uk then delete them.

Fake QR Code Scams for Charities

Fake QR codes have also been used in charity scams in the UK. In these scams, victims receive an email with a QR code leading them to a website to donate money towards what appears to be a legitimate charity organisation.

9 Tips To Spot A Fake QR Code Scam | With Examples (11)

Source: https://www.trellix.com/en-us/about/newsroom/stories/research/exploiting-tragedy-fake-donation-scams-amid-earthquake-in-turkey-and-syria.html

However, this is another way for scammers to collect money from unsuspecting donors.

9 Tips To Spot A Fake QR Code Scam | With Examples (12)Source: https://mothership.sg/2023/04/fake-qr-codes/

Warning Signs of a QR Code Scam

Poor Quality: Poorly designed QR code can be difficult to scan and may not even work at all. Additionally, a fake QR code may contain typos or other errors that make it difficult to read.

Unfamiliar Domain Name: Most legitimate businesses will use their own domain name on the real QR codes, so if the URL associated with the code looks unfamiliar or suspicious to you, it’s best to avoid scanning it.

Suspicious Content: If you scan a QR code and are presented with content that seems suspicious or out of place, this could be another warning sign of a QR code. For example, if you scan a restaurant’s QR code and are taken to an online casino site instead, this could be an indication of a fraudulent QR code.

Asking for Personal Information: Legitimate businesses will never ask for personal information such as your credit card information, payment information, financial information, login information or any kind of sensitive information via a QR code scan.

Offers Too Good to Be True: If you come across a website offering something that seems too good to be true after you scan QR codes (such as free money or products), this could also be an indication that the QR code is not legitimate.

What Could Happen If You Scan a Fake QR Code?

Any fake QR codes can lead to a range of cybersecurity risks. Some of the major risks include:

  • Malware Infection
  • Phishing Attacks
  • Financial Losses
  • Unauthorised Access
  • Data Theft

Fake QR code scams have a significant impact on consumers who are unaware that they have been targeted by cyber criminals.

In addition to financial losses, victims may also suffer from emotional distress and psychological trauma as a result of having their personal information stolen or compromised. Identity theft can take months or even years to resolve.

Source: CBS4 Indy

How to Spot Fake QR Code Scams?

Here are the 9 best tips to spot fake QR codes:

1. Check the Source

When you come across QR codes, it’s important to take a moment to check the source of the code as not all QR codes are safe to scan.

Make sure it is coming from a reputable source. If you don’t recognise the company or sites associated with the QR codes, it may be best to avoid scanning it altogether.

Additionally, if you see any misspellings or typos on the webpage where the code is located, this could be an indication that it’s not legitimate.

2. Look for Secure URLs

If you do decide to scan QR codes, make sure to look for secure URLs that start with “https://” rather than just “http://”.

Secure websites are more likely to protect your personal information and keep your data safe from hackers.

Additionally, most secure websites will also have a lock icon in the address bar of your browser when you visit them.

3. Don't Provide Sensitive Information

When scanning QR codes, never provide any sensitive information such as your credit card details or bank account details unless you are absolutely certain that the website is secure and legitimate.

It's also important to remember that no legitimate company will ever ask for personal information via any QR codes scan.

4. Avoid Unfamiliar Apps

If scanning QR codes lead you to an unfamiliar app download page, it's best to avoid downloading it altogether, as these apps could have malicious software designed to steal your personal information or damage your device.

5. Use Antivirus Software

It's also important to make sure that all your devices have up-to-date antivirus software installed on them to protect yourself from viruses and malware when you scan QR codes or visit unfamiliar websites.

6. Awareness of Scams

Be aware of any offers or deals that seem too good to be true when scanning a QR code as this could be a sign of scams or phishing attempts designed to steal your personal information or money.

7. Use Caution When Sharing Personal Data

If prompted by a website to share any personal data such as contact details or payment information after scanning a QR code, use caution, as this could be used by criminals for identity theft purposes later down the line.

8. Read Reviews Before Downloading Anything

Before downloading anything after scanning a QR code, always read reviews from other users who have tried out the product being offered in order get an idea of how reliable and trustworthy it is before taking any further action.

9. Be Wary of Links from Unknown Sources

Be wary of clicking on links sent via email from unknown sources after scanning a QR codes, as these could lead directly into malicious websites designed by cybercriminals specifically for stealing private data.

Steps to Take If You’ve Been Targeted by a QR Code Scam

If you've already scanned the code, disconnect from the Wi-Fi and turn off your phone's Bluetooth to prevent further harm.

Ensure you have an up-to-date antivirus software installed on your device and run a thorough scan.

If you've already given out sensitive information, such as financial or login credentials, contact your bank and service provider to let them know of the incident.

You can also:

  • Report the Scam
  • Change Your Passwords
  • Monitor Your Bank Account
  • Notify Your Credit Card Company
  • Contact Your Phone Provider
  • Be Wary of Future Scams
  • Reach Out for Support

Government Initiatives to Tackle Fake QR Code Scams

The UK government is taking several steps to tackle the increase in QR code scams over the last few years.

This includes introducing new laws which makes it illegal for companies to use misleading or deceptive practices when dealing with customers and their data.

They have launched a public awareness campaign about the dangers posed by fake QR codes and are investing millions into research of new technologies that can help detect fraudulent codes quickly and efficiently.

Top 5 Free QR Code Scanner Apps for Android & iOS

When you are wanting to scan a QR code, one of the safest ways is to scan it through any one of the below apps:

  • QR Code Scanner by ScanApp
  • Qrafter Pro
  • QuickMark
  • i-nigma
  • QR Code Scanner by ZXing Team

9 Tips To Spot A Fake QR Code Scam | With Examples (13)

Source: https://itservices.wp.st-andrews.ac.uk/2023/09/21/qr-code-scams-and-how-to-avoid-them/

QR Code Scams FAQs

Is it possible to make a fake QR Code?

Yes, it is indeed possible to create a fake QR Codes, which can carry misleading information or lead the user to a malicious website. Some free tools are Adobe Express app, QR code Monkey, mention QR code generator, QR code generator, Canva etc.

How can I check if a QR Code is valid?

One way is to use a QR Code scanner app that can detect if the code is valid or not. Another way is to examine the design of the code itself; genuine codes should have equal-sized squares and a clear pattern, whereas fake codes may appear distorted or contain elements that should not be there.

What happens if I scan someone's QR Code?

Usually, you will be taken to a webpage, or a product page related to the QR code. However, it's important to be cautious when scanning QR codes, as there have been cases of fraudulent QR codes.

What can hackers get access to if you scan a fake QR code?

Hackers can gain access to personal information, including name, address, and even credit card information details.

What should I do in the case of QR code scam?

The first step to take if you suspect you've been scammed through a QR code is to contact your financial institution and file a report.

Can a QR code get you hacked?

The short answer is yes, but the risk is relatively low if certain precautions are taken such as checking the URL, looking for signs of tampering and using a QR code scanner app.

9 Tips To Spot A Fake QR Code Scam | With Examples (2024)

FAQs

How to spot fake QR codes? ›

Follow these tips:
  1. Beware of the Sticker Switcheroo: Look for signs that a real QR code might be covered with a fake one. ...
  2. Peek Before You Leap: Most QR scanners will let you see the link before you click it. ...
  3. Stick to Familiar Faces: Scan codes from official sources that you know and trust.
Feb 7, 2024

What is the latest QR code scam? ›

The consumer protection agency said criminals were making their own QR codes and sticking them over legitimate ones on parking meters, or sending them to potential victims via SMS or email. Scammers overseas have put their QR codes in places where people are expecting to see and use this technology.

Can someone hack my phone by scanning QR code? ›

While QR codes themselves are not inherently malicious, they can be used as a vector for cyberattacks if they are linked to malicious websites or contain malicious code. For example, scanning a QR code that redirects you to a phishing website could lead to the theft of your personal information or login credentials.

How can I check if a QR code is valid? ›

Testing a QR code with your phone is easy and essential to ensure it works properly. You can open your phone's camera app and point it at the code – if the code is linked with an actionable item, your device will display information about what action it can take based on the data in the QR code.

What does a real QR code look like? ›

A QR code consists of black squares arranged in a square grid on a white background, including some fiducial markers, which can be read by an imaging device, such as a camera, and processed using Reed–Solomon error correction until the image can be appropriately interpreted.

Can a QR code be spoofed? ›

The scammers QR code may install malware on your device that allows them to control your device or steal your information. The QR code could also take you to a spoofed site that looks like a legitimate website but isn't.

What happens when you scan a scam QR code? ›

A scammer's QR code could take you to a spoofed site that looks real but isn't. And if you log in to the spoofed site, the scammers could steal any information you enter. Or the QR code could install malware that steals your information before you realize it.

How to avoid QR scam? ›

Do not download apps from QR codes or unfamiliar websites. * Install security software on your device to protect it from malware. Keep your security software up to date with the latest definitions.

What to do after scanning a scam QR code? ›

Minimize the Risk of Financial Loss

If scanning the QR code resulted in suspicious autonomous transactions, immediately contact your credit card company or bank for a refund. Likewise, change any financial or personal information saved on your browser that scammers can easily manipulate and use against you.

How to detect QR code malware? ›

Examine and preview the URL

Fake QR Codes often lead to a phishing website or an illegitimate app designed to either capture your personal information or steal money. Instead of scanning a suspicious QR Code, it makes sense to first preview the URL and check if it is a secure website.

How do I test a QR code with my phone? ›

How to scan QR Codes on Android 8 and above
  1. Open the camera app.
  2. Click 'More' or access 'Settings' and activate Google Lens suggestions.
  3. Point your camera at a QR Code to scan its contents.
Apr 24, 2024

How do you test a QR code safely? ›

To check the safety of a QR code, preview the URL it directs to by using your phone's camera or a QR scanner app. Your device should display the destination URL. Examine the URL for legitimacy and be wary of shortened, unreadable URLs, which could be suspicious.

How do you detect a QR code? ›

Open your Camera app and point it steadily for 2-3 seconds towards the QR Code you want to scan. Whenever scanning is enabled, a notification will appear. If nothing happens, you may have to go to your Settings app and enable QR Code scanning.

How to identify a QR code? ›

A QR reader can identify a standard QR code based on the three large squares outside the QR code. Once it has identified these three shapes, it knows that everything contained inside the square is a QR code. The QR reader then analyzes the QR code by breaking the whole thing down to a grid.

References

Top Articles
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 6488

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.