Quishing

The term 'quishing' is a neologism composed of the words 'QR code' and 'phishing'. Cybercriminals have long been using phishing methods to direct their victims to fraudulent websites. Increasingly, they are using not only e-mails but also physical media such as letters or stickers, which then use QR codes to redirect users to the fraudulent websites. For example, Würzburger Versorgungs- und Verkehrs-GmbH (WVV) recently issued a warning about tampered QR codes on parking ticket machines (https://www.tvmainfranken.de/wvv-warnt-vor-betrugsmasche-falsche-qr-code-aufkleber-an-parkscheinautomaten-385507/).

The danger is that QR codes – whether in e-mails, on letters or as stickers in public spaces – are usually only checked superficially by QR code readers, and the links contained within the QR code are not specifically flagged or blocked, provided they do not spread known malware. So if a fake website linked to a QR code (e.g. banking, social media, etc.) prompts you to enter personal (login) details, this can happen without any browser warnings at all.

The following points will help you recognise malicious QR codes in e-mails:

  • Look out for the well-known signs of phishing attacks, such as impersonal salutations, unusual phrasing, spelling mistakes or a suspicious sender address in e-mails containing QR codes.
  • Be particularly wary of emails that apply pressure, play on your fears and urge you to act quickly.


How can I protect myself against tampered QR codes outside of e-mails?

  • Check whether QR codes in public spaces have been covered up or look suspicious in any way, and, where possible, only use QR codes displayed on screens (e.g. at charging points, parking meters, etc.), as these are more difficult to forge.
  • Use multi-factor authentication (MFA) for sensitive accounts, such as online banking. This ensures your data remains protected even if your login details have been compromised.
  • After scanning: Check whether the URL displayed looks legitimate and whether any payment requests are realistic and make sense.
  • Do not enter any sensitive data if you have any doubts about the authenticity of the page you have been redirected to.


Sources
https://www.tvmainfranken.de/wvv-warnt-vor-betrugsmasche-falsche-qr-code-aufkleber-an-parkscheinautomaten-385507/
https://www.mainpost.de/regional/wuerzburg/neue-betrugsmasche-in-wuerzburg-wvv-warnt-vor-falschen-qr-codes-auf-parkscheinautomaten-art-11694179
https://www.polizei-dein-partner.de/themen/internet-mobil/detailansicht-internet-mobil/artikel/vorsicht-quishing.html
https://www.verbraucherzentrale.de/wissen/digitale-welt/phishingradar/quishing-falsche-qrcodes-in-mails-briefen-oepnv-und-strassenverkehr-98612