A New Phishing Tactic is on the Rise
Phishing is an approach hackers use to gain access to your computer, data, and account information. The most common type of phishing is email phishing followed by text message phishing (smishing) and voice phishing (vishing). You can dig deeper into the different types of phishing by reading our previous article on cyber-attacks here.
While these types of phishing are still prevalent, a new type of phishing has surfaced called QR code phishing. Even those who are well-educated in phishing have been fooled by QR code phishing. Often hiding in plain sight, this phishing tactic can allow a hacker access to your data within seconds.
What is QR Code Phishing?
QR code phishing (or quishing) refers to an attempt by a hacker to breach your data using a QR code. A QR code is a series of dot-based images organized to link directly to a website when a user scans the code. You may have encountered a QR code in place of a restaurant menu, on a business card, or on a print advertisement.
QR codes are a useful way to give everyday users a quick way to access a website, video, or link to download an app by scanning the code with their phone camera. However, because there is no way to inspect the link before visiting, it can be hard to determine if it is malicious. Because of this, it is important to make sure you know how to recognize the different types of QR phishing.
Types of QR Phishing
QR phishing can come in a variety of formats, each one can cause a significant amount of damage to your data, accounts, and devices. Let’s look at the different types of QR phishing and what can happen if you scan one.
Quishing
Quishing refers to the act of using email to steal email credentials or scam unsuspecting users. The hacker will spoof an email address that looks like a reputable company and ask you to scan the code to check a voicemail, change your login, or even enter financial information. Once you enter your information, the hacker can change your passwords, steal your information, and lock your accounts.
Drive by QR Code Phishing
Drive by malware via QR code phishing consists of an email sent to the target containing a QR code linking to a malware infection. When the QR code is scanned and the malicious website is visited, a trojan will be deployed into the device and will be able to steal any information accessed by the device.
QR Code Replacement
QR codes can be placed anywhere. If you’re in a public place, be wary of scanning QR codes. Cybercriminals can replace the QR codes of known companies or create QR codes for fake offers that will link to malicious websites. Always stay vigilant when you interact with QR codes, especially when in stadiums, public transport, and other public gathering spaces.
How Can I Avoid QR Phishing?
The best way to avoid QR phishing is education. Stay aware of the different types of QR phishing as well as the place they can be found will go a long way in protecting you from cybercrime. Secondly, using a DNS filter can help block malicious URLs by using a database of malicious links and adding them to a block list. Lastly, ensuring you have phishing protection on your email will keep phishing of all kinds out of your inbox and greatly decrease the chances of an attack.
That’s all for this week, we’ll see you next time for Tech Tip Tuesday!
If you need more information about phishing and how to protect your business from targeted attacks, give us a call at 512-86-1155 or visit our website at Computekonline.com
Comments