Skip to main content

In a rush? Watch out for dodgy QR codes

QR codes are everywhere; we use them to read the menu at a restaurant, pay for our parking, sign up to a newsletter or sign in to our streaming service. However, the popularity of QR codes now means that scammers are taking advantage. Quishing, or QR phishing, is where victims are convinced into scanning a fraudulent QR code, and provide their details to the phisher. 

How does QR phishing work?

This is a very simple scam, and it starts with the phisher creating a fraudulent QR code that links to a website that they have created. The website is created with the placement of the QR code in mind; for example, a phisher planning to place a QR code at a bar might have a clone of the bar’s website. Then the QR code can be printed onto a sticker and placed anywhere in the real world, from a bench to a lamppost to a restaurant menu, or somewhere online like on a website, or social media page.

There’s very little way to tell from looking at a QR code where it is going to take you, and as such the victim ends up on a website that looks something like the website that they expected, and enters their information. They then find themselves subscribed to something, having paid for a service they don’t need, or having sent their personal information away to the phisher who can then sell this information on or use it for further scams. 

Social engineering, and QR phishing

Social engineering is a way of exploiting a victims’ natural responses in order to extort something from them, such as their personal information or access to a building or account. A person who is carrying a ladder and wearing a high vis vest, for example, might be able to socially engineer their way into a building without the necessary identification, because people assume that they are there to work.

QR phishing also uses a kind of social engineering. People who are scanning QR codes are often looking to move through a process quickly; paying for parking, for example, is something that you might need to do on the way to somewhere else. Scammers can exploit this natural inclination, by creating a website that looks similar to the one the victim was expecting, and then having them provide their details or sign up to a subscription.

Keeping yourself safe from QR phishers

When you come across a QR code out in the world, look for signs of tampering before you scan, and where possible, access the website you need by searching for it manually. You should never scan a random QR code that you come across; remember, this is exactly the same as seeing a random website scrawled on the side of a wall and deciding to visit it. Sometimes just accessing a website can result in malware being installed on your devices. 

The same goes for QR codes that you might find online. Where possible, access the website you’re looking for yourself; that way you can be sure that you’re accessing something that is legitimate. If you receive a QR code randomly, either through email or through social media, do not scan the code (particularly if something in the email or the post implies that there is any kind of time limit). Keep yourself, and your devices safe, and send that QR code to Junk.


The Transcendit Way

Transcendit understand that when you choose to work with us, whether we're taking care of your IT, app or web development, you're trusting us with part of your business. So whether we're looking after your computers, phone systems or servers we always do things 'the Transcendit way'.

The whole of our team adhere to the same values, beliefs and policies - the principles that were written when Transcendit first formed in 2000. Whether you come to us for cloud services or recovery backup you can be confident that you'll always receive the same excellent service.

The Transcendit way outlines how we do business; following the same straightforward principles with every client and customer, regardless of how big or small they may be.

That means we get to know you and your business. We offer you a friendly, professional and efficient service, and we'll always be honest with you.
We understand that not everybody speaks fluent IT, so we try to explain things in a way that is simple and clear. We always spend as much time as is necessary explaining things to you.
If you need to talk to us about something, no matter how insignificant, we are only ever a phone call away – and we’re never too busy to make you a cup of tea and have a sit down with you in person.
We understand how frustrating it can be when things are late. When we schedule an appointment with you, we are there when you’re expecting us. If something prevents us from getting there, we always call you in advance to let you know.
Sometimes things can go wrong, but we never lie to you or try to cover something up. If things go askew we tell you what’s happened and how we plan to prevent it affecting your business.
We want you to continuously benefit from working with us. We regularly discuss your business and make suggestions for improving systems and processes wherever we can – but we never try to push you into a purchase.
When we quote a fixed price, that's always the amount we charge – you won’t find any nasty surprises on a bill from us. If you are paying by time and materials, we inform you if our approximations could change.
We understand the importance of privacy for your business and your customers. We respect the confidentiality of your data, and we will never pass on your information to third parties.
We appreciate it when you take the time to give us feedback. A system called CustomerSure records our client's responses, so you can trust that our reviews are from real people.
Find out what they're saying here.
Your team have been superb! Quick to respond. No hassle. They just get on with the job. After a well-planned and executed Microsoft 365 migration I have been firing out emails as teething problems have arisen and they have turned the requests around pronto. Not to mention being carried out in a friendly yet professional manner. Just amazing performance! Rosie Malcolm-MacEwan

Based on 12075 reviews our customers rate us 9.8/10. Reviews and ratings by Customersure. 09-October-2024

Transcendit are proud sponsors of CHUF, the Children's Heart Unit Fund.

Transcendit is a Microsoft Gold certified partner
VMWARE partner
Vipre partner
IPCortex partner
WithSecure partner
DELL partner
Barracuda partner
Veeam partner
N-Able partner