Cybersecurity Experts Warn: Fake QR Code Scams Rise

www.news4hackers.com-cybersecurity-experts-warn-fake-qr-code-scams-rise-cybersecurity-experts-warn-fake-qr-code-scams-rise

Rise in Deceptive QR Code Scams Sparks Warnings from Cybersecurity Experts Fake QR codes are increasingly being deployed to siphon funds and compromise merchant accounts across India, prompting cybersecurity professionals to issue urgent guidance on identifying and avoiding these threats.

Understanding the Threat

Fake QR codes are increasingly being deployed to siphon funds and compromise merchant accounts across India, prompting cybersecurity professionals to issue urgent guidance on identifying and avoiding these threats. The proliferation of digital payment systems, particularly Unified Payments Interface (UPI) transactions, has made QR codes a ubiquitous element of commerce, spanning retail outlets, hospitality services, and public infrastructure. Attackers are exploiting this reliance by embedding counterfeit codes that redirect users to fraudulent payment portals or phishing sites, enabling the theft of financial data and unauthorized transactions.

Distribution Channels

Malicious QR codes are distributed through multiple channels, according to security analysts. Fraudsters frequently affix deceptive stickers over legitimate payment codes at physical locations such as retail stores, parking facilities, and fuel stations. Simultaneously, cybercriminals distribute harmful codes via social media platforms and messaging apps, often disguised as promotions for cashback rewards, account verification requests, or urgent notifications.

Quishing Surge

The prevalence of QR code-based phishing, termed “quishing,” has surged dramatically. Data from 2025 indicates a fivefold increase in such attacks, with 12% of phishing emails now incorporating QR codes—a significant jump from near-zero levels just two years prior. Mobile users are disproportionately targeted, as smaller screen sizes limit visibility of URL previews, making it easier for attackers to conceal malicious links.

Recent Cases and Sophistication

Recent cases highlight the evolving sophistication of these schemes. Delhi Police uncovered a scheme inspired by a South Indian film’s storyline, where an individual posing as a customer requested a shopkeeper’s QR code to “verify a purchase.” The attacker then digitally manipulated the code, retaining the shopkeeper’s name while replacing the underlying account details. Many merchants reused the same QR code image from their phone galleries, unaware it had been altered, leading to payments being diverted to the fraudster’s account.

Merchant Risks

Merchants face additional risks as fraudulent actors exploit their QR codes for money laundering. Investigators note that stolen funds are often used to purchase goods from small businesses, creating a trail that ultimately implicates the merchant when law enforcement traces the transactions. This practice leaves business owners unable to access their accounts, disrupting operations and causing financial instability for employees and customers reliant on digital payments.

Regulatory Measures

Regulatory bodies are implementing countermeasures to mitigate these threats. Several Indian states have introduced dynamic QR codes that refresh every 60 seconds at high-risk locations like petrol pumps. The National Payments Corporation of India has also tested a “SafePay” verification feature for legitimate merchant codes in major cities, with plans to expand the initiative to 50 locations by September 2026.

Consumer Advice

Consumers are advised to scrutinize QR codes before scanning them. Signs of tampering, such as overlapping stickers, peeling edges, or recently applied labels, should raise immediate suspicion. Users should only engage with codes from verified sources and verify the destination URL on their devices, canceling the action if the address contains typos or unfamiliar domains. Experts emphasize that legitimate financial transactions do not require scanning QR codes to receive funds. Any request for a code to process refunds, salaries, prizes, or cashback is likely a ploy to initiate unauthorized payments.

Protecting Sensitive Information

Users should immediately terminate any session that prompts for sensitive information such as OTPs, UPI PINs, or banking passwords, as no authorized institution would request such details through a QR code. The Reserve Bank of India has proposed additional safeguards, including a one-hour delay for large peer-to-peer transfers and an annual cap on UPI credits to prevent the misuse of mule accounts. These measures remain under discussion and have not yet been implemented.

Reporting Suspicious Activity

Individuals encountering suspicious QR code activity are urged to report incidents promptly through the National Cyber Helpline at 1930 or the National Cyber Crime Reporting Portal. Timely reporting enhances the likelihood of intercepting fraudulent transactions before funds are irretrievably lost.

Delhi Police uncovered a scheme inspired by a South Indian film’s storyline, where an individual posing as a customer requested a shopkeeper’s QR code to “verify a purchase.” The attacker then digitally manipulated the code, retaining the shopkeeper’s name while replacing the underlying account details.



About Author

en_USEnglish