QR Code Scams Surge in India; Palo Alto Networks Urges Caution
By MYBRANDBOOK
The United Payment Interface (UPI) surpassed 10 billion monthly transactions in August with a transaction value of INR15.18tn ($204.77bn). While Indian netizens have quickly adopted digital payments, a surge in QR code scams is plaguing the country. Per Bengaluru city police data, more than 50,027 cybercrime cases were registered in Bengaluru between 2017 and May 31, 2023. 41% of them (20,662 cases) were related to QR codes, malicious links, or debit/credit card fraud.
Amidst this slew of financial frauds, Palo Alto Networks today issued an advisory to be vigilant against these TTPs (threats, tactics, and procedures). Given the visual similarity of most QR codes and the difficulty in discerning differences, attackers can compromise a business' website by substituting the genuine QR code with their own. When individuals scan this altered code, it can automatically redirect them to a phishing URL, where cybercriminals can request user credentials and gain access to email or social media accounts, among other things. Alternatively, it could lead users to an untrustworthy app store, urging them to download a malicious application. Such apps typically contain viruses, spyware, trojans, or other types of malware, enabling data theft, privacy breaches, ransomware attacks, and in some instances, even crypto-mining.
Another prevalent TTP among cybercriminals is the use of "evil twin" or hotspot honeypots. In this scenario, threat actors establish an insecure Wi-Fi network, enticing users with free internet access upon scanning their QR code. Once connected, hackers intercept and eavesdrop on the data being transmitted, pilfering personal or confidential business information, online banking credentials, and credit card details. Given the global adoption of hybrid working, individuals must exercise caution and connect only to secure Wi-Fi networks to avoid falling into these cyber-traps.
Online marketplaces, too, are fertile grounds for scammers to perpetrate such fraudulent schemes. For instance, when individuals post classified ads, scammers often masquerade as interested buyers. After initial negotiations with the buyer, the fraudster provides the victim with a QR code, instructing them to scan it to claim their payment. After which, the victim’s bank account is compromised.
Palo Alto Networks advises netizens to adhere to the following:
1. Think Before You Scan: Resist the urge to scan any QR code without knowing its destination. Prioritise caution and scrutinise the QR code's intended website and domain for legitimacy.
2. Preview the website: Utilise secure QR code scanning apps that offer website previews before visiting. In web browsers, disable automatic redirects to scrutinise the URL domain for trustworthiness.
3. Download Apps from Trusted Sources: Only download mobile apps from reputable sources like Apple's App Store or Google Play Store.
4. Keep Devices Updated: Regularly update all your smart devices with the latest security patches and software updates.
5. Stay Aware and Alert: Maintain a vigilant and alert attitude towards QR codes and potential security threats.
“With QR codes now deeply integrated into our daily lives, related scams have surged in prominence. Cybercriminals exploit this by surreptitiously replacing QR codes in establishments such as bars, restaurants, lounges, shops, and clubs. This can result in unauthorised UPI payments and potential financial harm. Incidents of scanner replacement fraud are on the rise, and the threat may escalate in the future,” said Vicky Ray, Principal Researcher – Unit 42 at Palo Alto Networks.
“Vigilance is paramount for both individuals and merchants. Regularly inspecting their QR code scanners and implementing essential precautions is crucial to thwarting these fraudulent activities,” Vicky added.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
INFOSYS TECHNOLOGIES PVT. LTD.
FRESHWORKS TECHNOLOGIES PVT. LTD.
TALLY SOLUTIONS PVT. LTD.
TAC SECURITY SOLUTIONS
Icons Of India : Arundhati Bhattacharya
Arundhati Bhattacharya serves as the Chairperson and CEO of Salesforce...
ICONS OF INDIA : VINAY SINHA
Vinay Sinha is the Managing Director of Sales for the India Mega Regio...
Icons Of India : NANDAN NILEKANI
Nandan Nilekani is the Co-Founder and Chairman of Infosys Technologies...
LIC - Life Insurance Corporation of India
LIC is the largest state-owned life insurance company in India...
PFC - Power Finance Corporation Ltd
PFC is a leading financial institution in India specializing in power ...
CSC - Common Service Centres
CSC initiative in India is a strategic cornerstone of the Digital Indi...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - Lal Karsanbhai, President & CEO, Emerson
Lal Karsanbhai, President and CEO of Emerson, assumed the leadership i...
Indian Tech Talent Excelling The Tech World - Aman Bhutani, CEO, GoDaddy
Aman Bhutani, the self-taught techie and CEO of GoDaddy, oversees a co...