{"id":292,"date":"2025-06-12T13:48:00","date_gmt":"2025-06-12T12:48:00","guid":{"rendered":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrccrc\/?p=292"},"modified":"2025-11-05T13:52:25","modified_gmt":"2025-11-05T13:52:25","slug":"qr-codes-are-they-safe-and-what-are-the-risks","status":"publish","type":"post","link":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/qr-codes-are-they-safe-and-what-are-the-risks\/","title":{"rendered":"QR codes: are they safe and what are the risks?"},"content":{"rendered":"\n<p>Once a convenient tool for accessing websites or menus, QR codes have now become a widespread gateway to digital services. From restaurant tables to parcel delivery notifications, they&#8217;re everywhere. But with convenience comes risk\u2014and the UK\u2019s National Cyber Security Centre (NCSC) has flagged some important concerns around QR code security.<\/p>\n\n\n\n<p>In this post, we\u2019ll explore the risks of scanning QR codes, how criminals are exploiting them, and what you can do to stay safe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Are QR Codes and Why Are They a Target?<\/h2>\n\n\n\n<p>Quick Response (QR) codes are two-dimensional barcodes that can store URLs, contact details, or payment information. When you scan one with your phone&#8217;s camera, it often takes you directly to a website or app.<\/p>\n\n\n\n<p>This directness is also what makes them attractive to cybercriminals. A malicious QR code can lead to a phishing site, download malware, or trick you into sharing sensitive information.<\/p>\n\n\n\n<p>Risks of Scanning QR Codes<\/p>\n\n\n\n<p>According to guidance from the NCSC, here are the key risks:<\/p>\n\n\n\n<p><strong>1. Phishing and Fraudulent Websites<\/strong><\/p>\n\n\n\n<p>QR codes can easily direct users to fake websites that mimic legitimate services (like banks or delivery companies). These sites may trick users into entering personal or financial details.<\/p>\n\n\n\n<p>For example: A QR code on a parking meter might link to a spoofed payment site that steals your card information. Spoof QR codes were seen in some<a href=\"https:\/\/news.leicester.gov.uk\/news-articles\/2024\/september\/fraudsters-target-council-parking-machines-with-fake-qr-codes\/\"> Leicester City Council car parks last year.<\/a><\/p>\n\n\n\n<p><strong>2. Malware Installation<\/strong><\/p>\n\n\n\n<p>Some QR codes can prompt the download of apps that contain malware &#8211; especially on devices where app permissions are too lax or from outside official app stores.<\/p>\n\n\n\n<p><strong>3. Credential Theft<\/strong><\/p>\n\n\n\n<p>When QR codes are used in phishing campaigns, they can be embedded in emails or posters. A scanned QR code might auto-fill login forms or redirect you to a fake login page.<\/p>\n\n\n\n<p><strong>4. Social Engineering<\/strong><\/p>\n\n\n\n<p>Attackers can place fraudulent QR codes over legitimate ones (called &#8220;QRishing&#8221;). For example, a cybercriminal may stick a malicious QR code over an official NHS or restaurant QR code.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Safe Are QR Codes Really?<\/h2>\n\n\n\n<p>QR codes themselves aren\u2019t inherently dangerous &#8211; they\u2019re just a medium. The problem is that you can\u2019t tell where a QR code will take you until after you scan it.<\/p>\n\n\n\n<p>That\u2019s why the NCSC advises treating QR codes with caution, especially in public places or if they appear in unexpected messages (like unsolicited emails or text messages).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tips for Staying Safe<\/h3>\n\n\n\n<p>Here are some practical ways to protect yourself:<\/p>\n\n\n\n<p><strong>Preview the Link<\/strong><\/p>\n\n\n\n<p>Most smartphones now show the URL before opening it. Always check that the domain name looks legitimate and is spelled correctly.<\/p>\n\n\n\n<p><strong>Don\u2019t Scan from Untrusted Sources<\/strong><\/p>\n\n\n\n<p>Avoid scanning QR codes from unknown posters, flyers, or suspicious emails. If you weren\u2019t expecting it, treat it with suspicion.<\/p>\n\n\n\n<p><strong>Use a QR Scanner with Security Features<\/strong><\/p>\n\n\n\n<p>Some apps can verify whether a link is safe before opening it. Some antivirus apps also scan QR codes for threats.<\/p>\n\n\n\n<p><strong>Don\u2019t Enter Sensitive Info After Scanning<\/strong><\/p>\n\n\n\n<p>Be cautious if a QR code takes you to a login or payment page. If in doubt, manually type in the known website URL instead.<\/p>\n\n\n\n<p><strong>Update Your Phone\u2019s Software<\/strong><\/p>\n\n\n\n<p>Ensure your phone&#8217;s operating system and apps are up to date to reduce vulnerabilities that malware could exploit.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Should Businesses Do?<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If your organisation uses QR codes:<\/li>\n\n\n\n<li>Avoid linking to sensitive actions (like payments or login) unless absolutely necessary.<\/li>\n\n\n\n<li>Use branded URLs so users can verify where they&#8217;re going.<\/li>\n\n\n\n<li>Educate staff and customers on the risks of fake QR codes.<\/li>\n\n\n\n<li>Monitor for tampering in physical locations &#8211; check if anyone has stuck a new QR code over your signage.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>QR codes are here to stay, but they\u2019re not risk-free. As the NCSC highlights, cybercriminals are exploiting them more often because they\u2019re easy to manipulate and users tend to trust them.<\/p>\n\n\n\n<p>By staying alert, being cautious of unknown QR codes, and encouraging good cyber hygiene, you can continue using this convenient technology &#8211; safely.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p class=\"has-text-align-center\"><strong>Reporting<\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center\"><strong>Report all Fraud and Cybercrime to Action Fraud by calling 0300 123 2040 or <a href=\"https:\/\/www.actionfraud.police.uk\/\">online<\/a>. Forward suspicious emails to report@phishing.gov.uk. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Once a convenient tool for accessing websites or menus, QR codes have now become a widespread gateway to digital services. From restaurant tables to parcel&#8230;<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-292","post","type-post","status-publish","format-standard","hentry","category-uncategorised"],"acf":[],"_links":{"self":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/posts\/292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/comments?post=292"}],"version-history":[{"count":1,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/posts\/292\/revisions"}],"predecessor-version":[{"id":293,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/posts\/292\/revisions\/293"}],"wp:attachment":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/media?parent=292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/categories?post=292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/eastmidlandscrc\/wp-json\/wp\/v2\/tags?post=292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}