Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Are QR Codes Convenient or Risky? What Your Business Needs to Know

Author: Scarinci Hollenbeck, LLC

Date: March 29, 2022

Key Contacts

Back
Are QR Codes Convenient or Risky? What Your Business Needs to Know

Should businesses and consumers be wary of QR codes?

Quick Response bar codes (better known as QR codes) are everywhere, from restaurant menus to product packaging. One company even floated one across fans’ television screens during the Super Bowl this year. But should businesses and consumers be wary of QR codes?

QR Code Use Increased During the Pandemic

Essentially, a QR code is a square barcode that a smartphone camera can scan and read to provide quick access to a website, prompt the download of an application, and direct payment to an intended recipient. The use of QR codes grew exponentially during the COVID-19 pandemic as they allowed businesses to provide “touch-free” services to customers and eliminate the need for paper items, such as menus and bills.

FBI Bulletin Warns Cybercriminals Are Targeting QR Codes

Unfortunately, cybercriminals have taken notice of our increased reliance on QR codes and stepped up their attacks. The increased cyber risks of using QR codes recently prompted the Federal Bureau of Investigation to issue an alert to both businesses and consumers.

“Businesses use QR codes legitimately to provide convenient contactless access and have used them more frequently during the COVID-19 pandemic,” the FBI bulletin stated. “However, cybercriminals are taking advantage of this technology by directing QR code scans to malicious sites to steal victim data, embedding malware to gain access to the victim’s device, and redirecting payment for cybercriminal use.”

Cybercriminals are targeting both digital and physical QR codes by replacing legitimate codes with malicious codes. According to the FBI, in a typical QR code scam, a victim scans what they think to be a legitimate code but the tampered code directs victims to a malicious site, which prompts them to enter login and financial information. Access to this victim information allows the hacker to potentially steal funds through victim accounts. Malicious QR codes may also contain embedded malware, which provides access to the victim’s mobile device and allows hackers to steal the victim’s location, along with personal and financial information.

Another version of the scam involves QR codes used by businesses to facilitate payment. When a business provides customers with a QR code directing them to a site where they can complete a payment transaction, cybercriminals can replace the intended code with a tampered QR code and redirect the sender’s payment for cybercriminal use.

The FBI offers the following tips to lower the risk of falling victim to QR code fraud:

  • Once you scan a QR code, check the URL to make sure it is the intended site and looks authentic. A malicious domain name may be similar to the intended URL but with typos or a misplaced letter.
  • Practice caution when entering login, personal, or financial information from a site navigated to from a QR code.
  • If scanning a physical QR code, ensure the code has not been tampered with, such as with a sticker placed on top of the original code.
  • Do not download an app from a QR code. Use your phone’s app store for a safer download.
  • If you receive an email stating a payment failed from a company you recently made a purchase with and the company states you can only complete the payment through a QR code, call the company to verify. Locate the company’s phone number through a trusted site rather than a number provided in the email.
  • Do not download a QR code scanner app. This increases your risk of downloading malware onto your device. Most phones have a built-in scanner through the camera app.
  • If you receive a QR code that you believe to be from someone you know, reach out to them through a known number or address to verify that the code is from them.
  • Avoid making payments through a site navigated to from a QR code. Instead, manually enter a known and trusted URL to complete the payment.

For businesses, there are also steps you can take to deter QR code fraud. Examples include generating dynamic QR codes at checkout, regularly policing QR codes for tampering, and not placing physical QR codes where they can easily be tampered with. While you likely will not be held liable if a customer is scammed, because QR fraud can’t erode trust and damage your brand, it is important to be vigilant.

If you have questions, please contact us

If you have any questions or if you would like to discuss the matter further, please contact me, Maryam Meseha, or the Scarinci Hollenbeck attorney with whom you work, at 201-896-4100.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Smart Contract Legal Issues: Drafting Agreements for Blockchain post image

Smart Contract Legal Issues: Drafting Agreements for Blockchain

Smart contracts feature a unique blend of legal agreement and technical code. This innovation has the potential to reshape how business is conducted. At the same time, smart contract legal issues around enforceability, jurisdiction, identity, and compliance are common. The legal framework for these self-executing agreements is still evolving. What Are Smart Contracts? Smart contracts, […]

Author: Bryce S. Robins

Link to post with title - "Smart Contract Legal Issues: Drafting Agreements for Blockchain"
Are Stay Interviews the Key to Retaining Top Talent? post image

Are Stay Interviews the Key to Retaining Top Talent?

Retaining top talent continues to be one of the greatest challenges facing employers today. Even in an employer’s market, the loss of a key employee can disrupt operations and result in significant costs. While compensation plays a role, long-term retention often depends on workplace culture, communication, and employee engagement. One increasingly popular strategy for improving […]

Author: Angela A. Turiano

Link to post with title - "Are Stay Interviews the Key to Retaining Top Talent?"
Why Secured Transactions Are Important post image

Why Secured Transactions Are Important

Secured transactions form the backbone of a wide range of business dealings, including business loans, mortgages, and inventory financing. Because the stakes are often high and relatively minor oversights can have drastic consequences, lenders and borrowers should thoroughly understand how to form an enforceable security agreement that protects their legal rights. What Is a Secured […]

Author: Dan Brecher

Link to post with title - "Why Secured Transactions Are Important"
Don’t Cash a “Paid in Full” Check Without Understanding the Legal Implications post image

Don’t Cash a “Paid in Full” Check Without Understanding the Legal Implications

Cashing a check marked “paid in full” can be a risky endeavor, particularly if you don’t fully understanding the legal implications. If you are owed more than the amount of the check you accept and deposit, you may waive your right to collect the full disputed amount. That is why you should consider either rejecting […]

Author: Dan Brecher

Link to post with title - "Don’t Cash a “Paid in Full” Check Without Understanding the Legal Implications"
Changes to Qualified Small Business Stock Will Benefit Startup Founders and Investors post image

Changes to Qualified Small Business Stock Will Benefit Startup Founders and Investors

The One Big Beautiful Bill Act of 2025 (OBBBA) significantly impacts federal taxes, credits, and deductions. A key change relating to Qualified Small Business Stock (QSBS) allows greater tax-free gains for investments in startups and other qualifying small businesses. Company founders and other investors should understand how the enhanced tax strategy works or risk missing […]

Author: Dan Brecher

Link to post with title - "Changes to Qualified Small Business Stock Will Benefit Startup Founders and Investors"
Corporate Consolidation and Antitrust Issues in Mergers post image

Corporate Consolidation and Antitrust Issues in Mergers

Corporate consolidation involves two or more businesses merging to become a single larger entity. The result is often a stronger and more competitive company that can better navigate today’s competitive marketplace. What Is Corporate Consolidation? Corporate consolidation closely resembles a basic merger transaction. The primary difference is that a consolidation creates an entirely new business […]

Author: Dan Brecher

Link to post with title - "Corporate Consolidation and Antitrust Issues in Mergers"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!