us

216.73.217.135

Back
News

“Cybercriminals are Tampering with QR Codes to Redirect Victims”, FBI Warns

“Cybercriminals are Tampering with QR Codes to Redirect Victims”, FBI Warns
R Richard M. JANUARY 24, 2022 1 minute read

The Federal Bureau of Investigation (FBI) has issued a warning regarding Malicious QR codes that are being used by criminals to scam Americans.

The FBI issued a warning as a public service announcement (PSA), that was published on the FBI’s Internet Crimes Complaint Center (IC3) earlier this week. The FBI warned citizens of America that cybercriminals are using malicious Quick Response (QR) codes to steal victims’ personal and financial credentials.

The law enforcement authority stated that the penetrators are replacing legit QR codes that are being used by the businesses for payment gateways with malicious ones to redirect the victims to bogus websites designed to steal Personally Identifiable Information (PII) along with the financial credentials. Furthermore, malware virus is then installed on their devices, or payments are diverted to criminals’ accounts.

“Cybercriminals are tampering with QR codes to redirect victims to malicious sites that steal login and financial information,” the federal law enforcement agency said.

After the victims scan the codes that appear legitimate, they are directed towards criminals’ phishing websites, where customers are provoked to provide their financial credentials. Once, the financial information is entered, the cybercriminals get access to PII and use it to steal funds using hijacked bank accounts.

“While QR codes are not malicious in nature, it is important to practice caution when entering financial information as well as providing payment through a site navigated to through a QR code,” the FBI added. “Law enforcement cannot guarantee the recovery of lost funds after transfer.”

The federal investigation authority advised locals to pay attention to the URL they are sent after scanning QR codes, always verify the sites before providing any kind of information, and make sure that the physical QR codes have not been replaced with malicious ones. Last but not least, always enter the URLs by hand when making payments instead of scanning QR codes that probably could be set up to redirect to the phishing sites. In addition to this, people should also avoid installing applications from QR codes, instead use the apps that come with the smartphone’s operating system.

Like this, the FBI had issued another PSA associated with QR codes risk in November 2021, alerting the people of America of emerging fraud schemes like criminals using malicious QR codes and cryptocurrency ATMs to hinder efforts to recover financial losses. For example, in a recent phishing attack targeting German e-banking customers, criminals use QR codes instead of buttons in spam emails to make their activities impossible to determine by the bank’s cybersecurity systems and seamlessly redirect the victims to phishing websites. Unfortunately, customers were redirected to the malicious landing pages and ended up providing personal and financial information.

Suggested Read: SMS Phishing Scams are Impersonating State Agencies – FTC Warns

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.