What is ‘QRishing’, the threat hidden behind a QR code

The National Police has warned about ‘QRishing’ type scams, a variant of ‘phishing’ that uses QR codes to allow victims to access fraudulent websites to steal information or distribute ‘malware’. Once they have collected this information, attackers can take advantage of it to carry out attacks such as identity theft, financial fraud or ‘ransomware’, as Cloudflare has highlighted on its website.

Faced with this type of scam, the National Police has indicated that both Android and iOS smartphones have settings to configure the camera scan to fully display the link to which the QR code redirects before opening it, in order to check it before clicking on it.

In addition, the National Cybersecurity Institute (INCIBE) recommends not scanning QR codes without being sure of their origin and purpose, checking that it is not a sticker, suspecting if it does not belong to the domain of the company or service and having the device’s protection tools updated.

By Editor