QR Codes Enable New Enterprise Phishing Threat


Enterprises increasingly targeted by scam QR codes embedded in PDF documents attached to emails, in latest twist to damaging attack model

Corporations are increasingly being targeted by scam QR codes embedded in PDF documents attached to emails, security researchers have warned, as attackers use the technique to bypass security systems and introduce malicious links into organisations.

Security vendor Barracuda said in a threat report that it had recorded half a million examples of the technique, which adds a new dimension to previous phishing threats.

In the past attackers at times embedded QR codes in emails themselves, but placing them in PDFs makes them that much harder to detect, the firm said.

Recipients are typically told to scan the code with a mobile device to view a file, sign a document or listen to a voice message, Barracuda said.

Image credit: Sora Shimazaki/Pexels

QR-code phishing

“If they do so, they are brought to a phishing website designed to capture their login credentials,” the company stated.

Microsoft is the most-impersonated company in the recorded scams, including its SharePoint and OneDrive services, at 51 percent, followed by DocuSign at 31 percent and Adobe at 15 percent.

The report suggested stronger email security, multi-factor authentication and AI could be used along with employee education to help limit such scams.

Security products generally do not scan images in documents attached to emails for potentially harmful content, and doing so could slow down delivery of emails and increase the cost of systems, security firm Sophos said.

Lenders Santander, HSBC, and TSB, along with the UK National Cyber Security Centre (NCSC) and the US Federal Trade Commission have all warned of QR codes being used in sophisticated phishing attacks, the Financial Times reported.

IBM found phishing attacks in general are increasingly expensive to companies, with the aveerage cost of a data breach rising nearly 10 percent year-on-year to $4.9 million (£3.8m) in 2024.

Sticker scams

The scams have increased in prevalence with the massive rise in usage of QR codes since the Covid-19 pandemic, when they were used for contactless transfer of information ranging from check-in codes to restaurant menus.

McAfee said in May that more than one-fifth of all online scams in the UK probably originated from QR codes, with reports of QR code scams in the UK more than doubling in the year to August 2024, according to Action Fraud.

The US Federal Trade Commission and multiple local authorities across the UK have warned this year of scam QR codes being placed on stickers that cover legitimate codes used to pay for parking.

These scams can lead users to websites asking for financial details or downloading malware, in addition to leading to fines for failing to pay for parking.

Reports have similarly said such scam QR codes are in use at EV charging points, train stations and restaurant tables.



Source link

Share

Latest Updates

Frequently Asked Questions

Related Articles

NASA reestablishes contact with one of two TRACERS satellites

WASHINGTON — NASA has restored contact with one of a pair of space...

tata technologies: Tata Technologies to fully acquire ES-Tec Group for nearly Rs 775 crore

Global product engineering and digital services firm Tata Technologies on Saturday said it...

Albania Appoints an AI as Government Official

Albania has appointed the world's first-ever AI government official in hopes of rooting...
sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online Sabung Ayam Online Sv388 Sv388 SV388 sabung ayam online sabung ayam online Sabung Ayam Online sabung ayam online sabung ayam online sabung ayam online Sabung ayam online Sabung ayam online SV388 sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online SV388 sabung ayam online SV388 SV388 Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sv388 SV388 SV388 sabung ayam online sv388 sv388 sabung ayam online sv388
judi bola judi bola Judi bola SBOBET judi bola judi bola judi bola Judi Bola Online judi bola judi bola judi bola judi bola judi bola judi bola juara303 juara303 Judi bola online judi bola judi bola judi bola judi bola judi bola judi bola judi bola judi bola SBOBET judi bola judi bola judi bola Judi Bola SBOBET88 SBOBET88 judi bola judi bola judi bola JUDI BOLA ONLINE JUDI BOLA ONLINE SBOBET88 Judi Bola Judi Bola judi bola judi bola judi bola judi bola judi bola Judi Bola Online judi bola judi bola judi bola judi bola mix parlay
CASINO ONLINE SLOT GACOR live casino mahjong ways Live Casino Online Slot Gacor Mahjong Ways slot pulsa Casino Online Slot Gacor Mix Parlay live casino online live casino online LIVE CASINO ONLINE LIVE CASINO ONLINE slot pulsa slot pulsa slot pulsa Mpo Slot
https://ejurnal.staidarulkamal.ac.id/ https://doctorsnutritionprogram.com/ https://nielsen-restaurante.com/ https://www.atobapizzaria.com.br/ https://casadeapoio.com.br/ https://bracoalemao.com.br/ https://letspetsresort.com.br/ https://mmsolucoesweb.com.br/ https://procao.com.br/
Rahasia Kemenangan di Mahjong Wild Pemain Tidak Menyangka Pola Scatter Jangan Anggap Remeh Mahjong Wild Pemain Pemula Heran Setelah Coba Mahjong Wild Menemukan Pola Rahasia yang Bikin Scatter Muncul Pola Scatter Rahasia yang Baru Terbongkar Pola Rahasia Pemain Pemula Terbongkar Mereka Ketagihan Karena Sering Dapat Kemenangan Mereka Ketagihan Karena Sering Dapat Kemenangan Trik Sederhana Saat Taruhan Kecil Pola Wild Liar Tersembunyi Bisa Menggandakan uang Pola Rahasia Baru Bisa Menghasilkan Wild Buktikan Pola Wild Liar dan Scatter Hitam Kaya Setelah Main Mahjong Wild Pria Asal Nepal Obrak-Abarik Kantor DPR