Tampered QR Codes
A QR code has no sender, and a sticker can replace it.
What Is Tampered QR Codes?
A printed QR code has no sender and no preview, and a sticker over a real one sends everyone who scans it somewhere else. You scan a tampered code, pay on the page it opens and see what that costs, then freeze the card and report the payments so they are reversed. Finally you go back over the warning signs that were there all along, open the address printed on the table card, and report the sticker so the next person is not caught.
What You'll Learn in Tampered QR Codes
- Explain why a printed QR code gives no sign of who placed it or where it leads until it is scanned.
- Read the address on the camera's result card and in the address bar, and compare it with the address printed beside the code.
- Recognize a lookalike payment page by its address, its missing padlock and its asking for card details before anything is ordered.
- Contain a card exposed to a scam page: freeze it with the issuer first, then report the payments, knowing a freeze reverses nothing on its own.
- Report a sticker over a QR code to the business so it can be removed before others scan it.
Tampered QR Codes — Training Steps
-
Another coffee
Alice has a table at Wrenloft Coffee and a deadline before lunch. Her cup is empty, the queue at the counter is long, and she does not want to lose her seat. A small card stands on her table, the kind every cafe has now: scan to order and pay at your table.
-
Scan to order
A code on the cafe's own table seems safe enough, and it saves her the queue. Alice picks up her phone and points the camera at it.
-
Open it
The camera reads the code and offers to open what it found. Alice glances at the result card, sees the cafe's name in the address, and taps through without reading the rest of it.
-
Pay at the table
The page wears Wrenloft's name, colours and cup logo, and it goes straight to a card form. Free Wi-Fi if she verifies the card, and her coffee brought over. Alice puts in the Ostmere card she uses for work and pays. The page thanks her, gives her a Wi-Fi code, and she goes back to her deadline.
-
Three payments she did not make
The coffee arrived and the Wi-Fi code worked. Nothing about the morning looked wrong until the card issuer wrote to her.
-
Open the card issuer
Alice goes to Pellmoor directly, by typing the address herself rather than following a link out of an email about card fraud.
-
Freeze the card
The three payments are sitting there on hold, and under them the £4.20 she really did spend. The card is still live, so the first move is to stop it spending anything more.
-
Report the payments
The card is frozen, but frozen is not the same as refunded. The three held payments still need Alice to say they are not hers before Pellmoor will reverse them.
-
What that saved
Pellmoor has what it needs. The money stays with Alice, and the details she typed into the page are worth nothing now. It cost her a frozen card, a replacement in the post, and a morning she will not get back. Catching it earlier would have cost nothing at all.
-
Whose code was it?
Security Framework Coverage
CWE
- CWE-451 User Interface (UI) Misrepresentation of Critical Information
MITRE ATT&CK
- T1204.001 User Execution: Malicious Link
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
- CIS 14.6 Train Workforce Members on Recognizing and Reporting Security Incidents
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind