Information for Businesses
WARNING FOR ALL BUSINESSES
An employee scanning a QR code can be as risky as them clicking a link in a phishing email.
With this increasing use of QR Codes, many people may assume that it is the appropriate technology for all identification applications. That is not correct. While QR Codes do have many strengths, such as data capacity and being able to be read by smart phones, they may also be a source of fraud. QR Codes are relatively easy to clone and adulterate. Even the inclusion of encryption to the QR symbol, that in itself does not protect against cloning or addition of fraudulent data. These issues have been described in several warnings published by the FBI. Bad actors are able to change QR Codes to send unsuspecting users to fraudulent sites with the intent to steal. Links to these FBI reports are included in this article.
While QR Codes may be appropriate for applications that require or invite consumer interaction, they certainly are not the best choice for applications that are mission critical, demand high levels of security and reliability, or are intended to detect counterfeiting and diversion in the manufacturing and distribution process. Over three hundred machine readable symbols have been created over the last 70 plus years, most of which have been authored in the last forty. Some of these, such as QR, Data Matrix, and most 1D codes are in the public domain. Some, however, remain proprietary, and often for good reason.
