QR codes have become a ubiquitous part of modern life, allowing smartphone users to quickly access websites, download apps, and make payments. However, cybercriminals are increasingly exploiting these convenient black-and-white squares to steal personal data. A new scam known as 'brushing' involves sending unsolicited parcels containing fake QR codes, tricking recipients into scanning them and exposing sensitive information.
Research from cybersecurity firm NordVPN suggests the problem is growing, with an estimated 26 million people potentially directed to malicious websites through fake QR codes. Marijus Briedis, chief technology officer at NordVPN, warned: 'QR codes have become a silent gateway for cybercriminals. Unlike traditional phishing emails, where people have learned to spot warning signs, a physical QR code often feels trustworthy.'
To protect yourself, experts advise following four key rules. First, always verify the source of a QR code and avoid scanning codes from unknown senders. Second, use your smartphone's preview feature to check the link before opening it. Third, keep security software up to date and consider using a VPN. Finally, share these tips with friends and family, especially those less familiar with technology.
QR codes, first invented in 1994 by Denso Wave in Japan, were originally used for tracking automotive parts. Their use expanded to marketing, payments, and tickets, and surged during the COVID-19 pandemic for contactless services. Despite their convenience, caution is essential to avoid falling victim to scams.



