The NCSC said QR codes were also increasingly being used in phishing emails to disguise links to malicious sites.
Microsoft said this was the fastest-growing scam technique aimed at people’s emails, with 18.7m cases recorded in March of this year.
This is because QR codes allow scam links to “slip through” on email, while a URL embedded in a message might be filtered out as spam, said Professor Filipo Sharevski of DePaul University in Chicago, who has studied the malicious use of QR codes.
The black and white squares also make it easier for criminals to hide the true website they are taking you to, he said, because even if your phone lets you preview the link before clicking, it is often shortened or disguised.
Another reason QR codes are so valuable to criminals is that people are often naturally trusting of them, Prof Sharevski said.
His team has carried out experiments placing QR codes around his university campus and in workplaces, to study people’s willingness to scan them.
“We don’t question our boarding pass on our phone, we don’t question our concert ticket,” he said.
“We learn slowly through scam experiences. Our phone rings… we abandon that.
“We get an email, and we abandon that…but these QR codes, we have no reason to suspect them.”
You can listen to Scam Secrets on Sounds.
