Scammers exploit QR codes in medical settings to harvest personal data
Criminals are using counterfeit QR codes in doctors' offices, pharmacies and hospital parking areas to direct victims to fake sites that collect sensitive health and financial information.
Scammers are leveraging the routine presence of QR codes in healthcare environments to launch phishing attacks, often called "quishing." By sending fake Medicare or prescription texts and mailing letters that contain authentic-looking personal details, they persuade victims to scan malicious QR codes placed over genuine ones or on parking meters. The resulting sites mimic insurers, pharmacies, or payment processors and solicit a range of personal data, from Medicare numbers to credit-card information.
Examples include a counterfeit Medicare notice that redirected users to a look-alike URL and a hospital parking machine in the United Kingdom where a fraudulent sticker was discovered. Experts advise checking QR code destinations, confirming codes with staff, looking for signs of tampering, and reducing publicly available personal data through broker removal requests. Reporting suspicious codes to staff or the FTC can help stop further exploitation.
Why it matters
QR code scams can steal health and financial data, putting patients at risk of identity theft and fraud.
In this story
