Exploring Phishing Threats through QR Codes in Naturalistic Settings

Sharevski, Filipo; Mossano, Mattia ORCID iD icon 1; Veit, Maxime Fabian ORCID iD icon 1; Schiefer, Gunther ORCID iD icon 1; Volkamer, Melanie ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)


QR codes, designed for convenient access to links, have recently been appropriated as phishing attack vectors. As this type of phishing is relatively and many aspects of the threat in real conditions are unknown, we conducted a study in naturalistic settings (n=42) to explore how people behave around QR codes that might contain phishing links. We found that 28 (67%) of our participants opened the link embedded in the QR code without inspecting the URL for potential phishing cues. As a pretext, we used a poster that invited people to scan a QR code and contribute to a humanitarian aid. The choice of a pretext was persuasive enough that 22 (52%) of our participants indicated that it was the main reason why they scanned the QR code and accessed the embedded link in the first place. We used three link variants to test if people are able to spot a potential phishing threat associated with the poster’s QR code (every participant scanned only one variant). In the variants where the link appeared legitimate or it was obfuscated by a link shortening service, only two out of 26 participants (8%) abandoned the URL when they saw the preview in the QR code scanner app. ... mehr

DOI: 10.14722/usec.2024.23050
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2024
Sprache Englisch
Identifikator ISBN: 979-8-9894372-5-2
KITopen-ID: 1000169461
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Symposium on Usable Security and Privacy (USEC) 2024
Veranstaltung Symposium on Usable Security and Privacy. Co-located with NDSS Symposium (USEC 2024), San Diego, CA, USA, 26.02.2024 – 01.03.2024
Schlagwörter QR-Code
Nachgewiesen in OpenAlex
