Scammers Are Turning Data Breach Notices Into a New Kind of Trap


Scammers Are Turning Data Breach Notices Into a New Kind of Trap

 

If you've received an email or letter warning that your personal information was exposed in a data breach, look twice before you click anything — especially if it includes a QR code.

That's the warning from Steve Weisman, a Bentley University professor and founder of the scam-tracking site Scamicide.com, who says con artists are exploiting a growing sense of digital fatigue among consumers. With more than 3,300 data breaches reported across the United States last year alone, Weisman said most people have grown used to receiving official-looking notices telling them their data may have been compromised and offering credit monitoring or other remedies.

Scammers, he said, are cashing in on that familiarity.

"We're always getting these notices regarding data breaches and what we might be eligible for," Weisman explained. "So the scammers are taking advantage of it — they're now sending notices that appear to be from a company where a data breach hit."

The fraudulent messages are designed to mimic legitimate breach notifications almost perfectly, making them difficult to distinguish from the real thing. But Weisman pointed to one telltale sign that should raise immediate suspicion: the presence of a QR code within the letter or email.

According to Weisman, scammers favor QR codes because they can slip past security filters that are built to catch typical phishing attempts. Most email systems have screening software designed to flag malicious links or suspicious language, but that same software often can't "read" or analyze what's hidden inside a QR code image.

"One reason they'll use QR codes in these emails is a lot of emails will have screening software to pick up certain scams, but they can't pick up scams that are in QR codes," Weisman said.

Once a victim scans the code, they're typically directed to a convincing but fake web form — one designed to look like an official data breach claims page. These forms often request highly sensitive details, including Social Security numbers, under the guise of verifying identity or processing compensation.

Weisman warned that handing over that information can open the door to full-blown identity theft, giving criminals everything they need to open accounts, file fraudulent tax returns, or drain existing finances in a victim's name.

Consumers are urged to treat any breach notification containing a QR code with caution, avoid scanning unfamiliar codes, and instead verify a company's data breach claims directly through its official website or customer service line before submitting any personal information.