
August 27, 2026
Cybercriminals are increasingly using fraudulent QR codes to target connected vehicle service kiosks, according to an Auto World News report. The technique, commonly called "quishing," involves placing a malicious QR code over or near a legitimate code that customers expect to scan when using a kiosk. The attack can redirect users to fraudulent websites designed to collect login credentials, payment information or other sensitive data.
Automotive service environments may be particularly attractive targets because kiosks increasingly connect customers with vehicle information, service scheduling, payments and other digital services. Consumers accustomed to scanning QR codes at these machines may have little indication that a sticker or displayed code has been altered, allowing attackers to exploit the trust associated with a legitimate dealership or service provider.
The threat highlights the need for kiosk operators to treat physical QR codes as part of their cybersecurity strategy. Measures such as routinely inspecting machines for unauthorized stickers, using tamper-resistant labels, clearly identifying legitimate web addresses and educating customers about suspicious redirects can help reduce exposure. The issue also illustrates how attacks against self-service systems can begin with physical tampering before moving into the digital environment.