Empowering Shared Mobility Vehicle Riders, Stopping Scams: A Cyber Kill Chain and Awareness Approach to QRishing on College Campuses
Frank Offei Gyimah, Ernest Ofori-Mensah, Henrietta Boowuo, Sakhi Aggrawal · 2024
QRishing, a phishing technique utilizing QR codes, presents a burgeoning threat in the digital age. This research explores the susceptibility of shared micromobility vehicles on US college campuses to QRishing attacks. The study uses a large Midwestern university as a case study to analyze how e-bikes/e-scooters can be exploited by malicious QR code placement. The study investigates common QRishing tactics and their potential impact on college students, staff and communities. It discusses the technical aspects of a simulated QRishing attack, highlighting the involvement of Artificial Intelligence (AI). Furthermore, the paper proposes countermeasures for e-bike rental programs and best practices for students to avoid falling victim. Emphasizing the importance of collaboration between universities, rental companies, and law enforcement, the paper aims to mitigate QRishing risks and safeguard the college community. The findings underscore the need for comprehensive cybersecurity awareness programs, secure QR code generation, and enhanced app security to protect users from evolving cyber threats.