Connect with us

Technology

FBI warns QR code phishing used in North Korean cyber spying

Published

on

FBI warns QR code phishing used in North Korean cyber spying

NEWYou can now listen to Fox News articles!

The Federal Bureau of Investigation has issued a warning about a growing cyber threat that turns everyday QR codes into spying tools.

According to the bureau, a North Korean government-sponsored hacking group is using a tactic known as quishing to target people in the United States. 

The goal is simple. Trick you into scanning a QR code that sends you to a malicious website. From there, attackers can steal login credentials, install malware or quietly collect device data.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

WHATSAPP WEB MALWARE SPREADS BANKING TROJAN AUTOMATICALLY

The FBI is warning Americans about a growing cyber threat that uses QR codes to steal data and spy on victims, tying the attacks to a North Korean hacking group. (Photo by Kevin Carter/Getty Images)

What quishing is and why it works

Quishing is short for QR code phishing. Instead of clicking a suspicious link in an email, the victim scans a QR code that hides the real destination. QR codes themselves are harmless. The danger lies in the link embedded inside them. Once scanned, the link can redirect users to fake login pages, malware downloads or tracking sites. Because QR codes feel familiar and fast, many people scan them without thinking twice. That split second of trust is exactly what attackers rely on.

Who is behind the attacks

The FBI says the activity is tied to a hacking group known as Kimsuky. The group has operated for years as a cyber espionage arm for North Korea. What is new is the delivery method. According to the FBI, the QR code-based attacks began in May 2025. In one example, attackers posed as a foreign policy advisor and emailed a think tank leader with a QR code that linked to a fake questionnaire. Scanning the code sent the victim to a malicious site designed to harvest information.

What happens after you scan the QR code

Once a victim lands on one of these sites, several things can happen. Some pages prompt users to download files that contain malware. Others mimic mobile login portals for popular services such as Okta, Microsoft 365 or VPN services. Even if no form is filled out, the site can still collect device details. That includes IP address, operating system, browser type and approximate location. Over time, that data helps attackers build intelligence profiles on their targets.

Advertisement

Why QR code phishing attacks are highly targeted

The FBI describes these campaigns as spear phishing rather than mass spam. That means the emails are crafted for specific individuals. The language context and sender details are tailored to look relevant and credible. When an email feels personal, people are more likely to trust it. That is why these attacks are especially dangerous for professionals, researchers, executives and anyone working in policy or technology.

Why QR code phishing threats are growing

QR codes are everywhere now. Restaurants, parking meters, event tickets and ads all rely on them. As their use grows, so does the opportunity for abuse. Attackers know people are conditioned to scan without hesitation. That makes caution more important than ever.

Ways to stay safe from QR code phishing

The FBI says one of the best defenses against quishing is slowing down. QR codes remove the visual clues people rely on, so a few extra checks can make a big difference.

1) Be cautious with unexpected QR codes

Treat QR codes like links in emails. If you did not expect it, do not scan it. QR codes sent by email, text or messaging apps are a common entry point for quishing attacks. Criminals rely on curiosity and urgency to push you into scanning without thinking.

2) Verify the source before scanning

Always confirm who sent the QR code. If a message claims to come from a coworker, vendor or organization, reach out through a separate channel before scanning. A quick call or direct message can stop a phishing attempt cold.

Advertisement

JANUARY SCAMS SURGE: WHY FRAUD SPIKES AT THE START OF THE YEAR

Federal investigators say hackers are using “quishing,” or QR code phishing, to lure victims to malicious websites that steal credentials and device data. (Jens Schlueter/Getty Images)

3) Never enter logins after scanning a QR code

QR code phishing often leads to fake mobile login pages. Attackers mimic sign-in screens for email, VPNs and cloud services to steal usernames and passwords. If a QR code takes you to a login page, close it and visit the site manually instead.

4) Inspect the website URL carefully

Once a QR code opens a page, check the address bar. Look for misspellings, extra words or unfamiliar domain endings. A strange URL is often the only warning sign that the site is malicious.

5) Use strong antivirus software for QR-based threats

Strong antivirus software adds an extra layer of protection against quishing. Security tools can block known phishing sites, stop malicious downloads and warn you before harmful pages load. This is especially important on mobile devices, where QR codes are most often scanned.

Advertisement

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

6) Use a data removal service to limit exposure

Some quishing sites collect device and location data even if you do nothing. A data removal service helps reduce how much personal information is publicly available online. That makes it harder for attackers to target you with convincing spear phishing emails that include QR codes.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Advertisement

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

7) Avoid QR code downloads entirely

Do not download files from QR code links unless you are absolutely certain they are safe. Malware delivered through QR codes can quietly install spyware or remote access tools without obvious warning signs.

INSTAGRAM PASSWORD RESET SURGE: PROTECT YOUR ACCOUNT

A North Korea-linked cyber group is targeting U.S. professionals by embedding harmful links inside seemingly harmless QR codes, according to the FBI. (Jaap Arriens/NurPhoto via Getty Images)

Kurt’s key takeaways

QR codes are convenient, but convenience can lower defenses. As this FBI warning shows, attackers are evolving and using familiar tools in dangerous ways. A moment of verification can prevent weeks or months of damage.

Advertisement

When was the last time you stopped to question a QR code before scanning it? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com.  All rights reserved.

Advertisement
Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Valve is so behind on Steam Controller orders that some won’t ship until 2027

Published

on

Valve is so behind on Steam Controller orders that some won’t ship until 2027

Valve has some good news and bad news about Steam Controllers. The good news: if you make a reservation for a Steam Controller, the company will now show you one of three estimates of when you’ll be able to actually order your gamepad: by September 2026, by December 2026, or sometime in 2027. The bad news: any reservations made today “indicate a 2027 date for shipping,” Valve says.

“We have no plans to stop making Steam Controller,” according to Valve. “But as we look at the current demand compared to how many we know we can make by the end of the year, we want to manage expectations as much as we can with regards to when folks can expect to receive their order.”

Valve’s very good new Steam Controller went on sale in early May, and the initial rush led some people to run into frustrating problems with trying to check out ahead of the controllers eventually going out of stock. A few days later, the company announced that it would be implementing a reservations queue for interested buyers so they could get on a waitlist. If you’re on the waitlist, when you get notified that a Steam Controller is ready for you to buy, you have 72 hours to actually make the order.

“When we launched Steam Controller last month, we quickly saw that initial demand exceeded our expectations,” Valve says. “Switching to a reservation queue has (hopefully) cut down on the headaches on the customer side, and for us it’s also been helpful as we plan ahead and try to get as many out as quickly as we are able.”

All three of Valve’s big hardware products were delayed from a planned early 2026 launch because of the component crisis, Valve still hasn’t announced when the Steam Machine PC or Steam Frame VR headset might go on sale. However, just yesterday, Valve officially launched its big SteamOS 3.8 update with support for the Steam Machine. It’s also been importing a lot of hardware into the US as of late.

Advertisement
Continue Reading

Technology

McDonald’s AI drive-thru may take your next order

Published

on

McDonald’s AI drive-thru may take your next order

NEWYou can now listen to Fox News articles!

The next time you pull up to a McDonald’s drive-thru, the voice taking your order may not be human. McDonald’s is testing a new AI-powered system called ArchIQ at five U.S. locations. The company has not said where those restaurants are located. The voice assistant, nicknamed Archy, can take drive-thru orders and has shown it can handle both English and Spanish.

For anyone who has repeated “no pickles” into a speaker box more than once, this could sound helpful. However, if you remember McDonald’s last AI drive-thru experiment, you may also wonder whether your burger order could somehow turn into a bag full of surprise McNuggets.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.

Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

WOULD YOU EAT AT A RESTAURANT RUN BY AI? 

Advertisement

McDonald’s is testing an AI drive-thru system called ArchIQ at five U.S. restaurants. (Kurt “CyberGuy” Knutsson)

 

What is McDonald’s AI drive-thru?

ArchIQ is McDonald’s new AI system for restaurants. It can take drive-thru orders and also help with operations behind the scenes.

In a post on X, McFranchisee, an anonymous McDonald’s franchisee account, said the system is currently in five test stores and has processed more than one million transactions. The account also said about 90% of orders were completed without a human stepping in. That number sounds promising. Still, McDonald’s has not confirmed a nationwide launch date. For now, this remains a limited test.

The system also appears to connect with a bigger McDonald’s plan called “McDonald’s > NEXT.” CEO Chris Kempczinski described the strategy as a way to bring in more customers and improve restaurant productivity. The plan also includes menu changes, restaurant redesigns, technology upgrades and more focus on hospitality.

 

Why McDonald’s is testing AI ordering

Drive-thrus can get chaotic fast. Someone changes an order after the total appears. A child calls out from the back seat. Road noise makes the speaker hard to hear. Then the driver remembers the extra sauce after everything has already gone through. That is the type of pressure McDonald’s wants AI to handle.

Advertisement

If ArchIQ works well, it could help restaurants move cars through the line faster. It may also reduce mistakes during busy hours. Workers could then focus more on preparing food, handling payments and helping customers who need a real person.

ArchIQ also appears to have a management role. In the same X post, McFranchisee described Archy as a tool that could alert managers to bottlenecks or other issues before they slow down operations. 

STARBUCKS USES CHATGPT TO SUGGEST DRINKS BASED ON MOOD AS EXPERT WARNS OF HIDDEN DOWNSIDES

The AI assistant, nicknamed Archy, can take drive-thru orders and may also help managers spot restaurant slowdowns. (McFranchisee)

 

McDonald’s tried AI drive-thru ordering before

This new test follows McDonald’s earlier AI drive-thru experiment with IBM. That program involved more than 100 restaurants. McDonald’s ended the test in 2024 after customers complained about order accuracy. Some mistakes also went viral, creating an embarrassing moment for McDonald’s and raising questions about whether the technology was ready for the drive-thru. Customers reported wrong items, strange quantities and other order mix-ups. That history is why this new test will get extra attention.

Advertisement

This time, McDonald’s is working with Google technology. McFranchisee also claimed every McDonald’s in the U.S. is getting Google Edge Cloud hardware in anticipation of the rollout. McDonald’s seems to believe the newer system can perform better than the last one. The real test will come when regular customers use it during real drive-thru rushes.

 

How McDonald’s AI drive-thru could help customers

If McDonald’s gets this right, the most obvious benefit is speed. An AI ordering system does not get tired during a long shift. It may also help more customers order in the language they prefer. That could make a busy drive-thru feel less frustrating, especially during breakfast or late-night hours.

The system may also ask clearer follow-up questions and catch missing details before the order reaches the kitchen. That would be a win for customers who want to get in, get their food and get on with the day.

 

The biggest problem with AI drive-thru orders

The biggest concern is accuracy. AI can still misunderstand people. That gets frustrating fast when you are trying to grab lunch between errands or get your kids fed from the back seat. A wrong order wastes time. It also puts workers in the position of fixing a mistake the machine made.

There is also the customer service side. Some people like hearing a real person at the speaker. Others may find an AI voice cold or annoying, especially if the system gets confused.

Advertisement

Then there is the privacy question. If an AI system takes your order, customers may wonder what gets collected, how long it is kept and who can access it. McDonald’s has not publicly explained those specifics for this current ArchIQ test.

ALEXA+ LETS YOU ORDER FOOD LIKE A REAL CONVERSATION

A drive-thru menu board stands outside a McDonald’s restaurant in Hercules, Calif., on Oct. 23, 2024, amid an E. coli outbreak linked to onions in Quarter Pounder sandwiches that has sickened dozens and killed one person across the U.S. (David Paul Morris/Bloomberg via Getty Images)

 

How to avoid AI drive-thru mistakes

Before you leave the drive-thru, take a moment to check the order screen. Make sure the items match what you said. Listen when the system repeats your order. Keep your receipt until you confirm the food is right.

Also, avoid sharing extra personal details at the speaker box. Your order should only require your food choices and payment.

Advertisement

If the AI gets confused, ask for a crew member. You do not need to keep going back and forth with a machine over fries.

 

What this means for you

For now, you probably will not notice a change at your local McDonald’s. The ArchIQ test appears limited to five U.S. restaurants, and the company has not said when it could expand.

Still, this gives customers a preview of where fast food may be heading. AI could soon play a bigger role in how restaurants take orders and manage the kitchen. That may speed up the line, though it could also make the experience feel less personal.

 

Watch the CyberGuy Live replay: Lock Down Your Phone in 30 Minutes

Your phone holds your email, passwords, photos, banking apps and personal data. In this free CyberGuy Live replay, Kurt the CyberGuy walks you step by step through simple phone security fixes you can do at your own pace. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Watch the replay and get our checklist here: CyberGuyLive.com

 

Kurt’s key takeaways

McDonald’s clearly wants AI to play a bigger role in its restaurants. From a business point of view, the idea makes sense. Shorter drive-thru lines could help franchisees and customers. Better restaurant data could also help managers fix problems faster. But I still want the human backup. Food orders can be messy because people are messy. We change our minds. We talk over each other. We forget the extra ketchup until the last second. AI may handle much of that one day. For now, I would treat it like any busy drive-thru interaction. Speak clearly. Check the order. Do not pull away until you know your food is right.

Advertisement

Would you trust an AI voice to take your McDonald’s order, or do you still want a real person on the other end of the speaker? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Midjourney goes from generating cat images to full-body ultrasound scans

Published

on

Midjourney goes from generating cat images to full-body ultrasound scans

Midjourney CEO David Holz just showed off the company’s first hardware product and plans to build a San Francisco spa, which he admitted is a bit different from the “cat pictures” produced by its AI image generator. Dubbed The Midjourney Scanner, it’s an ultrasound-based full-body scanner that uses a ring of sensors to capture vertical slices of the inside of your body, looking at the composition of your muscle, fat, bone, and organs to start. Holz said ideally, you could do this once a year or every single day, as it “aims for image quality comparable to MRI in many ways.”

He mentioned that one way he’d like to use it would be to see how his body changes in response to diet and workout changes, saying, “I’m not the most measured man on Earth yet, you know, but maybe I want to have that daily [measurable information].” A set of job listings advertises the company’s goal as trying to “build and launch the world’s first full-body ultrasound CT scanner, ultimately bringing safe, fast, and high fidelity preventative scanning to billions via a magical spa experience.”

The Midjourney Scanner was developed in a partnership with ultrasound tech company Butterfly Network, which said it uses “40 Butterfly Ultrasound-on-Chip imaging modules per system.”

The scanning process starts with stepping onto a platform that drops down into the water on rails through a ring of thousands of transducers that create ultrasonic waves. It then records the ripples passing through your body to analyze them and create detailed 3D images. The scan takes about 60 seconds. Holz said about a dozen people have been scanned so far.

It starts by stepping into a shallow pool of golden light. You then begin to descend into the water. Your body passes through a ring of underwater sensors, each acting like a dolphin, using its echolocation. The sensors send ultrasonic sound waves through your body from every angle. With enough waves, and enough angles, we form an image of what’s happening inside your body.

It combines those sensors with two petaflops of processing power. But after watching the livestreamed reveal, I’m still unclear on what Midjourney’s AI image generation tech exactly has to do with the Midjourney Medical effort, beyond an alternative business for otherwise-unused AI compute.

Advertisement

Holz hopes to put 10 of the scanners into a Midjourney Spa location in San Francisco’s Union Square that will open before the end of 2027 and offered to scan the hands of attendees at its launch event. The Midjourney Spa will have a gym, saunas, and cold plunges to go along with the hot tub–equipped scanning rooms where visitors will get into the water to be scanned.

He did mention that various medical applications would require FDA clearances, but for now, Midjourney Medical says it’s working on “body composition maps” that don’t require the same level of clearance as diagnostic imaging. It also says the “library of scans” users create can be shared with doctors, AI health tools, or others, and that, “We take data privacy seriously — more details on our data policies will come as we get closer to launch.”

Holz suggested that eventually these scans could become better than an MRI, without radiation, powerful magnets, or other complicating factors, to get a look at what’s going on inside people’s bodies “real fast.” In response to a question, he imagined a future where the FDA had a class of devices to look at “weird” things and allowed people to “just try to get as much data as we can.”

Continue Reading
Advertisement

Trending