Korea Tourism Times
Arrival Basics · Japan

What Happens When You Scan That QR Code — 'Quishing' and Fake Wi-Fi Targeting Japanese Visitors

· Korea Tourism Times Editorial Desk
사진: 인천국제공항 제2여객터미널 내부 · 한국관광공사(공공누리)

You scan a QR code stuck to a restaurant table, and instead of a payment screen, an unfamiliar website opens. The Wi-Fi you thought connected you to the airport lounge turns out to be a fake signal with a nearly identical name. Both situations are newly reported scam tactics from travel destinations recently, and they are points that Japanese visitors to Korea in particular need to watch for.

At a glance: Names of the tactics quishing (QR code + phishing), fake Wi-Fi ("evil twin") · Responsible agencies Korea Internet & Security Agency (KISA), National Police Agency Cyber Investigation Bureau · Reporting and consultation KISA 118 Cyber Complaint Center · Prevention principles do not scan QR codes of unclear origin; do not enter financial information over public Wi-Fi

With the yen remaining weak, the number of Japanese travelers choosing Korea for being "close and cheap" keeps rising, compounded by expanded flight options such as new Narita-Incheon routes and newly launched Kobe-Incheon service. Many of these trips are short-haul visits of one night, two days, or at most two nights, three days, and travelers on such tight schedules often connect to an unfamiliar payment method or Wi-Fi signal without pausing to check whether it's genuine. Because scammers target short itineraries, language barriers and the excited mood of travel, extra caution is especially needed during this period.

Quishing involves scammers pasting a fake sticker over a restaurant or café's legitimate QR code payment sign, or sending a QR code by text message or email to induce a scan. In real cases confirmed by Interpol, scanning the QR code led to a fake website made to look almost identical to the real payment page, tricking victims into entering their card number or login information as-is. Checking whether there are traces of a sticker placed over the QR code on the table, and confirming that the site address before payment matches a familiar payment provider's domain, can prevent a significant share of such damage on its own.

Fake Wi-Fi involves creating a wireless signal with a name nearly identical to an airport or hotel's legitimate Wi-Fi network (for example, differing by just one letter or an added space) to lure people into connecting. Logging into a banking app or email while connected to such a network can leak that information directly. It's safer to confirm the exact official Wi-Fi name with facility staff before connecting, and to avoid accessing financial services while on public Wi-Fi.

There's no need to fear payment itself. Most restaurants and cafés operate QR code or card payments normally, and scams intrude only as a rare, altered variant among them. Still, if a payment screen feels different from usual, or a strange pop-up appears after connecting to Wi-Fi, disconnect immediately, and if you suspect you've been affected, contact KISA at 118 for consultation. One small habit of double-checking can protect the happy memories of your trip.

Source · how this was written — 한국관광타임즈 편집부 작성(근거: 한국인터넷진흥원(KISA)·인터폴)
Meet buddies in this city → ← Back to the edition