QRjacking is a phishing technique that allows attackers to access your account by abusing QR-based login functionality.
If you’re looking to protect yourself or learn about the security risks QR codes pose, you’re in the right place. I’ll explain everything you need to know, including how QRjacking works and how to prevent it entirely.
QRjacking: What it is and how to protect yourself
QRlacking is short for Quick Response Code Login Jacking. The goal is to trick victims into authorizing an attacker’s session, granting them full account access. Scammers often combine this attack with phishing and social engineering tactics, meaning victims may not realize there’s a problem until much later.
To demonstrate how QRjacking works, let’s imagine a hacker is trying to break into your WhatsApp account. They begin by opening WhatsApp on their device and getting a login QR code. This code is then sent to the victim, often accompanied by a message that there’s a problem and they have to log in to resolve it. When the victim logs in via the attacker’s QR code, the attacker’s session is authorized, granting them complete access to the victim’s account.
Here are a few simple yet effective tips on staying safe and preventing QRjacking attacks:
- Be wary of QR codes. You can’t easily tell where the code will send you (or if it’ll download something harmful). Never scan a code that was sent unsolicited. In fact, the Open Worldwide Application Security Project (OWASP) suggests avoiding QR-based logins entirely.
- Learn to identify signs of phishing. Being aware of popular scams can help you realize when something suspicious is happening, and could prevent an account breach.
- Use a QR code scanner with a preview feature. This shows the URL that the QR code wants to send you to. Verify it’s pointing to the correct website and that there are no typos or misspellings (e.g. “WhatsAp” instead of “WhatsApp”).
- Try not to use vulnerable services. QRjacking only works if you’re using a service that logs you in immediately, with no additional verification required.
- Log in manually if possible. If you’ve received an email saying you urgently have to log into something, open the website or app yourself. There’s no reason to trust any links or QR codes in an email, even if they look official.
How does QRjacking work?
QRjacking is a form of QR code-based phishing (sometimes called “quishing”). It was first documented in 2016 by security researcher Mohamed Elnouby. If an app lets you scan a QR code to login with no further authentication required, it’s vulnerable to QRjacking. That’s a significant issue, since this attack vector sidesteps multi-factor authentication, one of the strongest protections against unauthorized account access.
In theory, this attack is quite straightforward. If the target logs into a service like WhatsApp or Signal using a QR code provided by the hacker, their account is immediately compromised.
The good news is that services with QR-based login systems typically refresh the QR code every few minutes. This means that attackers either have to create whole phishing websites that continuously update to display the latest unexpired QR code, or else get victims to scan the code within a few minutes of it being generated. Both workarounds increase the time and effort required to successfully scam someone, making Qrljacking a less appealing tactic.
How big of a threat is QRjacking?
There is a lack of research available on the prevalence of Qrljacking attacks. However, Microsoft noted a 146 percent increase in quishing during Q1 2026, with 18.6 million incidents in March alone. If even one percent were Qrljacking-related, that’s still 186,000 incidents, so it’s worth taking steps to protect yourself.
On the plus side, this exploit has been public knowledge for over a decade. Even then, it affected only a few well-known platforms, such as WhatsApp, AliPay, WeChat, Weibo, and Yandex Passport. Most of these now require additional verification when you use a QR code to sign in. As such, learning to use QR codes safely or avoiding them entirely should virtually eliminate any chance of QRLJacking.
Why are QR codes such a significant security problem?
Many websites and apps let you sign in using a QR code. It’s convenient since you only have to enter your login details once, and then you can scan a code to quickly sign into other devices. It’s far faster than, for instance, typing a complex password with a Smart TV’s built-in keyboard. Unfortunately, there’s no easy way to tell what data a QR code contains without scanning it.
This means QR codes are a fantastically useful tool for hackers, allowing them to send malicious links, download files, open specific apps, or even change your wifi network. To make matters worse, shady QR codes aren’t readily caught by most automated filters. In fact, most spam filters can’t tell if a QR code is present in an image, never mind verify it’s safe. That alone is extremely concerning since Cisco estimates 60 percent of all messages containing a QR code are spam.
What should I do if I’ve scanned a malicious QR code?
This really depends on the situation, but the most important thing is not to panic. If you’ve been a victim of QRLJacking, follow these steps in order to limit the damage:
- Forcibly end all other sessions and log out everywhere. This will kick the attacker out, meaning they can’t regain access without tricking you again.
- Verify what data the attacker was able to view, then change your password. If your phone number or email address was visible, you’ll likely receive additional scam messages in the coming days.
- Let your contacts know. Scammers often impersonate victims and reach out to their friends and family to ask for money.
- Tell your bank if you suspect any payment information was visible. They’ll be able to monitor your account for unusual activity, potentially saving you from losing anything.
- Report the initial message that included the QR code as phishing. This may prevent others from being victimized by the same scammer.
Conclusion
QR codes simplify the process of logging in across multiple devices. However, if you’re not careful, you could be helping a cybercriminal gain access to your accounts. Thankfully, due to this vulnerability’s age and the limited number of platforms affected, it’s unlikely you’ll experience a QRLJacking attack. Still, we have guides explaining how to spot scam emails and what to do if you’ve fallen for a phishing link, so you’re as prepared as can be.