Security & Forensics 6 min read August 20, 2026

QR Code Security (QRLJacking): How to Safely Scan and Generate QR Codes

Michael Ross

Michael Ross

Head of Security • 2FASafe Security Team

The Rise of Quishing (QR Phishing)

Quick Response (QR) codes encode structured alphanumeric data into two-dimensional pixel matrices. Because human eyes cannot read raw QR matrices, cybercriminals exploit this blindness through Quishing (QR phishing) and QRLJacking (Quick Response Login Hijacking).

How Attackers Exploit QR Codes

  • Physical Sticker Tampering: Placing malicious QR stickers over legitimate restaurant menus, parking meters, or retail payment portals.
  • Session Hijacking: Cloning login QR codes from services like WhatsApp Web onto phishing landing pages to hijack authenticated sessions.
  • Malicious URL Redirection: Encoding obfuscated redirection URLs that install malware or harvest credentials.

How 2FASafe’s QR Scanner Protects You

Our client-side QR Code Scanner decodes QR codes locally in your browser without automatically opening suspicious external URLs. It displays the raw decoded payload, allowing you to inspect domains, query parameters, or otpauth:// 2FA URI parameters before taking action.

Protect Your Accounts Today

Generate and test real-time 2FA codes with 100% client-side zero-knowledge security on 2FASafe.

Copied to clipboard!