QR Code Security (QRLJacking): How to Safely Scan and Generate QR Codes
Michael Ross
Head of Security • 2FASafe Security Team
The Rise of Quishing (QR Phishing)
Quick Response (QR) codes encode structured alphanumeric data into two-dimensional pixel matrices. Because human eyes cannot read raw QR matrices, cybercriminals exploit this blindness through Quishing (QR phishing) and QRLJacking (Quick Response Login Hijacking).
How Attackers Exploit QR Codes
- Physical Sticker Tampering: Placing malicious QR stickers over legitimate restaurant menus, parking meters, or retail payment portals.
- Session Hijacking: Cloning login QR codes from services like WhatsApp Web onto phishing landing pages to hijack authenticated sessions.
- Malicious URL Redirection: Encoding obfuscated redirection URLs that install malware or harvest credentials.
How 2FASafe’s QR Scanner Protects You
Our client-side QR Code Scanner decodes QR codes locally in your browser without automatically opening suspicious external URLs. It displays the raw decoded payload, allowing you to inspect domains, query parameters, or otpauth:// 2FA URI parameters before taking action.
Protect Your Accounts Today
Generate and test real-time 2FA codes with 100% client-side zero-knowledge security on 2FASafe.