Skip to content
QR Code Hijacking Vulnerability Exposes Users to Phishing Attacks

QR Code Hijacking Vulnerability Exposes Users to Phishing Attacks

First seen 28 Sep 2026, 23:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 23:08 UTC
  • •QR Jacking allows hijacking of abandoned QR code domains.
  • •Hundreds of vulnerable subdomains identified across multiple sectors.
  • •Organizations must review DNS records to mitigate risks.

A security vulnerability in QR Tiger's custom domain feature, termed 'QR Jacking', allows attackers to hijack abandoned branded QR code domains. This flaw enables malicious actors to redirect users scanning legitimate QR codes to phishing sites while displaying the authentic company domain. Security researcher Farzan Karimi discovered that QR Tiger's 'Own Short Domain' feature lacks adequate verification of domain ownership, allowing attackers to claim subdomains of businesses that have stopped using the service. Karimi identified hundreds of exposed subdomains across sectors like manufacturing, healthcare, and finance. Despite reporting the issue to QR Tiger, no remediation has been implemented. Organizations are advised to review their DNS records and remove unused integrations. Users should verify the destination URL after scanning QR codes before entering sensitive information.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
QR Jacking vulnerability disclosed
Farzan Karimi revealed the QR Tiger vulnerability that allows domain hijacking, affecting various sectors.
Cyberinsider
2026-09-28
Security advisory published
Organizations are urged to review their DNS records and remove unused QR code integrations to prevent exploitation.
Scworld

More articles in this cluster (2)