All News
26 September 2026IT News

Abandoned QR Code Subdomains Pose Hijacking Risk, Researcher Warns

Security researchers have identified that unused QR code subdomains can be hijacked, a technique dubbed "QR jacking," highlighting a simple yet effective threat to trusted digital ecosystems.

Written and published by the Wepro Technology team

A recent report by iTnews Australia cites a security researcher who has discovered that abandoned subdomains linked to QR codes can be taken over by malicious actors, a vulnerability now being referred to as "QR jacking."

QR jacking works by registering an unused subdomain that was previously associated with a QR code; when a user scans the code, the request is redirected to the attacker‑controlled site, allowing the delivery of phishing pages, malware or data‑exfiltration without the user suspecting foul play.

The threat is particularly relevant for Australian organisations that rely on QR codes for contactless payments, event ticketing, government services and retail promotions, where users expect the code to lead to a trusted domain.

Experts advise companies to regularly audit their DNS records, retire unused subdomains, implement short‑lived URLs and employ domain‑based authentication mechanisms to prevent hijacking.

Understanding such emerging threats is a core component of the CompTIA Security+ curriculum offered by Wepro Technology in Darwin, helping IT professionals and students build the skills needed to protect Australian networks.

Source
iTnews AustraliaView original
Newsletter

Stay ahead in IT

Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.

  • Weekly IT news & insights
  • New course announcements
  • Free quiz updates

Your email

No spam, ever · Unsubscribe anytime