Abandoned QR code subdomains expose organisations to hijacking, researcher warns
Security researchers have identified that unused QR code subdomains can be commandeered, enabling attackers to redirect users and harvest data, a risk that Australian businesses and students must heed.
Written and published by the Wepro Technology team
A recent report by iTnews Australia highlights a growing security concern known as “QR jacking”, where abandoned subdomains linked to QR codes are taken over by malicious actors. The vulnerability stems from the way many organisations generate QR codes that point to temporary or one‑time URLs, leaving the underlying subdomains active even after the original content is removed.
The technique is straightforward: an attacker registers an unclaimed subdomain that was previously used in a QR code, then hosts malicious content or phishing pages at that address. When a user scans the original QR code, the request is silently redirected to the attacker’s site, exposing credentials, personal data or installing malware without the user’s knowledge.
Industry analysts warn that the problem is especially acute for companies that rely on QR codes for marketing, ticketing, or internal communications, as the codes are often printed on physical media that remains in circulation for months or years. In Australia, where QR codes are increasingly used in retail and government services, the potential for large‑scale exploitation is significant.
Experts recommend a series of mitigations, including regular audits of QR‑linked domains, the use of short‑lived URLs with automatic expiration, and implementing DNS monitoring to detect unauthorized subdomain registrations. Organisations are also urged to educate staff and customers about the risks of scanning unknown QR codes, especially in high‑traffic environments such as airports and shopping centres in Darwin and other cities.
For IT professionals and students seeking to deepen their understanding of such threats, pursuing security certifications such as CompTIA Security+ can provide valuable skills. Wepro Technology in Darwin offers Security+ courses that cover topics like vulnerability assessment and secure URL management, helping participants protect their organisations against emerging attacks like QR jacking.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime