Skip to content
Notes by Axbom
Per Axbom Bluesky

I see people use QR codes in fundraising graphics.

Be advised that QR codes in graphics are easily replaced by bad actors, essentially giving them an opportunity to try and hijack some payments and funnel them to their own accounts.

(1/5)

The image shows two virtually identical campaign graphics asking for donations for World Kindness Day by scanning a QR code. The QR codes are different but it’s essentially impossible to see this.

The text above the graphics reads: If you have a campaign graphic with a QR code, a bad actor can easily edit your graphic to include their QR code instead. It’s virtually impossible to spot the difference.

Below the graphics is a web address: axbom.com/qr-hijacking

Imagine you are a campaign owner who has produced a graphic asking for donations, encouraging people to scan a QR code.

You see someone on social media posting your graphics and encouraging to donate to your efforts. It's likely full of praise for you and your mission.

(2/5)

Their praise makes you happy and proud, so you republish it and thank them.

Now what if I told you that person was not actually posting your graphic, but a manipulated one with their own QR code in place of yours.

(3/5)

So now you've repeated their version of the image to all of your own followers, essentially endorsing it and helping them in their deceptive efforts.

Recommendation: don’t use QR-codes in graphics. Use official, verifiable web addresses.

(4/5)

Here is my full article on how QR code hijacking can divert donations to criminals.

QR codes are immensely popular but also immensely open to fraud when they are used in public spaces and forums.

axbom.com/qr-hijacking/

(5/5)

QR code hijacking can divert donations to criminals

🔗 Originally posted on Bluesky

28 Sep 2024, 15:36
Share
LinkedIn Bluesky Email
  • Notes by Axbom
  • RSS

© 2026 Notes by Axbom