QR codes for Wi-Fi genuinely help. Visitors scan, their phone joins, and no long password needs typing. Creating one is covered in the guide to making a Wi-Fi QR code.

But one property sets it apart from every other method: its contents can't be read by eye.

A network name written on a board can be read and checked. A QR code can't. You only learn where it takes you after your phone has gone there.

How the scam works

The method is simple, and that's precisely why it succeeds: one sticker placed over the real one. Nothing needs hacking.

From there, two directions are common.

Directing to a fake network

A Wi-Fi QR code contains a network name and password. A fake one can name a different network, belonging to a device left nearby, with a similar-looking name.

Once joined, all the visitor's traffic passes through that device. This is the same attack covered in the guide to fake Wi-Fi and evil twins, only with a far more convincing invitation: an official-looking sticker on the table earns much more trust than a name appearing in a list.

Directing to an imitation page

A QR code can equally contain an ordinary web address. What opens resembles a Wi-Fi login page, asking for a phone number, an email, sometimes an account password.

This is the more common variant, because it requires no equipment at all. Just a sticker. And because Wi-Fi login pages routinely do ask for details, see the guide to captive portals, the request doesn't feel odd.

Spotting it before scanning

The code itself can't be judged by eye. The sticker can.

  • Placed over something. Look at the edges, a sticker on a sticker usually leaves a thick shadow or a lifted corner.
  • Different material from the venue's other printing. A cafĂ© with neatly printed menus rarely tapes a QR code onto plain paper.
  • Sitting crooked or out of line with the printing around it.
  • In an unusual place: on a toilet door, a car park post, on one table but not the others.
  • No network name written beside it. The most important sign, and covered again below.

When in doubt, the simplest approach still works: ask a member of staff. One question removes all uncertainty, and no venue objects to being asked its own Wi-Fi name.

What to watch after scanning

Most phones show the destination before doing anything. Read it, and stop in these three situations:

  • The network name doesn't match what's written at the venue. Watch for similar characters, zero and capital O, capital i and lowercase L.
  • A page opens instead of an offer to join. A genuine Wi-Fi QR offers to join a network; it doesn't open a browser.
  • The page asks for an account password, a card number, or an SMS code. No reasonable Wi-Fi login page needs any of those.

That last is the clearest line. There's no legitimate reason for a Wi-Fi page to want your email or social media password, whatever the page claims.

If you've already done it

  1. Disconnect, then forget the network so your phone doesn't rejoin it later.
  2. Enter nothing into whatever page has opened.
  3. If you've already entered an account password, change it immediately, from a different network, not the same one. The reasoning matches the guide to recovering after a Wi-Fi breach: a new password sent over a compromised path is read along with the old one.
  4. Tell the venue. That sticker is still there for the next visitor.

Worth some reassurance: most traffic today is encrypted, so its contents stay unreadable even on someone else's network. What's at risk is what you type into a fake page, not what merely passes through. Further protection is covered in the guide to using public Wi-Fi safely and the guide to mobile banking on Wi-Fi.

For venue owners

The loss isn't directly yours, but this happens on your premises, under your name, and visitors will remember it that way.

Four steps worth taking:

  • Print on something hard to cover. A standing acrylic holder, laminate, or printed directly on the menu. A paper sticker on a table is the easiest thing to paste over.
  • Write the network name in readable text beside the code. This is the single most helpful step: visitors can match what appears on their phone against what's written, without having to trust the code.
  • Check periodically. Once a week is plenty, and takes less than a minute.
  • Don't ask for details you don't need on the login page. An official page asking for a lot trains visitors to treat such requests as normal, which is exactly what makes fakes work. The limits are covered in the guide to customer data collection rules.

If your QR points to a login page, make sure the address uses your own domain and stays the same over time. An address that keeps changing leaves visitors nothing to check against.

What makes a QR code useful, that its contents needn't be read, is also what makes it forgeable. Nothing needs hacking; one sticker over another is enough.

For visitors, two habits close nearly all of it: look at the sticker before scanning, and read the network name before accepting. A Wi-Fi page asking for an account password is a clear line, at that point, stop.

For venue owners, one step helps more than the rest: write the network name in readable text beside the code. It gives visitors something they can check for themselves.

Frequently asked questions

Is scanning a Wi-Fi QR code dangerous?

The scan itself isn't. The risk is what follows, joining a network that isn't the venue's, or opening a page imitating a login screen. The danger lies in the destination, not the scan.

How can I tell a QR code has been covered over?

Look at the sticker, not the code. A sticker over another sticker, a lifted corner, material that doesn't match the venue's other printing, or a slight tilt, all worth suspecting. The code itself can't be told apart by eye.

What if I've already scanned a fake one?

Disconnect, forget the network, and enter nothing into whatever page appeared. If you've already entered an account password, change it from a different network, not from the same one.

How can venue owners protect visitors?

Print on something hard to cover, laminate, acrylic, or directly on the menu, and check periodically. Also write the network name in readable text beside the code, so visitors can verify without having to trust the code.