A security researcher has shown how attackers can take over companies' legitimately branded QR code web addresses by abusing a weakness in vendors' custom domain feature, sending anyone who scans a genuine code to a site of the attacker's choosing.
Farzan Karimi, who previously led red teams at Google and Electronic Arts, published the research this week under the label "QR Jacking".
"Every QR code pointed to a real corporate domain… but every destination was mine," Karimi said in a blog post.
Karimi demonstrated the flaw via popular code provider QR Tiger, using the company's "Own Short Domain" feature.
This lets businesses serve codes from a branded address such as qr.company.com, set up with a CNAME record, a domain name system (DNS) entry that points the subdomain at QR Tiger's servers.
However, Karimi said the platform only checked that the record existed, never who was claiming it.
That let any QR Tiger account holder claim a subdomain still pointing at the platform but no longer registered, typically because a company had stopped using the service without removing its DNS record.
"The entire takeover takes under a minute," Karimi said.
Karimi confirmed to iTnews that the flaw affects existing QR codes as well.
"Absolutely. If the QR code was generated for a campaign and the company doesn't clean up the DNS record after the campaign ends, every existing QR code printed for that campaign is at risk of compromise through this methodology," Karimi explained.
He said he had found hundreds of vulnerable companies across manufacturing, healthcare, financial services and technology, though Karimi did not publish a count or name any of them.
Karimi said QR Tiger had not fixed the flaw five months after he reported it to the company.
To mitigate the vulnerability, Karimi proposed a check most software-as-a-service (SaaS) platforms already use, namely a unique ownership token published in a TXT record.
Karimi said people who distrust email links rarely question a code on packaging or a conference stand, particularly when the phone shows the company's own domain.
Printed codes also can't be recalled with a software update.
Still, the attack has limits as each vulnerable subdomain exists only because a company left a stale DNS record in place, a basic hygiene failure on the customer's side.
"If the [DNS] record exists and nobody on your team owns that integration, remove it today," Karimi said.
The security researcher said he was disclosing similar findings for other QR vendors, and planned to release his scanning tool, QR Tiger King, on GitHub.
The QR Jacking technique is not be confused with QRLJacking, a similarly named attack published in 2016 by Egyptian researcher Mohamed Abdelbasset Elnouby and hosted as an OWASP project.
QRLJacking targets "log in with a QR code" features, such as WhatsApp Web, by showing victims an attacker's live login code so that scanning it hands over their session.

HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast
RIMPA Live Convention 2026
iTnews Benchmark Security Awards 2026
iTnews State of Security Breakfast Sydney



