Know What the QR Code Connects
A code presented as “join this group” can actually link another device to your messaging account.
Illustrative scenario
How It Looks in Real Life
A message invites you to a private community group and asks you to scan a QR code from inside your messaging app. The scanner that opens is the “Link a device” screen.
Understand it
How the Attack Works
Messaging apps let you link a desktop or web session by scanning a QR code. Attackers disguise their linking code as a group invite. Once scanned, they can read and send messages as you.
Red flags
Warning Signs
- Being asked to scan a code from the “Linked devices” or “Link a device” screen.
- Invites that require scanning instead of tapping a normal invite link.
- Unknown entries in your linked devices list.
Safer habits
What to Do Instead
- 1Only scan linking codes displayed on your own computer.
- 2Check Linked devices regularly and log out anything you do not recognise.
- 3Join groups through standard invite links from people you know.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: approved app permissions or a sign-in request
- 1Report it straight away so IT can revoke the session or app consent.
- 2Remove the unfamiliar app from your account’s connected apps or permissions page.
- 3Changing your password does not remove app permissions or tokens already issued.
Knowledge Check
What Would You Do?
You are asked to scan a code to join a “verified investors” group, and your app opens the link-device camera. What should you do?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.