Is a free Wi-Fi QR code at a hotel or airport safe to scan?
Public Wi-Fi QR codes can be cloned or faked by attackers to intercept your traffic. Verify with staff and use a VPN on any public network.
Last reviewed: 1 August 2026
Explanation
Fake Wi-Fi access point attacks using QR codes work as follows: an attacker creates a hotspot with a name similar to the venue's genuine network and posts a QR code sticker nearby, sometimes covering the real one. When you connect via the fake QR code, all your unencrypted internet traffic passes through the attacker's device. Modern HTTPS encryption protects most browsing, but credential harvesting pages that intercept app traffic or inject content into HTTP connections remain risks.
The more common danger in practice is the fake captive portal — the login page that appears when you join. An attacker's portal can imitate the venue's branding and ask for far more than a real one would: an email address is normal, but a password, payment card 'for verification', or a prompt to install an app or certificate is not. Anything typed into that page goes straight to the attacker, and travellers in a hurry at an airport gate are the ideal audience for it.
When connecting to hotel or airport Wi-Fi, verify the exact network name with reception or the venue's official signage rather than trusting a sticker, use a reputable VPN to encrypt your traffic, and avoid logging into banking or other sensitive accounts on public networks — mobile data is the safer route for those. If a portal asks for a password or payment, disconnect and check with staff before going further.
Common red flags
- QR code sticker is placed on a piece of paper rather than embedded in official signage
- Network name after scanning is slightly different from the venue's listed network
- You are asked to log in to a portal requesting email and full name but also a password
What to do now
- Ask staff to confirm the official network name and password before connecting
- Use a reputable VPN when on any public Wi-Fi network
- Avoid logging into banking or sensitive accounts on public networks
- Report suspicious Wi-Fi stickers to venue staff
Frequently asked questions
Is HTTPS enough to protect me on public Wi-Fi?
HTTPS protects the content of most communications, but a malicious hotspot can still intercept metadata, target apps that do not use full encryption, or serve you fake pages. A VPN adds an important additional layer.
What should a legitimate Wi-Fi login portal ask for?
At most an email address, room number, or acceptance of terms. A portal requesting an account password, payment card details, or the installation of an app or certificate is a strong sign of a fake network — disconnect and verify with staff.
Is mobile data safer than public Wi-Fi for banking?
Yes. Your carrier connection is not interceptable by someone running a rogue hotspot in the room. For banking and other sensitive logins while travelling, switching to mobile data removes this entire class of attack.