The risks of QR codes in photos describe what anyone looking at an image with a clearly visible code can read. The consequences describe what happens to people: a return flight that suddenly shows as cancelled, a message that knows a little too much and asks for a payment, a colleague who receives an odd request in your name, a travel day spent on the phone to customer service.
The boarding pass is the clearest example. The square at the bottom — a two-dimensional barcode, a pattern of dots that a reader turns back into text, very often an actual QR code — is not decoration: it holds, in readable form, the passenger’s name, the booking reference, the flight and sometimes the frequent flyer number. And the booking reference is almost always printed in plain text too, a few centimetres away. This post tries to describe what can happen after a photo shared without a second thought, honestly, without dramatising and without downplaying.
It expands on the recommendation to avoid posting photos with QR codes on social media.
A realistic scenario
Helen runs a small business and, twice a year, flies to an industry trade fair. At the terminal café she takes a photo of her phone resting on the table, with the boarding pass open on the screen next to her cup, and posts it with a simple caption: “And we’re off!”. Her profile is public, because she also uses it for the business. In the photo you can read her name, the flight, the date and the booking reference; the two-dimensional code is perfectly sharp.
On the same booking, which she made herself, is Paul, the colleague travelling with her to the fair.
Two days later, on the eve of the return flight, Helen receives a confirmation email for a change she never made: the contact address on the booking has been changed. Someone, starting from the photo, has got into the booking management page, where many airlines ask for nothing more than the surname and the booking reference.
From this point on, the consequences spread across five planes.
1. Operational consequences: when the trip is no longer under your control
A practical example
Helen tries to open the booking to check in for the return flight, but the system flags it as modified. Her seat has been changed and notifications are going to an address that is not hers. She spends the morning of the fair on the phone to the airline’s customer service instead of on her stand.
Possible effects
- check-in blocked, or to be done again at the desk, with queues and waiting;
- seats, extras or contact details changed without authorisation;
- in the worst cases, the return flight cancelled or changed;
- hours taken away from the reason for the trip: meetings, work, rest;
- the need to prove that you are the holder of the booking, far from home.
Why it matters
People who post a boarding pass think they are sharing a moment. In reality, for a while, they are also sharing a key: until the trip is over — and sometimes even afterwards — that booking can still be changed by anyone who has the right details. And a problem at the gate, in another city, weighs far more than one you can sort out calmly at home.
2. Financial consequences: when the damage becomes a number
A practical example
Helen’s and Paul’s return flight shows as cancelled: to get home on time they need two new tickets, bought at the last minute. Meanwhile, the points collected in her frequent flyer programme have been spent on a flight she never booked. Then a message arrives, well written and with every detail right, asking her to pay an “excess baggage fee” through a link.
Possible effects
- tickets to buy again at last-minute prices;
- frequent flyer points or credits taken;
- payment card details entered on a fake page, prompted by a convincing message;
- indirect costs: extra nights, transport, lost working days;
- refunds that are possible but not automatic, with timescales and outcomes that depend on the airline.
Why it matters
The fake message is the most delicate point. Someone who knows the flight, the date, the name and the booking reference can write a message that really does look like it comes from the airline, and the rush of travelling does the rest. To understand how this kind of deception is built, see how to recognise phishing. And for what to keep an eye on after a photo has already been posted, there are the signs someone used your QR code.
3. Legal and regulatory consequences: when other people’s data is involved
A practical example
The booking also holds Paul’s details: his name, sometimes his date of birth and the document number entered for check-in, and a phone number. Helen made the booking, for a business trip. With access to the booking management page, that data has been exposed too.
Possible effects
- a colleague’s data exposed because of a choice he did not make;
- as an employer, the need to assess what happened and, where the conditions apply, to take the steps required for personal data protection;
- reports to make to the airline and, in the case of fraud or impersonation, to the relevant authorities.
Why it matters
A group booking is not data that belongs only to you. When other people are on it — family, friends, colleagues — posting its reference means making a decision for them as well. This section describes the general picture and is not a substitute for legal advice: if an exposed booking involves other people’s personal data, or if you have been the victim of fraud, it is worth speaking to a professional or to your data protection contact.
4. Reputational consequences: when the photo becomes a script
A practical example
One of Helen’s clients receives a message from an unknown number: “It’s Helen, I’m stuck at the airport and my phone’s nearly dead. Could you pay the invoice early into this account?”. The message mentions the fair and the flight time. Fortunately, the client rings her before paying. Another contact does not.
Possible effects
- clients and colleagues receiving convincing requests in your name;
- the need to warn your contacts publicly, in the middle of the trip;
- wariness towards the messages that follow, including genuine ones;
- the impression, often unfair, that you could not protect the business’s data.
Why it matters
A travel photo provides exactly what a convincing scam needs: where you are, when you are hard to reach, who you are travelling with. A reputation is not repaired by deleting the post; it is rebuilt through openness and over time. It helps a great deal to know who actually sees what you share: that is the subject of connecting only with people you know.
5. Personal consequences: when it weighs on the person
A practical example
Helen comes home tired and with a new feeling: someone has followed her trip step by step. She goes back through the photos she has posted in recent months, wondering what else she has shown without realising. For a few weeks she posts nothing at all.
Possible effects
- stress at a time, travelling, when you have less room to react;
- the feeling of having been watched, which lingers even once things are resolved;
- personal details — name, dates, documents, travel habits — that can be reused for other attempts, even months later;
- the fact that the house was empty on those days, made public without meaning to;
- giving up on sharing moments you used to enjoy telling people about.
Why it matters
This is the least visible consequence and the most lasting one. And it is worth saying clearly: if this has happened to you, it is not because you were careless. Posting a boarding pass is a common gesture, almost a ritual; nobody tells us that the square holds data anyone can read. On location data in photos, a related but different subject, see turning off photo geotagging.
| Plane | What changes | How long it lasts |
|---|---|---|
| Operational | Booking changed, check-in blocked, trip to rebuild | Hours to days, far from home |
| Financial | Tickets to buy again, points taken, payments on fake pages | Weeks, not always recoverable |
| Legal | Other passengers’ data exposed, reports and formal steps | Tight deadlines, formal procedures |
| Reputational | Scams in your name built on the details of the trip | Months |
| Personal | Stress, feeling watched, details that can be reused | Variable, often the longest |
The cost no one budgets for: time
The cost of a new ticket is quick to work out. Time is much harder — and it is almost always the heaviest item, above all because it arrives when you are far from your desk.
A realistic estimate, based on how these situations usually unfold:
| Activity | Indicative time |
|---|---|
| Contacting the airline’s customer service and proving you hold the booking | An hour to a whole day, depending on the airline |
| Restoring the contact details and checking the booking | 1–2 hours |
| New tickets, changes of plan, letting people know | A few hours |
| Checking the frequent flyer account, cards and transactions | 1–2 hours |
| Messages to clients, colleagues and contacts to warn them | 1–3 hours |
| Reports and refund claims | Days, with documents to gather |
These are hours that were never on the calendar, taken away from the fair, from work or from rest, and packed into the very days when you are most tired.
That is precisely why the comparison is so telling: covering the code and the booking reference before posting takes less than a minute.
The consequences that fall on other people
A boarding pass looks like a personal document, but its consequences rarely stop with the person who photographed it.
- Travelling companions on the same booking may see their flight changed or cancelled, and their details are exposed.
- Clients and colleagues receive convincing messages that exploit the details of the trip, and some of them fall for it.
- Family members at home find themselves, without knowing it, in a house that was publicly signalled as empty for a few days.
- People waiting at your destination have to change their plans because of a delay nobody saw coming.
This is why, in the Cyber Welfare Framework, personal security is not treated as a purely private matter: every piece of data you protect also protects the people whose information it holds.
How this ties back to the recommendation
All of these consequences start from the same place: a readable code, posted together with a photo.
Not a sophisticated theft. Not a technical failure. An image shared with enthusiasm, in which a square of dots and a string of letters were worth far more than they seemed.
The boarding pass is the most obvious example, but not the only one: concert tickets, parcel labels, event passes and documents with a printed code all work the same way. To understand why a sharp shot is all it takes for anyone to read it, see how QR codes work. That is why recommendation R24 is not just about travel: it is about any code that ends up in a photo.
How to reduce the risk
- Post the photo of the trip, not the boarding pass. The window seat, the suitcase or the coffee tell the story of setting off just as well.
- If you want to show it, cover everything readable: the two-dimensional code, the booking reference, the name and the frequent flyer number. Use a solid block, not a light blur. The steps are explained in how to hide a QR code in a photo.
- Wait until you are back. A photo posted once the trip is over exposes much less than one posted at the gate; covering the code is still worthwhile, though.
- Check who can see your profile. A public profile that you also use for work reaches people you do not know.
- If you have already posted it, take the photo down, open the booking from the airline’s official website or app, check the contact details and extras, and if in doubt ask customer service to look into it. Let your travelling companions know.
- Be wary of messages that know about your trip. If they ask for payments or details, go in through the website or app you normally use, never through the link you received.
Quick checklist
- ☐ Before posting a photo, I check whether it shows any readable codes, names or numbers
- ☐ I do not post boarding passes, tickets or labels with the code visible
- ☐ I know that the booking reference alone may be enough to manage a flight
- ☐ When I cover a code, I use a solid block rather than a blur
- ☐ I know who can see what I share on social media
- ☐ If I receive a message that knows about my trip, I check through the official website
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that a code in a photo is readable information, not a graphic detail |
| Skills | Telling the five planes of consequence apart and knowing what to cover before posting |
| Secure Behaviour | Checking every photo before sharing it, especially when travelling |
Reference level: FL2 — Beginner. This is the level at which a spontaneous gesture, such as sharing a departure, stops being automatic and becomes a choice with a clear reason behind it.
Conclusion
A posted boarding pass does not produce “a cyber risk.” It produces a check-in that does not work, tickets to buy again, a colleague whose details are exposed, contacts who receive requests in your name, and the feeling, hard to shake off, that someone followed your trip.
Looking back at Helen’s photo, what could have been covered was very little, and always in the same place: the two-dimensional code, the booking reference, the name and the frequent flyer number. With four solid blocks, the photo would have told the same story of setting off, the same coffee, the same excitement — without handing anyone the keys to the trip.
The good news is that most of these consequences can be reduced with one habit within anyone’s reach: looking at every photo for a second longer before sharing it. If you would like to see which other areas are worth working on, the digital resilience self-assessment helps you spot them in a few minutes.
Something to think about. Among the photos you have posted over the past year, is there one with a ticket, a parcel or a document in full view — and could you say what that code contained?
Related resources
Short explainers from the Resources section, for anyone who wants to focus on a single aspect:
Related content
- Posting photos with QR codes — the recommendation this belongs to
- Risks of QR codes in photos — the technical plane: what can be read in a photographed code
- How to hide a QR code in a photo — the practical steps, before you post
- Signs someone used your QR code — what to check after a photo has already been shared
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



