A photo with a QR code in view usually looks perfectly ordinary: a boarding pass before take-off, a pair of concert tickets, the Wi-Fi card on the shelf at home. The problem is not the photo itself: it is that the little square can be read from a screen too, and whoever reads it may find a booking reference, a valid ticket or the password to your network.
This post brings together the signs someone used your QR code after you posted it: what they mean, where you can see them, and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): traces suggesting that someone else has got hold of something that belongs to you.
It is the diagnostic deep dive on the recommendation about posting photos with QR codes: covering the code before you share is the prevention; recognising the signs matters when the photo is already online, perhaps for days, and you want to know whether anyone has taken advantage of it.
What the signs of a QR code used by someone else are
A QR code is a square of black and white modules holding a piece of information in a format a camera can read: a link, a code, some text. Anyone who scans it, even from a photo on someone else’s phone, gets exactly the same information you would. How it is built and what it can contain is explained in the post on how QR codes work.
A sign of use by someone else is an observable trace suggesting that a person has read that code and made use of it. It is not proof. It is a reason to check: it may have a harmless explanation, such as a change made by the airline or a device at home you had forgotten about, or it may mean that the code was used by someone who saw it online.
The value of these signs lies in timing: noticing before the trip or the event means you can ask for a new code and have the old one cancelled; noticing at the gate means finding out when it is too late to sort things out calmly.
Why they matter more when the photo is public
A QR code shown in person, at the check-in desk or at a theatre entrance, is seen by whoever is in front of you for a few seconds. A QR code you post stays visible for a long time, to an audience you do not control: your contacts’ contacts, people who reshare, people who save stories before they disappear.
That is why a sign has to be read knowing how long and to how many people the photo was exposed. A private photo removed after an hour is not the same as a highlighted story visible to everyone for weeks. Who sees what you post also depends on whom you have accepted as a contact, the subject of the recommendation on social media, only people you know.
There is a second point too: many codes stay valid until the date of the journey or the event, and Wi-Fi codes until you change the password. An old photo may therefore still be useful to someone, even if you have long forgotten it.
Technical indicators
These are the traces that services record and tell you about: in confirmation emails, in the personal area of the website or app, in your router’s settings page. The router is the box that creates your home network and connects your devices to the internet.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| An email about a booking change you did not make | Someone has changed the details, times or extras of your trip | The code in the photo may be enough to retrieve the booking and change it | The email address used to book, the “My bookings” area | Sign in from the official website or app, check, and contact the airline or operator |
| A seat change you did not ask for | Your allocated seat differs from the one you chose | It is a small change, often the first sign that someone has accessed the booking | Update email, flight or train details | Report the anomaly to customer service and ask them to protect the booking |
| Check-in completed by someone else | Check-in shows as done, but not by you | Someone has used your details to manage the trip in your place | Check-in confirmation email, booking status | Ask the airline or operator whether the boarding pass needs to be reissued |
| A ticket transferred or reissued | An event ticket appears under another name or has been replaced | Whoever has the code may try to claim it as their own | Notifications from the ticketing service, personal area | Contact the organiser straight away through the official channel |
| Unknown devices on your home network | Names you do not recognise appear in the list of connected devices | If you posted the Wi-Fi code, anyone who scanned it knows the password | Router settings page or your broadband provider’s app | Change the Wi-Fi password and disconnect the unknown devices |
| Sign-ins to the service account from new devices | The airline or ticketing website reports a sign-in you do not recognise | Someone may have got into the account starting from the details read in the code | Security emails, sign-in history | Change the password and turn on multi-factor authentication if available |
| Devices linked to a messaging app that you do not recognise | The app shows as open on a computer that is not yours | Some QR codes are used to pair a new device with an account | The app’s “Linked devices” section | Disconnect the device and review the security settings |
Multi-factor authentication is a second check, such as a code sent to your phone, on top of the password.
Signs you can observe yourself
These do not require you to open any settings page: you notice them in everyday life.
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| The ticket shows as already validated | The code was scanned at the entrance before you arrived | Someone used a copy of your ticket | The scanner at the entrance rejects it as already used | Ask the staff to check, and show your purchase confirmation and ID |
| Your seat is already taken | Someone is sitting in your seat with what looks like a valid ticket | It may be a mistake, or it may be your code being used | On the train, on the plane, in the venue | Speak to the staff rather than arguing with the other person |
| Messages or calls quoting the real details of your trip | Someone knows your date, destination and booking reference | Real details make a fake request for payment or data more convincing | Emails, text messages or calls claiming to be from the airline or operator | Do not give details or pay; check through the official website or app |
| Your home connection is slower than usual | More devices than expected are using the network | Together with other clues, it may point to unauthorised use of your Wi-Fi | Everyday use, videos that keep buffering | Check the list of connected devices before drawing conclusions |
| Points or credit missing from a card | The balance on a loyalty or gift card has gone down | Some digital cards show a QR code that works just like the card itself | Checking the balance in the app or at the till | Block the card and ask for the code to be replaced |
| A parcel shows as collected, but not by you | The collection code was used before you got there | Whoever has the code can collect the parcel in your place | Delivery completed notification, empty parcel locker | Contact the delivery service and report the unauthorised collection |
The third signal deserves particular attention: messages built on real details are among the most convincing. How they are put together is explained in the post on QR code attacks.
A real-life example
Sarah has bought two tickets for a concert and posts a story with her phone screen in the foreground: “We’re going!”. You can see the name of the band, the date and the QR code, perfectly sharp. The story stays highlighted on her profile.
A week before the concert she gets an email from the ticketing service: her account has been opened from a new device. She assumes it was the computer at work and forgets about it.
On the night of the concert, at the entrance, the scanner reports that one of the two tickets has already been validated. With her purchase confirmation and ID the staff let her in, but it takes time.
The first signal was already enough. On its own, it looked like a slip; read alongside the story with the code in view, it would have led her to remove the photo, change the password and ask the ticketing service to reissue the tickets.
What to check right away
On the photo
- whether the code is still visible in the post, in highlighted stories or in albums;
- whether anyone has reshared it or messaged you about it.
On bookings and tickets that are still valid
- booking status, allocated seat, check-in;
- the name of the holder and the contact details on record;
- confirmation or change emails you do not remember.
On your home network, if the Wi-Fi code was visible
- the list of devices connected to the router;
- the guest network, if you have one, and its password.
On the accounts of the services involved
- sign-in history and connected devices;
- recovery email address and phone number;
- the status of multi-factor authentication.
If you find a suspicious indicator
- Remove or edit the photo. It does not delete copies already saved, but it stops new people from reading the code.
- Contact the service through the official channel, typing the address yourself or opening the app, never through links you have received: ask whether the code can be cancelled and replaced.
- Change the Wi-Fi password if the code was for your network, then reconnect only your own devices.
- Change the password for the service account and turn on multi-factor authentication where it is available.
- Be wary of messages quoting your details in the days that follow, even if they appear to come from the airline or operator.
For future photos, the simplest ways to make the code unreadable are in the post on how to hide a QR code in a photo. If the code was on a boarding pass, what can happen in the more serious cases is described in the post on the consequences of posting a boarding pass.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: getting alarmed over nothing, and getting used to ignoring the real signals.
| Situation | Why it is usually not a signal |
|---|---|
| A change of time or platform announced by the operator | It is an operational change made by the service, not a change made by someone else |
| Automatic check-in before departure | Some services do it on their own and send you a confirmation |
| Promotional emails after a purchase | They show that you are on the customer list, not that someone has used your code |
| An “unknown” device on the network that turns out to be the TV or a speaker at home | Many appliances show up with technical names that are hard to recognise |
| The scanner does not read the code at the first attempt | It often comes down to screen brightness or a reflection |
| A new sign-in after you changed phones | It is your new device, registered as such |
The rule of thumb: one isolated signal deserves a check; two signals together deserve action.
When to run these checks
You do not need a demanding routine. You just need to know which moments matter.
| Moment | What to check |
|---|---|
| As soon as you realise you have posted a code | The photo first, then the service the code belongs to |
| Up to the date of the trip or the event | Change emails, allocated seat, ticket status |
| The day before departure or the event | That bookings and tickets are still in your name and unchanged |
| After posting a photo with the Wi-Fi code | Devices connected to the router, then the network password |
| Every now and then, scrolling through your profile | Old photos and highlighted stories with codes that can still be read |
Looking at your profile through a stranger’s eyes helps beyond QR codes too: the same photos may reveal where you live, the subject of the recommendation geotagging: photos without your location. For Wi-Fi, a guest network with a separate password makes any card left in view far less sensitive.
Two important caveats
An indicator is not proof. An airline may move a seat for operational reasons, a device at home may show up with an odd name, a scanner may get it wrong. Check before you get alarmed, but always check, and do it through the official channel.
No indicators is not a guarantee. Someone who reads a code may simply use the information it holds, such as name, dates or destination, without changing anything and without leaving visible traces. That is why protection does not rest on watching for signals, but on the habit described in the recommendation: the code gets covered before you post. Why even a code that looks harmless can hold more than you might think is explained in the post on the risks of QR codes in photos.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to read a service’s emails, your personal area and the router’s device list to recognise unauthorised use |
| Awareness | Understanding that a posted code stays readable and valid even when the photo seems forgotten |
| Secure Behaviour | Reviewing photos you have already posted and acting through the official channel when a signal does not add up |
Reference level: FL3 — Autonomous. This is the level at which you link a signal to the photo that made it possible and act on it without needing outside support.
Conclusion
The signs someone used your QR code are not meant to make you look at every photo you have posted with suspicion. They are meant to help you know where to look when a notification does not add up, before the problem turns up at the gate or the entrance.
What to do right now. Scroll through the photos and highlighted stories on your profile looking for QR codes that can still be read: tickets, boarding passes, Wi-Fi cards. If you find one linked to something that is still valid, remove the photo and check the service it belongs to. To see where you stand on the other aspects of your digital security too, you can take the digital resilience self-assessment.
Related resources
Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:
- Home network security: the router nobody configures
- How to recognise phishing when it is built to be convincing
Related content
- Posting photos with QR codes — the recommendation this belongs to
- QR code attacks — the mechanisms that produce these signals
- How to hide a QR code in a photo — what to do before you post
- Risks of QR codes in photos — what is exposed when a code stays in view
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



