Campaign purpose

Why QR-code awareness matters

QR codes are common in restaurants, parking areas, events, payments, and public spaces. That familiarity can cause people to scan first and verify later.

The campaign uses harmless poster concepts to demonstrate how an attacker could disguise a link behind something useful, familiar, or rewarding. Legitimate participants are taken directly to a transparent security lesson.

Research question

Which type of message is most persuasive?

Reward Convenience Familiarity Utility Information

What participants learn

  • Preview the destination before opening a QR link.
  • Look for misspelled domains and unexpected redirects.
  • Do not enter credentials after an unverified scan.
  • Be cautious with payments, giveaways, parking, and account warnings.

What the project does not collect

  • Names, email addresses, or passwords
  • GPS coordinates or precise location
  • Raw IP addresses
  • Payment information or account credentials
Campaign materials are intentionally private. The live QR images, tokenized tracking links, and analytics dashboard are kept in a protected administrative workspace so ordinary website visits do not distort the campaign results.
Everyday security

Simple habits that prevent common attacks

Use these checks whenever a message, link, QR code, login request, or download feels unexpected.

  • Pause before opening unexpected links, attachments, or QR codes.
  • Verify the sender, website domain, and request through a separate trusted method.
  • Use unique passwords, a password manager, and multifactor authentication.
  • Keep devices and applications updated, and report suspicious activity quickly.