Estonian Smart-ID Plus: QR Code Authentication Upgrade (January 2026)
Estonia's Smart-ID+ (January 2026) replaced control codes with QR scanning to prevent SIM-swap and man-in-the-browser attacks. Only scan QR codes from self-initiated logins.
Smart-ID+ is a security upgrade rolled out by the Estonian RIA (State Information System Authority) in late January 2026. It replaces the previous control code comparison method with QR code scanning. Security improvement: QR code authentication prevents SIM-swap attacks and man-in-the-browser attacks that could exploit the previous control code method. Usage: Scan the QR code with the Smart-ID app specifically (not the phone's camera app). Only scan when YOU initiated the login — never scan a QR code from an unsolicited prompt. Note: terviseportaal.ee (Estonian health portal) is a legitimate government site operated by TEHIK and Tervisekassa on an official .ee domain.