Are the QR codes on your packaging safe?

A QR code is the only link in common use that nobody can read before they follow it.

A person can hover over a hyperlink and see where it goes. They can look at a short link and at least recognize the domain. A QR code offers none of that. It is a machine-readable instruction printed on a physical object, and the decision to trust it is made entirely on the basis of what it is printed on.

Which is why, when somebody puts a sticker over yours, it works.

What quishing actually is

The technique has a name now, quishing, or QR phishing, and it is almost disappointingly simple. Print a code that leads somewhere hostile. Stick it over a legitimate one. Wait.

Parking meters have been a favourite. So have restaurant table cards, EV chargers, public transit posters and event signage. The attack needs no technical sophistication, no compromise of your systems, and no access to anything you own. It needs a printer and thirty seconds of nobody looking.

The FBI issued a public advisory on malicious QR codes in January 2026, and it has been covered widely since. The reason it warrants an advisory is not that the technique is clever. It is that the victim behaves completely reasonably at every step: they scan a code on a sign that looks official, they land on a page that looks right, and they enter what they are asked for.

The uncomfortable part for publishers

If you print QR codes, on packaging, on equipment nameplates, in a catalogue, on a trade show stand, you are not the target of that attack. Your customer is, and your brand is the thing being borrowed to make it work.

You also cannot prevent it. There is no platform, no vendor and no technology that stops a person putting a sticker on your poster. Anyone who tells you otherwise is selling something.

What you can control is narrower, and more useful than it first appears:

  • whether your own codes can be corrected after printing
  • what domain your codes resolve through, and who controls it
  • whether you would notice something unusual happening

Those three are worth more than they sound, and most organizations have none of them.

Static codes are the bigger risk, and nobody talks about them

The threat that has actually cost businesses money is duller than quishing.

A static QR code has the destination encoded directly into the pattern. The code is the URL. That means it cannot be changed, ever, without reprinting whatever it is on.

So consider the ordinary lifecycle. You print fifty thousand cartons with a code pointing at a campaign landing page. Eighteen months later the site is restructured and the URL returns a 404. Or the campaign ends and the page comes down. Or the product line moves to a new domain. The code is still out there, on stock still in the channel, pointing at nothing.

Worse: if that domain or subdomain ever lapses and is registered by somebody else, every one of those fifty thousand codes now points at whatever the new owner wants. That is not hypothetical. Expired-domain takeover is a well-established technique, and printed codes are a uniquely durable way to keep sending traffic somewhere long after you have stopped thinking about it.

A dynamic code avoids all of this. The printed pattern points at a short link you control, and the short link points at the destination. Change the destination whenever you like; the printed run stays valid. If something is wrong, a bad URL, a compromised page, a campaign that needs pulling, it is a thirty-second fix instead of a recall.

For anything printed at volume or with a long shelf life, this is not an optimization. It is the difference between an asset and a liability with a delayed fuse.

What to ask about the platform generating your codes

Is the code dynamic or static? Many free generators produce static codes by default. If you cannot change the destination after printing, you have printed a permanent decision.

Who controls the domain the code resolves through? Every dynamic code depends on an intermediary domain. If that domain is a free shortener, you inherit its reputation, including any blocklisting caused by other people links, and its business continuity. Google discontinued its own URL shortener, and a generation of printed codes pointing at it became an exercise in trusting a redirect to keep working.

Can you see the scans? Scan analytics are usually sold as a marketing feature, and they are. They are also the only way you would notice that a code on a regional campaign is suddenly being scanned somewhere it should not be, or that scans have stopped entirely because something upstream broke.

Who can change the destination? A dynamic code is a permanent instruction pointing at a mutable target. That target should sit behind an authenticated account with a clear owner, not in a shared login somebody set up during a campaign three years ago.

What to tell customers, if you want to be useful

Most QR safety advice tells people to stop scanning codes, which is not advice anybody follows. Two things are more practical.

Check the physical code for tampering. A sticker over a printed surface is usually visible or detectable by touch, and on parking meters and public signage it is by far the most common form of the attack.

Look at the domain after scanning and before entering anything. Most phone cameras preview the destination. A payment page on a domain unrelated to the business whose sign you are standing in front of is the signal, and it is the last point at which the attack is easy to stop.

In short

QR codes are not inherently unsafe. They are unusually hard to inspect before use, which shifts more responsibility onto the publisher than most publishers realize.

The failure most likely to affect you is not a criminal with a sticker. It is a static code on a long-lived printed object, pointing at a URL you no longer control, still being scanned by people who trust your brand.

Where we sit

Every QR code generated by 1Link is dynamic, so you can repoint it after printing without reprinting anything. Codes resolve through a domain TAPQUAD Inc. operates and monitors, and scans are reported in real time by device, platform and location. It is a subscription in the App Store and Google Play, priced by how many links you keep live.