MDXTORAExplore↗

September 22, 2026 · Security · 2 min read

QR code security: how to create and scan codes safely

QR codes are convenient because you can scan them without thinking. That same convenience is what attackers exploit. A code is just a link in disguise, and you cannot tell where it goes by looking at it. Here is how to stay safe, whether you scan codes or publish them.

What can go wrong

The most common attack is sometimes called quishing: a malicious QR code that leads to a fake login page, a payment page that sends money to the wrong place, or a site that tries to install unwanted software. Criminals stick their own code over a legitimate poster or parking meter sign, hoping people scan without checking.

Safe habits for people who scan

  • Look at the link preview your phone shows before you open it. Check the domain carefully.
  • Be cautious with codes on stickers placed over other signs; check whether the sticker looks tampered with.
  • Never enter passwords or payment details on a page you reached through an unexpected code.
  • Be suspicious of urgent messages such as "your account is suspended, scan to fix".
  • Keep your phone's operating system and browser up to date.
  • If a code leads to a download you did not expect, close it.

Safe habits for businesses that publish codes

If you print codes in public places, you have a responsibility to make them trustworthy and to notice tampering.

  • Use a short, recognisable domain so people can verify where the code leads.
  • Print codes directly onto materials or protect them under a clear cover that makes stickers hard to add.
  • Check public codes regularly to make sure no one has covered or replaced them.
  • Add a short text link near the code, so cautious users can type it instead.
  • Send visitors only to pages served over HTTPS.

Redirect-based codes and safety

Redirect-based codes have a security advantage: if a destination is ever compromised or a page is taken down, you can change or disable it without reprinting. They also have a responsibility: the redirect service must protect your account, since anyone who gains access could re-point your printed codes. Use a strong, unique password and enable extra sign-in protection where available.

Protect your account

  • Use a long, unique password stored in a password manager.
  • Enable two-factor authentication where offered.
  • Review who has access to your workspace and remove people who no longer need it.
  • Check destination links periodically to make sure they still lead where you intend.

What to do if you scanned something suspicious

Close the page without entering anything. If you did enter a password, change it immediately, and change it anywhere else you used it. If you entered payment details, contact your bank. Report the code to the venue or owner so they can remove it.

Awareness is the best defence. A few seconds spent checking the link before you tap it is enough to avoid most QR-based scams.