QR codes have become part of daily life. We scan them to read menus, access event tickets, pay bills, and even log in to secure accounts. But while these square patterns are a quick bridge between the physical and digital world, that same speed and simplicity make them attractive to cybercriminals.
Most people know to be cautious about clicking links in suspicious emails, but they may not realize QR codes can hide those same dangerous links. A cybercriminal can create a code that, when scanned, directs a user to a phishing site, initiates a malicious download, or prompts them to enter sensitive information.
And now, attackers are getting more creative. In a recent warning, the FBI reported scammers mailing unsolicited packages containing QR codes — a twist on the “brushing scam.” Traditionally, brushing scams send items to people without their consent to generate fake reviews. In this variation, the QR code lures the recipient to scan it to learn where the package came from, only to land on a malicious site designed to steal information or install malware. Often, these packages omit sender information to increase curiosity.
Why Businesses Should Care
For companies, the risk extends beyond personal devices. An employee scanning a malicious QR code on a phone connected to company email or internal apps could give attackers a pathway into corporate systems. Public-facing QR codes — like those printed on marketing materials or invoices — can also be tampered with if not secured properly, redirecting customers or vendors to fraudulent sites that damage brand trust.
Other Common QR Code Threats
While the mailed-package scam is new, there are several established methods cybercriminals use:
-
QR Code Overlays – Attackers place fake QR code stickers over legitimate ones in public places, sending users to phishing sites.
-
Malicious Ads and Flyers – Codes in posters, ads, or handouts lead to infected downloads.
-
Compromised Business QR Codes – If your business’s QR code is hijacked, customers could unknowingly hand over sensitive information to attackers.
How to Stay Safe
The FBI and security experts recommend:
-
Don’t scan codes from unknown sources — whether in an email, flyer, or package.
-
Verify before scanning — if a code claims to be from a known company, confirm directly with them.
-
Inspect public QR codes — check for stickers placed over originals.
-
Limit permissions — don’t automatically allow apps or QR code scanners to open links or access phone data without review.
-
Educate employees — security training should include the risks of QR codes, not just email phishing.
-
Secure your own codes — monitor your printed and online QR codes to prevent tampering.
A Small Square with Big Security Implications
QR codes aren’t going away — in fact, their use is only increasing. But the same qualities that make them convenient also make them vulnerable to exploitation. Businesses that treat QR codes with the same caution as email links, and train their employees and customers accordingly, will be far better positioned to avoid costly breaches.



