A QR code itself is just a way of encoding data — it isn't inherently dangerous. The risk comes from where a code points, not the pattern of black-and-white squares. Here's what business owners should know, and how to reassure customers who are (reasonably) cautious.
How QR codes actually get misused
Scammers occasionally place a fake sticker over a legitimate QR code — on a parking meter or a menu, for instance — redirecting to a malicious site instead of the real destination. The code itself isn't hacked; the physical sticker has simply been swapped.
How to protect your own printed codes
- Check printed codes in public spaces (tables, posters, signage) periodically for tampering or an unfamiliar sticker layered on top
- Use tamper-evident materials or laminate codes where they're exposed to the public and hard to monitor constantly
- Avoid displaying a bare code with no business branding around it — a code that clearly belongs to a recognizable business is harder to swap unnoticed
What to tell cautious customers
Most phone cameras show a preview of the destination URL before opening it when you scan a QR code — encourage customers to glance at that preview, especially if a code appears in an unexpected place, and only proceed if the domain looks correct and familiar.
Best practice for your own business codes
Link to your own domain wherever possible rather than an unfamiliar third-party shortener — a URL customers recognize builds more trust than an unfamiliar redirect link, even if both go to the same place.