Guide
Are QR codes safe to scan?
The QR pattern itself is inert — it's just encoded text, and scanning one cannot install anything by itself. The real risk is what a malicious code points at, or a fake sticker placed over a legitimate one. A little caution before tapping through removes most of the danger.
Published 28 August 2026 by 123QR
Quishing: stickers over legitimate codes
"Quishing" (QR phishing) usually works by physically covering a real, trusted QR code with a sticker carrying a malicious one — on a parking meter, a restaurant table, a delivery locker, a poster. The victim trusts the context (a parking meter looks official) more than the specific code, and scans without checking.
This attack targets static codes especially, since there's no way for the business to notice a sticker swap remotely. A business using a dynamic code at least retains the ability to see scan volume drop off oddly if a placement is tampered with, though it still can't detect the sticker itself.
Shortened URLs hiding the real destination
Any short link, whether from a QR redirect service or a plain URL shortener, hides the actual destination domain until you click through. This is normal and not inherently malicious, but it does mean scanners can't tell where a code leads just by looking at the preview their phone shows.
The honest trade-off: this is exactly how every dynamic QR code works, including the ones 123QR generates. A short link is what makes the destination editable. The mitigation isn't avoiding short links altogether, it's only scanning codes from sources you trust the physical placement of.
Public WiFi codes
A QR code advertised as connecting to WiFi could instead point to a fake captive portal designed to harvest credentials, or connect you to a network controlled by someone else entirely. Cafes, airports and hotels are common targets because people expect to see a WiFi QR code there and don't scrutinise it.
There's no reliable way to visually distinguish a genuine WiFi QR code from a malicious one before scanning. Ask staff to confirm the network name matches what the code connects to, and be more cautious of a WiFi code that isn't posted somewhere staff-controlled (e.g. taped loosely near a table rather than printed on the venue's own signage).
Advice for people scanning codes
- Check your phone's link preview before tapping through, not after — most camera apps show the destination URL before opening it.
- Be suspicious of a code that looks stuck on top of another surface, especially in places with lots of foot traffic (parking, transit, public boards).
- Don't enter passwords or payment details on a page you reached via QR code unless you recognise the domain.
- If a QR code is the only way to access something important (a parking payment, an event ticket), consider whether the venue offers an alternative way to reach the same page directly.
Advice for businesses printing codes
- Use a tamper-evident placement where possible — printed directly onto the material rather than a separate label that's easy to peel and replace.
- Check physical placements periodically for stickers or overlays, especially in public or unsupervised locations.
- Keep an eye on scan analytics for a sudden, inexplicable drop or spike at one location, which can be an early sign something changed at that placement.
- Tell customers what to expect: if your code always redirects through a specific domain, a small printed note ("scans via 123qr.net") helps a cautious customer recognise it as normal.
How 123QR handles redirects transparently
Every 123QR code redirects through a visible 123qr.net short link — we don't disguise or cloak the intermediate domain. A scanner's phone will show 123qr.net in the preview before the final destination loads, which is more transparent than services that route through unbranded or rotating domains.
We can't prevent someone from printing a malicious sticker over your legitimate code in the physical world, and no QR provider can. What we can do is give you scan analytics so an unusual pattern at one location is visible to you, and keep the redirect layer itself straightforward rather than obscured.
Common questions
- Can scanning a QR code alone install malware?
- No. Scanning just decodes text and typically opens a URL in your browser, the same as tapping a link. Risk comes from what you do after — entering credentials, downloading a file, granting a permission — not from the scan itself.
- Are dynamic QR codes less safe than static ones because they can be edited?
- Not inherently. Editability is controlled by the account holder, not by scanners. The safety question is really about who controls the code and what they point it at, not whether it's static or dynamic.
- How do I know a QR code hasn't been tampered with?
- You generally can't tell by looking. Check whether it looks stuck onto a surface rather than printed as part of it, and check the link preview before opening. There's no fully reliable visual test.
- Does 123QR scan destinations for malicious content?
- 123QR does not claim malware scanning or content moderation of destination URLs. Only point codes at destinations you control and trust.
Keep reading
- Do QR codes expire?Why codes stop working, and which part actually has an expiry.
- QR code analyticsSee when, where and on what device your printed material gets scanned.
- SecurityHow redirects, account data and scan records are handled.
- Static vs dynamic QR codesThe one structural difference, and what it means once something is printed.
Print once. Change the destination anytime.
Create a free account, generate your code and edit where it points whenever you need to.
