Safeguarding Yourself from The Surprising Dangers Lurking Behind QR Codes

Malicious QR Codes are Hidden Everywhere  

QR codes have become a common part of everyday life. They can be found in restaurants, parking lots, social events, product packaging, and even in unexpected places, like on modern gravestones. It is understandable, after all, that they are easy to use and very practical. We are so used to seeing them everywhere that it is easy to overlook the risks they can carry. According to the Anti-Phishing Working Group (APWG) in its Q1 2025 report, over 1.7 million unique malicious QR codes were detected by cybersecurity researchers, along with “an average of 2.7 million emails with QR codes attached daily”.


How Does a Malicious QR Code Function?  

QR codes work by encoding information into a square pattern that can be read by a scanner or camera. This information can include a URL, text, or contact details. QR codes are fast, reliable, and capable of storing much more data than traditional barcodes. However, because the content is encoded within the pattern, attackers can exploit this to hide malicious links or actions. Some devices and apps show a preview before opening a link, but not all do, and users often do not inspect the preview carefully, making QR codes a useful tool for phishing and other malicious attacks. 

QR codes Can Be Exploited in Various Different Ways 

1. Phishing Campaigns (Quishing) 

Attackers can embed URLs in QR codes that redirect users to phishing sites designed to steal personal information, login credentials, or financial details. Since users often do not see or carefully check the URL before opening it, they may not realize they are being directed to a fraudulent website. This tactic is widely used because of its high effectiveness. 

2. Malware Distribution 

QR codes can also direct users to websites that prompt users to download malicious software onto their smartphones or computers. If users proceed with the installation, the software can infect their devices with malware. Although most devices require user permission to complete the installation, attackers often rely on social engineering tactics to overcome users’ caution. 

3. Fake Payment Requests 

Scammers can create fake QR codes or replace legitimate ones in public places (known as QR code tampering), to redirect payments to their own accounts. This method is commonly used in situations like parking meters, charity donations, or sending them via email or chat, tricking victims into unknowingly sending money to cybercriminals. 

5 Quick and Easy Steps to Take in Order to Safely Scan and Verify QR Codes 

There are 5 steps that one can easily and quickly take to better safeguard themselves and their data against Malicious QR codes.  

1. Inspect The QR Code Source 

Before scanning a QR code, make sure it comes from a trusted source. Be cautious of codes found in public places that look out of place, are poorly printed, or appear to be stickers placed over original codes. Watch out for posters or messages with QR codes that try to grab your attention or offer something that seems too good to be true. 

2. Verify the URL Before Clicking  

Most modern smartphone cameras display a preview of the link or information encoded before opening it, allowing users to review what type of content is behind the QR code. Before clicking any links, always take a moment to verify the URL is legitimate and a trusted website and not an imitation with misspellings or suspicious characters. Be cautious with shortened or unclear links, as attackers may use link obfuscation to hide malicious destinations. If anything looks off, it is safer to type the known URL manually into your browser.  

 In case your device does not display a preview of the QR code, consider installing a camera or scanner app that allows you to view the content before opening it. Always use trusted QR code scanning apps from reputable sources to ensure your security. 

 3. Avoid Entering Sensitive Information 

Never enter sensitive information on websites accessed through QR codes unless you are certain the site is legitimate and secure. Cybercriminals can create fake websites to steal personal identifiable information, login credentials, credit card numbers, or other confidential data. If scanning a QR code opens a form asking for personal details, especially in a public space, consider it a red flag and think twice before entering anything. Always verify that the site uses a secure HTTPS connection and that the domain name is correct and trusted. You can also search for the site online for verification. 

4. Do Not Download Files from QR Codes 

QR codes can take you to websites asking you to download files, especially software or apps. While this might seem convenient, it is a common method used by cybercriminals to install malware. Unless you trust the source, avoid downloading anything it points to. Instead, use official app stores or trusted websites when downloading or installing software. 

 5. Keep Devices Updated and Use Anti-Malware Software 

It is important to make sure that your device and apps stay updated. Those updates often fix security vulnerabilities that cybercriminals could exploit. Additionally, installing anti-malware software adds another layer of security and can help detect and block potential threats before they cause harm. 

Stay Safe and Stay Aware  

Using QR codes to deliver attacks remains a common and growing threat in 2025. This technology has become a part of everyday life, and most people use it without a second thought. That convenience also makes QR codes an easy target for cybercriminals. As technology advances, so do the tactics used to exploit it. That is why staying alert matters. Taking a moment to check a link can help you avoid much bigger problems. 

Author: The Safeguards Consulting, Inc. Cybersecurity Team 

Release of the April 2025 Safeguards Consulting Chronicle

Our team is proud to share that we recently released the April issue of our firm's monthly newsletter, The Safeguards Consulting Chronicle, and we would love to invite you to subscribe for free. This year, we are also proudly celebrating its second anniversary, and in June, we will publish our 30th newsletter! 

Our newsletter covers numerous industry events, news, and updates.  

Some of the items we included in our April issue was:    

+ A featured friend spotlight piece on Pattern Energy.    

+ An exclusive article written by our Founder, Mark Schreiber, “1 False Hope of Artificial Intelligence?”.  

+ A list of beneficial industry events, which includes events we are supporting/speaking at, as well as other events we recommend attending.    

+ Our list of useful blog articles.     

+ A selection of key industry news and updates.     

+ A quick industry tip as provided by our experts.    

This month’s “Featured Friend” will also be our client, Scout Motors! 

If interested, please subscribe using the hyperlink included below.    

Newsletter Signup — Safeguards Consulting, Inc.    

If you subscribe to our free newsletter, you gain access to all the exclusive security content mentioned above as well as additional content we hope will help you in your role as a security professional. It is also a wonderful way for my firm to stay in contact with you regarding company news, updates, or events, so please consider subscribing in time for our May issue!    

Schreiber Joins SIA’s Voice of the Industry (VOI) Committee to Assist Security Practitioners Advancing Real Conversations (SPARC)

Safeguards Consulting is proud to share that our Founder, Mark Schreiber, is furthering his involvement in the Security Industry Association (SIA) even more!  

Recently, Schreiber joined an esteemed group of experts to form one of SIA’s newest committees, the Voice Of the Industry (VOI) committee. This committee falls under SPARC’s umbrella of 3 bodies, which are membership, VOI, and support services. The VOI committee focuses on engaging with manufacturers, integrators, and specifiers to discuss industry needs, concerns, and expectations.  

One of the ways the new committee is seeking to grow and improve the industry is by assisting the Security Practitioners Advancing Real Conversations (SPARC) committee, which is also known as the SIA Technical End User Forum, with white papers to support large end users in and outside of SPARC.  

SPARC is a new community of security professionals brought together to support end-user technical practitioners with a large network of technical professionals. These professionals all seek to deliver impact in the security technology industry while also engaging and encouraging compliance with technology and industry standards. In addition, SPARC’s members are provided with state-of-the-art security technology research, training, and networking opportunities, among other things! 

To learn more about the Security Industry Association (SIA), visit:  

Security Industry Association (SIA) - Information. Insight. Influence. 

To learn more about Security Practitioners Advancing Real Conversations (SPARC), visit:  

SPARC: SIA's Technical End User Forum - Security Industry Association 

If you are interested in learning more about the Voice Of the Industry committee, consider following us on social media or subscribing to our free newsletter to receive updates as Schreiber continues to serve and advance the industry with his VOI peers! 

To subscribe to our newsletter, The Safeguards Consulting Chronicle, visit:  

Newsletter Signup — Safeguards Consulting, Inc. 

Celebrating 15 Years of Trusted Advisory

At Safeguards Consulting, Inc., our journey began 15 years ago on April 7th, 2010, in the beautiful Upstate of South Carolina, with a vision to create a consulting firm that would make a meaningful difference in the world of physical security design and technology consulting.  

Our Founder, Mark Schreiber, who has over 25 years' worth of experience within the industry, recognized the need for trusted advisors within our industry to share valuable institutional knowledge and serve the many organizations that remain vulnerable and in need of guidance.  

Starting solo, Schreiber helped as many organizations as possible until he needed to expand to a team of trusted advisors with diverse backgrounds and skill sets to support our many clients.  Through a deep pool of experience and development of advanced processes, we address the pressing need for comprehensive physical security consulting solutions. We also recognized that physical security is not a one-size-fits-all solution as each client's needs and challenges are unique, so our team of consultants works closely with security stakeholders to meticulously assess their existing security measures, identify vulnerabilities, and develop tailored strategies to fortify their defenses.  

When we asked Schreiber to reflect upon our anniversary milestone, he stated, “It is amazing how much we have accomplished over this time, but it has moved quickly as we are always addressing new challenges and supporting new clients.  I am most proud of my team that has never wavered from the highest level of quality serving our amazing clients”.  

Over the years, we have grown alongside our clients, responding to new security challenges and evolving threats. 2025 is predicted to be our biggest year yet, but our success is built on the trust you have placed in us - trust formed by transparent communications and information sharing, tailored services, and our relentless passion to protect others with a servant’s heart.  

Today our team proudly serves numerous clients worldwide alongside our partners. In addition, we also serve within the security industry community by providing education, resources, and advice to further the industry and our mission to protect and serve others as trusted advisors.  

Thank you for making us your trusted advisors for 15 years. In addition, thank you also to our partners and industry peers for their support. Most of all, thank you to our team for your efforts and passion.  

Therefore, here's to many more years of serving as trusted advisors!  

If you would like to learn more about our history or how we can help secure your future, please reach out to our team today by using the link below!  

Safeguards Consulting, Inc. 

Contact — Safeguards Consulting, Inc. 

If you would like to stay in contact with us on a more frequent basis, consider subscribing to our free newsletter, The Safeguards Consulting Chronicle, which will be proudly celebrating its 30th issue this June.  

Newsletter Signup — Safeguards Consulting, Inc.