5 Step QR Incident Playbook for U.S. Users Backed by FBI, FTC, CISA

24 September 20265 Step QR Incident Playbook for U.S. Users Backed by FBI, FTC, CISA

5 Step QR Incident Playbook for U.S. Users Backed by FBI, FTC, CISA

Decorative QR security playbook title card

Treat every QR code like a link you have not clicked yet: preview the destination before your phone opens it, and only scan codes with clear context or a source you trust. Following qr code security best practices means pausing for two seconds before you tap, checking the actual web address, and enabling phishing-resistant protections on your important accounts so a single bad scan cannot cascade into a bigger problem.


TL;DR:

  • Only scan QR codes from trusted sources and always preview the URL to check for typos, unusual domains, or suspicious redirects before proceeding.
  • Use the native camera app on iOS or Android, as it shows a destination preview that helps identify malicious links or redirections.
  • Avoid scanning codes embedded in unsolicited messages, emails, or found on packages unless the source is verified and the context is clear.
  • Enable phishing-resistant multi-factor authentication on your most important accounts to prevent account breaches if a malicious scan occurs.
  • If a QR code prompts for login credentials immediately, type the website address directly into the browser instead of trusting the scanned link.

Qrlytics
Keep Your QR Campaigns Reliable
QRlytics helps businesses manage QR codes with dynamic updates, real-time analytics, GDPR-compliant tracking, and lasting functionality.
Explore QRlytics

Table of Contents

  • How to scan QR codes safely
  • What does quishing look like in practice?
  • How can you create and share QR codes securely?
  • What protects your accounts after a scan?
  • What to do after a suspicious QR code scan
  • Quick QR code safety checklist
  • Small habits that reduce QR code risk
  • Sources
  • FAQ

How to scan QR codes safely

Your phone’s built-in camera app is your first line of defence. Unlike some third-party scanner apps, the native camera on iOS and Android shows a preview of the destination URL before anything opens, giving you a chance to inspect it rather than being dropped straight into a browser or app store. Duke University’s information security guidance recommends sticking with the native scanner for exactly this reason.

Person inspecting a QR destination preview

Once the preview appears, read it properly. Do not just glance at the first word. Look for the full domain, watch for typos or extra characters slipped in before the real brand name, and be wary of unusual top-level domains you would not expect from that organisation.

A few habits make the difference between a safe scan and a costly one:

  • Pause on any shortened or redirected link. If you cannot see where it ultimately lands, do not proceed.
  • Turn off automatic deep-linking or auto-app-opening in your phone settings so links land in a browser first, where you can see the address bar.
  • Never grant a permission (camera, contacts, location) just because a page asks for it immediately after scanning.
  • Avoid scanning codes sent via unsolicited text messages, emails, or found inside unexpected packages.

Pro Tip: If a QR code takes you somewhere that immediately asks for a password, stop. Open a new browser tab and type the organisation’s website address yourself instead of trusting the link you just scanned.

What does quishing look like in practice?

“Quishing” is QR-code phishing: hiding a malicious link inside a scannable image so it slips past the filters that usually catch a suspicious web address. Attackers lean on the same emotional triggers as any phishing email, just wrapped in a code instead of a hyperlink.

Watch for these signs before you scan anything:

  • Urgency or fear. “Your account will be suspended” or “payment failed, rescan to confirm” are classic pressure tactics.
  • Unearned rewards. A free prize, refund, or gift card tied to a code you were not expecting.
  • Missing sender details. No return address, no order number, no way to verify who sent it.
  • Codes buried in email images or attachments. Microsoft’s security team has documented a sharp rise in this tactic because it dodges traditional link scanning in mail filters.
  • Tiny, vague context text next to the code, or a link that is oddly truncated once you preview it.
  • Physical tampering. A sticker slapped over an existing code, a mismatched logo, or noticeably poor print quality on something that should look professional.

The FBI has flagged a related scheme where criminals mail unsolicited packages containing QR codes designed to harvest personal data or install malware, often with no return information included to discourage questions before scanning. Details are in the FBI’s 2025 alert on QR-enabled fraud schemes.

How can you create and share QR codes securely?

If you generate QR codes yourself, whether for a small business, an event, or a one-off flyer, the choices you make at creation stage determine how safe that code stays for everyone who scans it later.

  1. Choose dynamic over static codes. A dynamic QR code lets you edit the destination after printing and revoke access if something goes wrong, which matters if a URL is ever compromised or a campaign needs updating.
  2. Always point to HTTPS destinations. A branded landing page on a domain people recognise builds more trust than a generic redirect, and it gives scanners something concrete to verify.
  3. Never encode sensitive data directly in a static payload. Passwords, personal identifiers, or account numbers baked into a QR code cannot be revoked once printed.
  4. Password-protect or encrypt sensitive files if the code links to a document rather than a public page.
  5. Keep an owner and an audit trail. Someone needs to be accountable for what a redirect points to, and any change should be logged so unauthorised edits get caught and reversed quickly.

Some QR code platforms build dynamic codes with permanent functionality and full redirect history as standard, which is the kind of control this list assumes you have access to. For deeper guidance on avoiding reprints and hijacked links, see this breakdown of QR code best practices for marketers, and for landing page design specifically, these examples of branded code landing pages show what good context looks like.

Pro Tip: If you are handing off QR creation to an intern or a print shop, write down who owns the redirect and how to change it before the codes go to print. That single habit prevents most of the “who changed this link” panics.

What protects your accounts after a scan?

Even careful scanners occasionally land somewhere they should not. The controls you have in place beforehand decide whether that becomes a minor annoyance or a real breach.

  • Turn on phishing-resistant MFA such as FIDO or WebAuthn for your most important accounts, particularly email and banking. CISA recommends this as the gold standard, because a physical authenticator cannot be replayed or phished the way a text-message code can.
  • Keep your operating system and apps updated, and run a reputable mobile security tool that flags known malicious domains.
  • Audit app permissions regularly. Revoke camera, location, or contact access from anything you no longer use or do not recognise.
  • Review connected devices and active sessions on your major accounts every few months, not just after something feels wrong.
  • On a work device, ask IT whether mobile device management rules already evaluate or block risky URLs before you scan anything company-related.

Where full FIDO/WebAuthn migration is not yet possible, app-based one-time codes with number matching are a reasonable interim step, according to the same CISA guidance. State-sponsored groups have specifically used malicious QR codes to push victims from secured corporate email onto unmanaged mobile devices, where those email-level defences do not apply, as detailed in an IC3 advisory on quishing campaigns.

What to do after a suspicious QR code scan

Act quickly and in this order:

  1. Disconnect the device from Wi-Fi or mobile data, close the page immediately, and do not enter any credentials if a login screen appeared.
  2. Run a full antivirus or anti-malware scan, then clear your browser cache and cookies.
  3. Change passwords on any account you think may be exposed, and reconfigure your MFA if you suspect it was targeted.
  4. Check bank and card statements for unfamiliar activity if financial information may have been entered or captured.
  5. Report it. File a complaint with the FTC or the FBI’s Internet Crime Complaint Center, and notify whichever organisation was impersonated so they can warn other customers.

Quick QR code safety checklist

Save this one for your less technical friends and colleagues:

  • Never scan a code from an anonymous or unsolicited source.
  • Always preview the full destination domain before tapping through.
  • If a scanned page asks for login details, go to the official site yourself instead.
  • When in doubt, ask for an alternative such as a printed menu or a typed web address.
Situation Safe action
Unexpected package with a QR code Do not scan; report to the FTC or FBI
Code asks for login after scanning Close it; type the site address yourself
Sticker looks layered over another code Skip it; find the official source
Shortened link in the preview Do not proceed until you see the full domain

Small habits that reduce QR code risk

The single biggest shift I would ask any reader to make is turning “inspect before you tap” into a reflex rather than a rule you remember only after something goes wrong. That habit alone stops most quishing attempts, because these attacks rely on speed and inattention, not sophistication.

For organisations, the fix is largely about reducing ambiguity. A branded landing page with clear context does more to prevent accidental scans than any warning label, because it gives people something recognisable to check against. And a simple internal policy, naming who owns each redirect and how to revoke it fast, closes off the operational errors that let a code go stale or get hijacked in the first place.

QR redirect ownership and revocation workflow

Sources

For deeper technical or reporting guidance, consult the FBI’s IC3 quishing alerts, the FTC’s consumer scam alerts, and CISA’s phishing-resistant MFA guidance.

If you manage QR campaigns yourself and want the creation side handled properly from the start, Qrlytics’s free plan lets you build dynamic, trackable codes with permanent redirect control, no credit card required to begin. For teams that need editable targets and revocation on demand, the dynamic QR code generator covers exactly the safeguards this guide recommends creators put in place.

  • Unsolicited packages containing QR codes used to initiate fraud schemes — FBI (2025)
  • Scam alert: QR code in an unexpected package — FTC (2025)
  • North Korean Kimsuky actors leverage malicious QR codes in spearphishing campaigns targeting U.S. entities — IC3 (2026)
  • Implementing phishing-resistant multi-factor authentication — CISA

FAQ

How Secure Are QR Codes?

QR codes themselves are just a data format; they carry no inherent malware. The risk comes from where the code points, so security depends entirely on verifying the destination before you follow it, as the FTC’s guidance on unexpected QR codes explains.

What Are Common QR Code Mistakes to Avoid?

The biggest mistakes are scanning codes from unsolicited packages or messages, skipping the URL preview, and entering login details on a page reached through a scanned link rather than typing the address directly. Encoding sensitive personal data into a static, unchangeable code is another frequent error among people creating codes.

What Is the FBI Warning About QR Codes?

The FBI has warned that criminals mail unsolicited packages containing QR codes designed to harvest personal or financial data or install malware, often deliberately leaving out return information. Full details are in the FBI’s 2025 alert.

What Best Practices Should You Follow to Avoid Unsafe QR Codes?

Preview the destination URL before opening it, only scan codes from sources with clear context, avoid entering credentials on a page reached via a scanned link, and enable phishing-resistant MFA on important accounts. Skip any code from an unsolicited package, email, or message entirely.

Recommended

  • Secure QR solutions checklist for business teams
  • Avoid Legal Risk: Launch QR Consent in 7 Steps in the US (ESIGN/UETA)
  • Types of QR code fraud risks: your 2026 guide
  • Role of QR codes in product recalls: a practical guide