Benjamin Claeys is CEO of QR TIGER, MENU TIGER and GiftLips. He also hosts Stay QRious, a podcast about QR code best practices.

​The most dangerous QR code is not necessarily the one that fails to scan. It’s the one that scans perfectly and takes the user somewhere they were never meant to go.

​Microsoft’s Q1 2026 email threat report reveals that between January and March 2026, QR code phishing, or “quishing,” attack volume jumped from 7.6 million to 18.7 million, increasing by 146%. March, in particular, had the highest incident volume.

​These findings deserve special attention. It offers both a challenge and an opportunity to give users confidence that the QR code—and the destination behind it—can be trusted.

The Cost Of QR Code Phishing

The first quarter of 2026 saw a significant increase in the use of QR codes in email phishing attacks. According to Microsoft, cybercriminals commonly embed QR codes with malicious URLs directly in the body of emails or within attachments.

​Since the URL is encoded inside an image, it requires decoding before the destination can be evaluated. This can make QR-based attacks harder for some conventional text-based security systems to detect. The attack becomes even more dangerous as victims use their personal smartphones or apps, where organizational security controls may be less restrictive.

​While Microsoft’s data captures the attack on digital ecosystems, the quishing attacks happening in physical spaces are equally as troubling.

​Recent Action Fraud reports from April 2024 to April 2025 recorded 784 reports of quishing, with almost £3.5 million lost. These attacks have appeared in familiar settings, including parking meters, railway stations, restaurant menus and parcels.

​In 2022, the FBI received reports of QR code scams in cryptocurrency transactions. Some also deliver these scams through gift cards.

​But the cost of quishing is not limited to financial losses for both businesses and customers. It can also erode the trust customers place in the businesses and organizations that use QR codes.

​According to my company’s findings on consumers’ perception of QR codes, four in 10 users hesitate to scan QR codes due to security concerns. In particular, over 50% skip scanning when they receive them via email or messages.

​Even when the business itself is not responsible for a malicious QR code, a negative scanning experience can still affect how customers perceive the brand.

​This puts the business in the uncomfortable position of owning reputational risk for an attack surface they don’t fully control. And it’s a big reason governance can’t be optional.

Designing Security Into The QR Experience

In my conversation with Masahiro Hara, the inventor of the QR code himself, he acknowledged the security challenge now surrounding the technology and pointed to the importance of authentication.

​It leads us to a broader issue: QR code security doesn’t end with the code itself. It extends to the identity, destination and controls surrounding it. Quishing isn’t simply a problem of malicious QR codes. It’s a problem of trust across the QR code lifecycle.

​Establishing a governance process enables businesses and organizations to take control of the entire lifecycle of a QR code—from creation and authorization to deployment, destination management, monitoring and retirement.

​Ownership And Access

A QR code should never become a “set it and forget it” asset. Organizations need appropriate access controls and internal processes for managing destinations.

​They should know who created the QR code, who can edit its destination, where it has been published, what destination it currently leads to, when the destination was last changed and whether the destination is still active and legitimate.

​Infrastructure And Controls

Businesses should be selective about the platforms they use to generate and manage QR codes. Beyond marketing, a QR code generator is part of the digital infrastructure of organizations for running user authentication, payments, product information, digital product passports and other sensitive experiences.

​Security should be evaluated alongside customization, analytics, integrations and pricing. Look for providers that offer appropriate account protections, secure infrastructure, access controls, white labeling for destination URLs, monitoring and mechanisms to detect or respond to abuse.

​Context And Authenticity

Scanning a QR code is an intentional act. A person often finds a few signals before scanning one: a benefit or value, relevance to their context, the authority of the QR code’s source and the urgency to scan it.

​Cybercriminals feed on these signals well. They don’t merely put malicious URLs into QR codes. They create a reason for the victim to want to scan them through an email request to verify an account, resolve a payment issue, complete multifactor authentication, sign a document or access an important notification—actions that feel legitimate before the user ever sees the destination.

​Context and authenticity, in this case, should go beyond branding, like the logo, colors, surrounding copy and even the overall layout. A business’s QR code should always be accompanied by clear context, explaining why it’s there and what happens after scanning.

​The goal is not to make users blindly trust QR codes. It is to give people enough information to make an informed decision about whether the scanning experience makes sense.

A More Secure Future For QR Codes

The rapid growth of quishing can create an understandable reaction: If attackers are abusing QR codes, perhaps businesses should stop using them.

​That would miss the bigger lesson. QR codes are no more inherently malicious than URLs, email or NFC technology. They are data carriers. The security of the experience depends on what they point to, who controls that destination and whether users can establish that it is legitimate.

​The appropriate response is to build trust around their use. Businesses and organizations should respond by treating QR codes as part of their digital security surface. They may only occupy a small space on a sign or screen, but their impact can extend across the entire user and business experience.

​Convenience made QR codes ubiquitous. Trust will help keep them useful.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version