Security and the 2D barcode transition

QR code security for retail packaging

A QR code is a printed address nobody can read before they arrive at it. That single property is the entire security question, and it is narrower than the one most articles on the subject answer. This page separates what is documented from what is merely plausible, then sets out which parts of the problem a brand owner actually decides.

The threat model, stated precisely

QR codes are not inherently unsafe. The symbol is a public, well documented encoding with no secrets in it. The problem is one step earlier. When a shopper reads a printed word, they can evaluate it before acting on it. When they point a camera at a square of black and white, evaluation and action collapse into one gesture, because what is encoded stays opaque until it has already resolved.

Two distinct failures live inside that property, and conflating them is how most security writing on this topic goes wrong.

Substitution, the physical failure

Someone covers a legitimate printed code with a sticker carrying a different one. Nothing else changes. The artwork is genuine, the product is genuine, the shelf is genuine, and a well cut label sitting inside the quiet zone is close to invisible at arm's length. This is the attack that makes people uneasy, and it is worth being exact about where it has actually been seen.

Drift, the digital failure

The printed code is untouched and entirely legitimate, and what sits at the other end of it stops being trustworthy. A domain lapses and is re-registered by someone else. A subdomain keeps pointing at decommissioned infrastructure. A shortener account changes hands, or the shortener shuts down. The agency that registered the domain during a campaign is no longer your agency. Packaging stays in circulation for years, while the commercial arrangement behind a web address rarely lasts that long. Drift needs no attacker at the beginning, only an opportunist at the end, and unlike substitution it is entirely yours to prevent.

What is documented, and what is not

Sticker-over-code tampering is real and it has been reported by named institutions. The FBI issued a public service announcement in January 2022 on criminals tampering with QR codes to steal victim funds, and its physical guidance is specifically about checking that a code has not had a sticker placed on top of it. Several United States cities found exactly that on parking infrastructure over the same winter: San Antonio identified fraudulent stickers on a large number of meters in late 2021, and Austin subsequently checked its own pay stations and found them on a few dozen. The FTC published a consumer alert in December 2023 describing the same pattern, again on parking meters. It has appeared at other unattended payment points too, including EV charging stations, where at least one US utility has warned that stickers were added to its chargers.

What none of that establishes is a pattern on retail product packaging. We are not aware of an established pattern of stickers being applied over QR codes on consumer packaged goods on a shop shelf, and we are not going to imply one in order to make this page feel more urgent. The honest characterisation is that this is a foreseeable risk rather than a current one. The mechanism transfers cleanly, the economics are less attractive than they are at a payment point, and the right posture is the one you take toward a risk you expect to meet rather than one you are already meeting.

The statistic that keeps getting misapplied

You will see confident figures about QR code phishing rising by some large percentage. Read what they measure before you repeat them. Almost all of them count QR codes as a share of phishing email payloads: an image embedded in a message to get a malicious link past a filter that scans text. That is a real and well measured phenomenon, and not the same one as a sticker in a grocery aisle. Nothing about the volume of quishing email tells you how often a printed code on a pack gets covered, which is why this page quotes none of those figures. The same care applies to the FBI's 2025 advisory about unsolicited packages containing QR codes: those arrive in the post, and no code a brand printed is replaced.

What a GS1 Digital Link changes, and what it does not

A GS1 Digital Link URI is an ordinary web address that carries the product identifier in its path: a hostname you control, the application identifier for a GTIN, then the GTIN itself. The difference from an opaque shortened link is not cryptographic. It is that the address is legible.

A shopper who sees your own domain resolve after scanning your pack has a reference point. A shopper who sees a seven character shortened link has nothing, because every shortened link looks like every other one, including the hostile one. Printed underneath the symbol, a readable address makes a substituted sticker something that can in principle be noticed, and it makes a claim about where the code should go that is falsifiable rather than unverifiable.

Now the honest limit. This raises the bar and it does not eliminate the attack. Someone producing convincing stickers can register a lookalike domain and print a readable address differing from yours by one character, which is exactly the failure mode the FBI advisory describes. Most shoppers never read a URL at all. And a Digital Link is not signed: nothing in the standard lets a phone prove the code on the pack is the code the brand printed. Anyone telling you that adopting Digital Link solves packaging security is describing a benefit that does not exist. What it buys is narrower and still worth having, which is that noticing becomes possible.

What a brand actually controls

Every item here is a decision you can make alone, without a retailer, a standards body or a shopper cooperating. That is the test for inclusion. Most are cheap and most are settled at the artwork stage, which is why they belong in the packaging conversation rather than a separate security project. The order to do this work in is on the migration guide.

  • Own the printed domain outright. Registered to your company, not an agency or a vendor, with registrar lock on and renewal owned by someone who will still be here in five years.
  • Make the address human readable. A shopper can only compare a destination against something if the printed form is legible at all.
  • Do not put a third-party shortener on packaging. It is unreadable by design, and it puts a dependency you do not control inside artwork that stays in circulation for years.
  • Keep the destination on one domain across the catalogue. Consistency is what makes an exception visible. If eleven products resolve to your domain and the twelfth does not, that is a question worth asking.
  • Keep the redirect chain short and yours. Every hop between the scan and the page is somewhere ownership can change quietly. Count the hops you have, not the ones you designed.
  • Price the downside by category. A substituted promotion costs you a bad afternoon. A substituted allergen or dosage page is a conversation for your regulatory people first.

The last point is worth pressing. In a regulated category the destination behind a code is not marketing, and a shopper reaching a page that appears to carry your allergen or dosage information and does not is a different kind of harm. What each regime expects of on-pack digital information differs by market, and that belongs with the EU, Canada and US readiness pages rather than here.

What a brand does not control

This section exists because the previous one is incomplete without it, and because a security page listing only defences is an advertisement in a lab coat.

  • You cannot stop a sticker. Anyone can walk into a store with an adhesive label. No printing decision and no platform prevents that, and a vendor implying otherwise is selling something.
  • You cannot make shoppers check. Most people scan and tap without reading the address, and a control that assumes vigilance is not a control.
  • You do not control the scanning surface. Whether the destination is shown before the page opens, and for how long, is decided by the phone camera or the scanner app.
  • You do not control what happens after the tap. Once a shopper is on a page that is not yours, nothing you printed is still in play.

Together these set a realistic objective. You will not prevent substitution, because the physical act sits outside any system you operate. You can make it harder to perform convincingly, likelier to be noticed, and quicker to answer. Detection and response rather than prevention is the right frame here, and it is also the frame that keeps the effort proportionate to a threat that has not yet shown up in your category.

The other side of the gap

Everything above works on the printing side. The same gap can be closed from the scanning side, by a reader that shows a destination and says something about it before the page opens rather than after. That puts evaluation back in front of action, which is the property the printed symbol took away.

Disclosure: we publish one

QRbolt publishes a consumer scanner at qrbolt.app, free on iOS and Android. It scans a QR code and shows a safety check on the destination before you tap through to it, and it also reads ordinary retail barcodes and surfaces information about the product. It is ours, so read that as a disclosure rather than a recommendation: a safety check is a judgement about a destination and not a guarantee about one, no scanner catches everything, and a lookalike domain that nothing has reported yet will look unremarkable to any of them.

If a code on your product is tampered with

Start with the uncomfortable part, because it changes the plan. You will almost certainly not detect this yourself. It arrives as a customer contact, a social media post or a call from a retailer, some time after it started.

What your resolver logs will and will not tell you

They will not tell you a sticker exists. Stated flatly: a scan of a substituted code never reaches your resolver at all, because the shopper went somewhere else entirely. Your logs record the scans that arrived, not the ones that were taken. What they can offer is an absence, and a weak one. A product with steady scan volume going quiet in one region while the rest of the catalogue does not is worth a look, but it is a soft signal with many innocent explanations, and treating it as an alarm will produce mostly false ones.

What to do, in order

  1. Preserve the physical evidence before anyone peels it off. Photograph it in place, on the shelf, with the store identifiable. The instinct of whoever finds it is to peel it off, which destroys the only artefact anyone can examine.
  2. Capture the destination without interacting with it. The full URL and any redirects. Nobody should enter credentials or payment details to find out what a hostile page does.
  3. Tell the retailer, at the store and above it. The store can check its other facings the same afternoon. Head office can check other stores, which is the only containment that scales.
  4. Report it to the authority that collects this. In the United States, the FBI Internet Crime Complaint Center and the FTC. In Canada, the Canadian Anti-Fraud Centre. Reporting is also how the frequency question below eventually gets an answer.
  5. Chase the destination through its registrar and host. A lookalike domain usually sits with a registrar that has an abuse process, and a takedown is often faster than anything on the packaging side.
  6. Decide in advance who owns the answer. The report lands in a customer service inbox. With no named path from there to someone with authority over the domain, it sits there.

The last of these is the only one that has to happen before anything goes wrong, and it is the one most often missing. The rest a competent team can do on the day. A named owner is not.

What this page is not certain about

An honest reference should say where its own edges are.

The frequency question is the largest gap and the one that matters most. This page says tampering is not an established pattern on retail packaging, and the basis for that is an absence of published incidents rather than evidence of absence. Retail fraud is under-reported, a substituted sticker may never be attributed to anything in particular, and a shopper who lost money after scanning a pack has no obvious place to say so. If the pattern is emerging, a page written today would look exactly like this one. That cuts against the reassurance as much as it cuts against alarm.

The advisories cited here are dated and their agencies update them. The FBI and FTC material is summarised rather than quoted, and should be read at the source before it is relied on. Nothing here is legal advice or a security assessment of your packaging, supply chain or resolver. The detection and response posture above is a judgement about proportionality rather than a standard, and a brand with a genuinely high-value counterfeiting problem should expect to be told to do more by people who specialise in it.

Related reading: the migration guide for the order this work belongs in, the bilingual packaging page for how a resolver decides what to serve, the glossary for terminology, and the overview for what Sunrise 2027 is and is not.

Where we stand

QRbolt sells a platform for GS1 Digital Link QR codes and publishes the consumer scanner named above, so we have a commercial interest in both halves of this subject, stated openly rather than buried. That interest is also why this page declines to call packaging tampering a present danger: the version of this argument that would sell more software is the version that is not supportable. QRbolt is listed by GS1 Canada as a solution provider, which is a directory listing rather than an endorsement or a certification of this platform.