Security and the 2D barcode transition
A QR code is a printed address nobody can read before they arrive at it. That single property is the entire security question, and it is narrower than the one most articles on the subject answer. This page separates what is documented from what is merely plausible, then sets out which parts of the problem a brand owner actually decides.
QR codes are not inherently unsafe. The symbol is a public, well documented encoding with no secrets in it. The problem is one step earlier. When a shopper reads a printed word, they can evaluate it before acting on it. When they point a camera at a square of black and white, evaluation and action collapse into one gesture, because what is encoded stays opaque until it has already resolved.
Two distinct failures live inside that property, and conflating them is how most security writing on this topic goes wrong.
Someone covers a legitimate printed code with a sticker carrying a different one. Nothing else changes. The artwork is genuine, the product is genuine, the shelf is genuine, and a well cut label sitting inside the quiet zone is close to invisible at arm's length. This is the attack that makes people uneasy, and it is worth being exact about where it has actually been seen.
The printed code is untouched and entirely legitimate, and what sits at the other end of it stops being trustworthy. A domain lapses and is re-registered by someone else. A subdomain keeps pointing at decommissioned infrastructure. A shortener account changes hands, or the shortener shuts down. The agency that registered the domain during a campaign is no longer your agency. Packaging stays in circulation for years, while the commercial arrangement behind a web address rarely lasts that long. Drift needs no attacker at the beginning, only an opportunist at the end, and unlike substitution it is entirely yours to prevent.
Sticker-over-code tampering is real and it has been reported by named institutions. The FBI issued a public service announcement in January 2022 on criminals tampering with QR codes to steal victim funds, and its physical guidance is specifically about checking that a code has not had a sticker placed on top of it. Several United States cities found exactly that on parking infrastructure over the same winter: San Antonio identified fraudulent stickers on a large number of meters in late 2021, and Austin subsequently checked its own pay stations and found them on a few dozen. The FTC published a consumer alert in December 2023 describing the same pattern, again on parking meters. It has appeared at other unattended payment points too, including EV charging stations, where at least one US utility has warned that stickers were added to its chargers.
What none of that establishes is a pattern on retail product packaging. We are not aware of an established pattern of stickers being applied over QR codes on consumer packaged goods on a shop shelf, and we are not going to imply one in order to make this page feel more urgent. The honest characterisation is that this is a foreseeable risk rather than a current one. The mechanism transfers cleanly, the economics are less attractive than they are at a payment point, and the right posture is the one you take toward a risk you expect to meet rather than one you are already meeting.
You will see confident figures about QR code phishing rising by some large percentage. Read what they measure before you repeat them. Almost all of them count QR codes as a share of phishing email payloads: an image embedded in a message to get a malicious link past a filter that scans text. That is a real and well measured phenomenon, and not the same one as a sticker in a grocery aisle. Nothing about the volume of quishing email tells you how often a printed code on a pack gets covered, which is why this page quotes none of those figures. The same care applies to the FBI's 2025 advisory about unsolicited packages containing QR codes: those arrive in the post, and no code a brand printed is replaced.
A GS1 Digital Link URI is an ordinary web address that carries the product identifier in its path: a hostname you control, the application identifier for a GTIN, then the GTIN itself. The difference from an opaque shortened link is not cryptographic. It is that the address is legible.
A shopper who sees your own domain resolve after scanning your pack has a reference point. A shopper who sees a seven character shortened link has nothing, because every shortened link looks like every other one, including the hostile one. Printed underneath the symbol, a readable address makes a substituted sticker something that can in principle be noticed, and it makes a claim about where the code should go that is falsifiable rather than unverifiable.
Now the honest limit. This raises the bar and it does not eliminate the attack. Someone producing convincing stickers can register a lookalike domain and print a readable address differing from yours by one character, which is exactly the failure mode the FBI advisory describes. Most shoppers never read a URL at all. And a Digital Link is not signed: nothing in the standard lets a phone prove the code on the pack is the code the brand printed. Anyone telling you that adopting Digital Link solves packaging security is describing a benefit that does not exist. What it buys is narrower and still worth having, which is that noticing becomes possible.
Every item here is a decision you can make alone, without a retailer, a standards body or a shopper cooperating. That is the test for inclusion. Most are cheap and most are settled at the artwork stage, which is why they belong in the packaging conversation rather than a separate security project. The order to do this work in is on the migration guide.
The last point is worth pressing. In a regulated category the destination behind a code is not marketing, and a shopper reaching a page that appears to carry your allergen or dosage information and does not is a different kind of harm. What each regime expects of on-pack digital information differs by market, and that belongs with the EU, Canada and US readiness pages rather than here.
This section exists because the previous one is incomplete without it, and because a security page listing only defences is an advertisement in a lab coat.
Together these set a realistic objective. You will not prevent substitution, because the physical act sits outside any system you operate. You can make it harder to perform convincingly, likelier to be noticed, and quicker to answer. Detection and response rather than prevention is the right frame here, and it is also the frame that keeps the effort proportionate to a threat that has not yet shown up in your category.
Everything above works on the printing side. The same gap can be closed from the scanning side, by a reader that shows a destination and says something about it before the page opens rather than after. That puts evaluation back in front of action, which is the property the printed symbol took away.
QRbolt publishes a consumer scanner at qrbolt.app, free on iOS and Android. It scans a QR code and shows a safety check on the destination before you tap through to it, and it also reads ordinary retail barcodes and surfaces information about the product. It is ours, so read that as a disclosure rather than a recommendation: a safety check is a judgement about a destination and not a guarantee about one, no scanner catches everything, and a lookalike domain that nothing has reported yet will look unremarkable to any of them.
Start with the uncomfortable part, because it changes the plan. You will almost certainly not detect this yourself. It arrives as a customer contact, a social media post or a call from a retailer, some time after it started.
They will not tell you a sticker exists. Stated flatly: a scan of a substituted code never reaches your resolver at all, because the shopper went somewhere else entirely. Your logs record the scans that arrived, not the ones that were taken. What they can offer is an absence, and a weak one. A product with steady scan volume going quiet in one region while the rest of the catalogue does not is worth a look, but it is a soft signal with many innocent explanations, and treating it as an alarm will produce mostly false ones.
The last of these is the only one that has to happen before anything goes wrong, and it is the one most often missing. The rest a competent team can do on the day. A named owner is not.
An honest reference should say where its own edges are.
The frequency question is the largest gap and the one that matters most. This page says tampering is not an established pattern on retail packaging, and the basis for that is an absence of published incidents rather than evidence of absence. Retail fraud is under-reported, a substituted sticker may never be attributed to anything in particular, and a shopper who lost money after scanning a pack has no obvious place to say so. If the pattern is emerging, a page written today would look exactly like this one. That cuts against the reassurance as much as it cuts against alarm.
The advisories cited here are dated and their agencies update them. The FBI and FTC material is summarised rather than quoted, and should be read at the source before it is relied on. Nothing here is legal advice or a security assessment of your packaging, supply chain or resolver. The detection and response posture above is a judgement about proportionality rather than a standard, and a brand with a genuinely high-value counterfeiting problem should expect to be told to do more by people who specialise in it.
Related reading: the migration guide for the order this work belongs in, the bilingual packaging page for how a resolver decides what to serve, the glossary for terminology, and the overview for what Sunrise 2027 is and is not.
QRbolt sells a platform for GS1 Digital Link QR codes and publishes the consumer scanner named above, so we have a commercial interest in both halves of this subject, stated openly rather than buried. That interest is also why this page declines to call packaging tampering a present danger: the version of this argument that would sell more software is the version that is not supportable. QRbolt is listed by GS1 Canada as a solution provider, which is a directory listing rather than an endorsement or a certification of this platform.