QR Code Security Report 2026: What QRLynx Flagged in 754 URLs


Key Takeaway
QRLynx screening data from 754 URL-type QR submissions: 12.7% required review, why a flag is not a malware verdict, and how to protect each QR campaign.
Direct answer: 12.7% required review, not 12.7% confirmed malicious
In a fixed cohort of 754 URL-type QR submissions created from December 2025 through April 2026, 658 passed QRLynx automated screening on first assessment and 96 required additional review. That is an 87.3% initial pass rate and a 12.7% review rate. A review flag is a precautionary platform result. It can reflect a young domain, failed DNS resolution, an unavailable age signal, an account review, or a stronger risk signal. It is not by itself proof of phishing, malware, or criminal intent.
Read the report with the correct denominators
| Measure | Cohort or scope | What it supports |
|---|---|---|
| Initial URL screening | 754 URL-type QR submissions | The 87.3% pass rate and 12.7% review rate |
| Risk-score distribution | The same frozen screening cohort | The share of records in each automated score band, not a confirmed-malware rate |
| Domain-age analysis | The new-domain flags inside the cohort | How recently those flagged domains had been registered |
| Platform scan scale | More than 5 million scans processed during the reporting window | Operational context only; the scans were not 5 million independently screened destination URLs |
| Deactivated-code events | A separate production event dataset captured for the original report | Evidence that a printed code can continue receiving attempts after its redirect is disabled |
Methodology and frozen-cohort policy
The report covers URL-type QR records created from December 1, 2025 through April 30, 2026. The screening result and risk score were analyzed as they existed for the original report. Later DNS repairs, manual reviews, destination changes, and scheduled rechecks can change a QR record's current status, so a present-day database query is not a substitute for the frozen first-assessment cohort.
The report measures platform screening outcomes, not the prevalence of malicious QR codes across the internet. It does not estimate how many printed QR codes are fraudulent, how many people encountered a scam, or how many flagged destinations were later confirmed abusive. Percentages apply only to the stated QRLynx cohort.
QRLynx screens supported external-URL QR destinations during creation. Internal-content and non-URL payload types follow different validation paths. Dynamic destinations can also be rechecked later, which is why current status and historical first-assessment status must remain separate.
Initial screening results in the 754-URL cohort
| Result | Share | Interpretation |
|---|---|---|
| Passed initial screening | 87.3% | The destination cleared the checks applied at assessment time |
| Required additional review | 12.7% | One or more checks could not establish the required confidence |
| Risk score 20 or higher | 1.6% | Multiple or stronger automated indicators were present; confirmation still required review |
| Risk score 50 or higher | 0.3% | The strongest score band in this historical model, not a legal or forensic verdict |
| Zero recorded risk indicators | 71.9% | No score-producing indicator was recorded in the cohort assessment |
Monthly first-assessment review rates
| Month | URL submissions | Required review |
|---|---|---|
| December 2025 | 30 | 2 (6.7%) |
| January 2026 | 106 | 0 (0.0%) |
| February 2026 | 91 | 5 (5.5%) |
| March 2026 | 153 | 42 (27.5%) |
| April 2026 | 374 | 47 (12.6%) |
What the monthly variation means
March had the highest review rate in the cohort, but the table is descriptive rather than predictive. The months have different sample sizes, and a flag can represent a precautionary domain or DNS condition rather than confirmed abuse. The result supports keeping review controls active as volume and submission patterns change. It does not prove that QR phishing increased by the same percentage.
Across the complete cohort, newly registered domains were the largest recorded review category. A fresh domain has limited reputation history, which gives an automated system less evidence to evaluate. Legitimate organizations launching a new domain can therefore receive the same precautionary flag as a destination that deserves deeper investigation.
Age of domains flagged for being under 30 days old
| Age at submission | Share of new-domain flags | Cumulative share |
|---|---|---|
| Same day | 25.0% | 25.0% |
| 1 to 7 days | 44.2% | 69.2% |
| 8 to 14 days | 23.1% | 92.3% |
| 15 to 29 days | 7.7% | 100% |
A young-domain flag is a review signal, not a malicious-domain label
Within the historical new-domain subset, 69.2% were less than eight days old and 25.0% were registered on the submission day. Those figures explain why domain age contributed heavily to review volume. They do not show how many of those domains hosted phishing or malware.
A legitimate launch does not need to delay its campaign for an arbitrary number of days. Instead, the owner should verify DNS, confirm the exact HTTPS destination, provide the evidence requested during review, and test the final managed QR before printing. QRLynx can recheck a destination after DNS or reputation evidence changes.
How QRLynx protects a managed URL QR
| Stage | QRLynx control | Owner action |
|---|---|---|
| Creation | Validates the URL and applies the current security checks | Use the final HTTPS destination and review the displayed result |
| Unverified result | Keeps the destination in a precautionary state and can show an interstitial | Check DNS, spelling, domain ownership, and the reason provided |
| Later recheck | Selected active URL QRs can be rescanned as destination evidence changes | Keep the destination controlled and respond to a new warning |
| Abuse report | Accepts reports and supports investigation and takedown | Report the exact code and destination with useful evidence |
| Deactivation | Stops a managed dynamic redirect from reaching its saved destination | Remove or cover the physical code because the printed pattern still exists |
How to secure a business QR campaign in QRLynx
Verify the destination, managed redirect, printed placement, and response process as one system.
Create the final destination first
Publish the intended HTTPS page, verify its certificate and DNS, remove placeholder routes, and confirm that the organization controls the hostname.
Create a managed dynamic URL QR in QRLynx
Choose URL, enter the exact destination, save it as dynamic, and review the creation-time security result before designing the printed asset.
Resolve any review result before printing
Read the verification reason, check the hostname and DNS, correct mistakes, and request or run the appropriate recheck. Treat the flag as a prompt for evidence rather than a malware verdict.
Label and test the complete physical proof
Add a specific action label that states what the scan opens and identifies the organization. Scan the final-size printed proof from representative phones, inspect the URL preview, confirm the QRLynx redirect host, and verify that the correct HTTPS page opens.
Protect the placement
Use clear branding, placement context, tamper-evident materials where appropriate, and routine physical inspection so an added sticker or replacement symbol is easier to notice.
Monitor the campaign
Review scans for the campaign's expected geography and schedule. Investigate material changes using the destination, placement, campaign events, and access logs rather than assuming one unusual scan proves tampering.
Prepare a response path
Know who can update or deactivate the QR, how physical materials will be removed, where abuse will be reported, and which verified company channel customers can use when a destination looks unfamiliar.
Destination verified?
Create and test the managed QR before it reaches print
Run the destination through QRLynx screening, verify the redirect, and keep an editable response path for the campaign.
What happened after deactivation in the original event snapshot
The original report separately recorded 127 or more attempts across deactivated managed codes, an average of 3.3 attempts per affected code, with a maximum of 46 attempts on one code. These events show persistence of the physical symbol. They do not reveal who scanned, why they scanned, or whether an attacker was testing reactivation.
Digital deactivation and physical removal solve different problems. QRLynx can stop its managed redirect from reaching the saved destination. The campaign owner still needs to remove, cover, or replace printed materials and provide a trusted alternative route for legitimate users.
Practical checks for scanners
- Use the context around the QR to decide what action should follow.
- Inspect the URL preview and identify the actual registered domain before opening it.
- For payments, account access, or personal information, open the organization's known app or type its official address independently.
- Do not install an unexpected app, profile, or permission request from an unfamiliar QR journey.
- Check for a sticker or altered label covering the expected code.
- Report suspicious destinations through the organization's verified contact channel and, when relevant, through the FTC or FBI IC3.
The Federal Trade Commission advises checking the URL for misspellings or switched letters and avoiding unexpected QR links. The FBI advises caution with QR codes from unknown origins and unexpected packages.
QRLynx QR security report questions
Does 12.7% flagged mean 12.7% of QR URLs were malicious?
No. In the fixed 754-URL cohort, 12.7% required additional review. A flag can reflect limited domain history, failed DNS resolution, an unavailable signal, an account review, or a stronger risk indicator. Confirmation requires separate evidence.
Were 5 million URLs security-scanned for this report?
No. More than 5 million scans describe QRLynx platform activity during the reporting window. The initial URL-screening cohort contained 754 URL-type QR submissions.
Why can current database totals differ from the report?
The report freezes first-assessment results for records created from December 2025 through April 2026. Later DNS repairs, manual decisions, destination changes, and scheduled rechecks can change each record's current status.
What does a QRLynx security interstitial mean?
It means QRLynx has not established the confidence required for a direct redirect or the owner is under review. The page lets the scanner see the destination and make a more deliberate choice. It is not automatically a confirmed-malware notice.
Can a QR Code itself install malware?
The symbol stores data. The risk comes from what a decoded URL or later instruction asks the scanner to open, download, authorize, disclose, or pay. Treat an unfamiliar QR destination like any unfamiliar link.
Why use a managed dynamic QR for a business URL?
The owner can update the destination, deactivate the managed redirect, review eligible scan activity, and respond without changing the printed pattern. The physical asset still needs inspection and removal when retired.
Does an unusual scan prove that a QR was copied or tampered with?
No. Location, time, and volume can support an investigation but do not identify intent by themselves. Compare the scan with campaign context, destination logs, physical inspection, and other evidence.
Should a legitimate company wait 30 days before using a new domain?
Not as a universal rule. A young domain may receive additional review because it has limited reputation history. Verify DNS and ownership, use the final HTTPS destination, respond to the review evidence, and test before printing.
What should a business do after deactivating a printed QR?
Remove, cover, or replace the physical symbol, update nearby instructions, provide a verified alternative route, and monitor support or abuse reports. Deactivation controls the managed redirect but does not erase printed copies.
How does QRLynx screen URL destinations?
QRLynx applies its current URL validation and security checks to supported external-URL QR destinations during creation and can recheck selected active routes later. Internal-content and non-URL payload types follow different validation paths.
Sources and citation guidance
- QRLynx frozen December 2025 through April 2026 URL-screening cohort and the accuracy-pass record used to publish the original report.
- Current QRLynx URL validation, security scoring, redirect interstitial, scheduled recheck, abuse-report, and deactivated-event implementations.
- FTC: Scammers hide harmful links in QR codes to steal your information.
- FBI: Unsolicited packages containing QR codes used to initiate fraud schemes.
When citing this report, include the 754-URL cohort, December 2025 through April 2026 window, and the distinction between an automated review flag and confirmed abuse.


