Are QR code business cards safe?
A QR code is just an encoded link, so the safety question is really about where it points and who holds your data. The real risks, and the habits that neutralize them.
Yes, QR code business cards are safe to use, with one caveat that does all the work: a QR code is not content, it is an address. Scanning one is the equivalent of clicking a link. The security question is never about the black-and-white square, it is about where the link goes and who runs the destination.
That caveat matters because scammers noticed the same thing. Quishing, QR phishing, works by getting people to scan codes that lead to convincing fake pages. Security agencies have logged campaigns using stickers pasted over legitimate codes on parking meters, restaurant tables, and conference signage.
None of that makes a QR business card risky in itself. It makes the habits around it worth understanding. Below: how the attacks actually work, how to scan safely in five seconds, and what to check about the platform hosting your own card.
What a QR code actually contains
A QR code is a visual encoding of a short piece of text, almost always a URL. It cannot execute code, install anything by itself, or read data off your phone. When you scan one, your camera decodes the text and offers to open it. Everything that happens next is ordinary web browsing.
This is good news for business cards specifically. A card QR code points at a card profile page: a name, a title, contact details, and a save-to-contacts button. There is no payment step, no login, and no credential entry in a legitimate flow, which means there is very little for an attacker to imitate profitably.
You would glance at the domain before clicking a link from a stranger. Same instinct, same protection. Every modern phone shows you the destination URL before opening it.
Programmez le rappel pendant que la conversation est encore fraîche.
The real risks, honestly stated
Quishing: codes that lead to fake pages
The dominant attack. A code in a public place leads to a page impersonating a bank, a parking service, or a login screen, and asks for credentials or card details. It works through the page, not the code, which is why the destination check defeats it.
Sticker tampering on printed materials
Attackers physically cover a legitimate printed code with their own. This is a risk for public signage and posters. It is a negligible risk for a business card exchange, where the code is on a person's phone screen or on a card they hand you directly.
Look-alike domains
A destination that reads almost right at a glance, using a hyphen, an extra word, or a different suffix. This is why the preview is worth reading rather than glancing at.
Oversharing on your own card
The risk that applies to you rather than to your scanner. Anything you put on a card that has a public URL is public. That is the point of the card, but it means your personal mobile number is a deliberate choice, not a default.
How to scan safely in five seconds
- Read the URL preview before tapping. Your phone shows it; the whole attack class depends on you not looking.
- Check the domain, not the path. The part right before the first single slash is what matters.
- Be suspicious of any card code that asks you to log in or enter payment details. A business card exchange never needs either.
- On printed materials in public places, feel for a sticker edge over the code. On a card handed to you in conversation, this risk effectively disappears.
- Keep your phone updated. Browser and OS updates carry the phishing protections that catch known bad destinations.
That is the entire discipline. It costs a couple of seconds and removes almost all of the practical risk, which is why security teams treat QR codes as a manageable everyday technology rather than something to avoid.
What to check about the platform behind your card
When you share a QR business card, you are also asking people to trust the service hosting it, and you are trusting it with the contacts you collect. Worth checking before you commit:
Encryption in transit and at rest
Your data should be encrypted both while moving and while stored. ConnectMachine encrypts data in transit and at rest.
A clear answer on selling data
Contact data is valuable, and some free services monetize it. ConnectMachine does not sell your data, and your contacts are private by default.
A recognizable, stable domain
Your card should live at a domain recipients can read and trust in the preview. Every ConnectMachine card has a public browser URL you can share directly, which also means people can reach your card without scanning anything at all.
Regulatory posture
Check that the service is GDPR compliant and offers data localization if you work in regions where that matters.
Protecting your own privacy while sharing
The safety conversation usually focuses on the person scanning. The more useful question for you is what your card reveals, since a card exists to be handed to people you have just met.
- Decide deliberately about your mobile number. A work number, a scheduling link, or an email address is often enough to keep a conversation going.
- Put your credentials and license details on the card if your profession expects them, since that is exactly the kind of information people want to verify.
- Remember that the card page is public by design, while the contacts you collect should not be. Keep those two things separate in your mind, and check that your platform does too.
- Download your QR code as a print-ready file if you want it on physical materials, and treat anything printed as permanent, because you cannot recall a printed card.
The bottom line
QR code business cards are safe for both sides of the exchange. For the scanner, the destination preview neutralizes the one attack class that matters. For the sharer, the questions worth asking are about the platform, encryption, data handling, and a trustworthy domain, rather than about the code itself.
The risk profile is genuinely lower than the alternative it replaced. A paper card in a stranger's pocket has no preview, no revocation, and no idea where it ends up.
Frequently asked questions
Can scanning a QR code give you a virus?
What is quishing?
Is it safe to scan a QR code business card from someone I just met?
Is my information safe on a QR business card?
Are QR codes safer than NFC cards?
How do I check where a QR code goes before opening it?
Private by default