How to create secure QR Codes for your customers

Published in July 2026 • 8 min read

How to create secure QR Codes for your customers

QR Codes have become ubiquitous in Brazilian daily life — from payments via Pix to restaurant menus, event tickets and corporate badges. However, as the technology became more popular, the security risks associated with it also grew. Scammers have already learned to exploit QR Codes to direct victims to fake phishing sites, install malware on cell phones or steal bank details.

In this article, we will explain the real risks of QR Codes, the crucial difference between static and dynamic QR Codes from a security perspective, and how you can protect your customers by generating reliable and transparent codes.

How scammers use QR Codes for fraud

The most common attack using QR Codes is called "QRishing" (a combination of "QR" and "phishing"). It works like this:

  1. The scammer generates a QR Code that points to a fake website that imitates a well-known bank, store or service.
  2. The fake QR Code is pasted on top of a legitimate QR Code in a public place (such as a payment terminal, parking totem or restaurant table).
  3. The victim scans the code thinking it is legitimate and ends up on a phishing site where they enter personal data, passwords or banking information.

Another common attack involves QR Codes that direct to automatic downloads of malicious applications or that exploit cell phone browser vulnerabilities to silently install spyware.

Static vs Dynamic QR Code: Security

Understanding the difference between these two types is essential for security:

Static QR Code

Contains the destination URL encoded directly into the code's visual pattern. When the user scans, the cell phone decodes the pattern and shows the full URL before opening. The user can see exactly where the link goes (for example, https://seurestaurante.com.br/cardapio).

Security advantage: Total transparency. The destination is visible before the click. It does not depend on any intermediary service. If the URL is from your business domain, the customer knows it is legitimate.

Dynamic QR Code

Contains an intermediate URL (usually from a third-party service like bit.ly, qr-code-generator.com, etc.) that redirects to the final destination. The URL the user sees when scanning is something like https://qr.servico.com/abc123 — they don't know where they will be redirected until they click.

Security risk: If the intermediary service is compromised, or if someone with access to the control panel changes the destination, all printed QR Codes will redirect to a different website — potentially malicious. Furthermore, if the service closes or the plan expires, the QR Code simply stops working.

Good security practices with QR Codes

To protect your customers and your business’s reputation, follow these recommendations:

For establishments with Pix via QR Code

If your business accepts payments via Pix using a printed QR Code, you need to pay extra attention:

Generating safe and free QR Codes

Free Conversion QR Code Generator exclusively creates static QR Codes — the most secure and transparent option available. The generated code contains the destination URL directly, without intermediaries, without third-party tracking and without an expiration date. It works forever and your customer will always see exactly where the link leads before opening it.

Furthermore, the entire generation process happens locally in your browser. No data is sent to our servers. Not even we know which QR Codes you are generating — your privacy is complete.

Conclusion

QR Codes are powerful and practical tools, but they need to be used responsibly. Always opt for static QR Codes from domains you control, check your physical codes regularly, use HTTPS, and educate your customers on how to check links before entering personal data. With these simple precautions, you protect your customers and the credibility of your business.