Information Security

Protect Yourself From Malicious QR Codes

QR codes offer a fast and convenient way to access websites, applications, payments, and other online services. However, cybercriminals increasingly use them in phishing attacks to direct users to fraudulent websites that steal credentials, collect sensitive information, or install malicious software.

Unlike traditional links, QR codes conceal the destination website until they’re scanned, making it harder to identify suspicious sites. Malicious QR codes may be distributed through emails, text messages, social media, printed materials, or by placing stickers over legitimate QR codes in public locations.

If you use your USPS® mobile device to scan QR codes, always pause and verify before proceeding. One scan could expose personal information, login credentials, or sensitive Postal Service™ data.

To help protect Postal Service information, follow these CyberSafe at USPS® tips:

n Scan QR codes from trusted sources only.

n Preview the website address before opening the link, if your device allows it.

n Avoid sharing your USPS credentials if a login screen or password prompt appear.

n Look for stickers or labels that may’ve been placed over legitimate codes.

n Report suspicious QR codes or websites through established cybersecurity reporting procedures.

For more information about additional security best practices and resources, go to the CyberSafe at USPS Blue page at blue.usps.gov/cyber/.