Skip to content
VixQR

By the VixQR team · published on · 9 min read

QR Code Statistics 2026: The Numbers, and Which Ones to Trust

Market size, scan volumes, security incidents and regulation — the 2026 QR code figures worth citing, with an honest note on where each number comes from.

A dashboard of charts showing QR code adoption, scan volumes and market growth figures

Every QR code statistics roundup has the same problem: it dumps forty numbers without telling you that half of them come from companies selling QR code subscriptions.

That matters. A vendor survey of its own customers reporting that 98% of marketers see positive results is not the same category of evidence as Microsoft's telemetry on billions of emails. Both can appear in the same listicle, formatted identically, and you'd never know.

So this roundup does something slightly unusual: it groups the figures by how much weight they can carry, and says plainly where each one comes from.

How to read any QR statistic

Three tiers, roughly.

Measured telemetry. Someone counted actual events in a system they operate — emails processed, scans served, attacks detected. Microsoft's threat intelligence, platform scan data, government registries. These are the strongest numbers, though they only describe that platform's slice of the world.

Market research. Firms like Mordor Intelligence and eMarketer build models from company filings, surveys and extrapolation. Directionally useful, precise-looking, and different firms routinely disagree by wide margins on the same market.

Vendor surveys and self-reported results. A company surveys its users or its market and publishes the findings. Genuinely informative about sentiment, close to worthless as a measure of effect — particularly for any claim about performance uplift, where the vendor has an obvious interest in the answer.

I'll flag which is which as we go. Use the tier, not just the number.

Market size and growth

$15.23 billion — the estimated global QR code market value in 2026, projected to reach $33.14 billion by 2031 at a 16.82% CAGR (market research, Mordor Intelligence). The same source puts 2025 at $13.04 billion.

17.03% — an alternative CAGR estimate for 2026–2030 from a separate model (market research).

Treat both as an indication that the market is growing at a healthy double-digit rate, not as a forecast you can plan a budget against. The gap between two credible models over the same period tells you how much precision is really available here.

64.92% — the share of QR code format revenue attributed to dynamic (subscription) codes (market research).

That figure deserves a footnote, because it's easy to misread. It measures revenue, not usage. Static codes are free, so they generate essentially no revenue no matter how many exist. A statistic showing dynamic codes dominating revenue tells you about the business model, not about what most people actually use.

Scan volume and adoption

~1 trillion — QR codes scanned globally across 2025, roughly 2.7 billion per day (aggregated platform estimates).

102.6 million — Americans projected to scan a QR code in 2026 (market research, eMarketer).

75% — restaurants worldwide reported to use QR codes in some form (vendor survey).

The scan volume figures are aggregations across platforms and inherently approximate — no single entity counts every scan, because static codes scanned by a native camera app are counted by nobody at all. That's worth remembering: the true total is structurally unmeasurable, and every published figure undercounts static usage.

Payments

$3 trillion — annual spending flowing through QR code payment systems (market research).

This is the single largest QR use case by value and it's overwhelmingly concentrated in Asia — China and India in particular, where QR payments are default infrastructure rather than a novelty. Western coverage consistently underweights it, which distorts the picture: globally, QR codes are primarily a payments technology that also does marketing, not the other way round.

Marketing usage and effectiveness

This is the section where the sourcing matters most, because nearly all of it is vendor-generated.

98% — marketers reporting a positive impact from QR codes (vendor survey, Uniqode 2026, based on 524 marketers, 1,000 consumers and an analysis of 188 million scans).

12% — marketers who measure the direct revenue impact of their QR campaigns (same survey).

Put those two side by side and the interesting story emerges. Ninety-eight percent report a positive impact; twelve percent measure revenue. Which means the overwhelming majority of that positive sentiment is not based on revenue measurement. It's based on scan counts.

Scan counts are a vanity metric unless connected to an outcome. We wrote about how to actually connect them — for free — in tracking QR codes without a subscription.

84% — marketers planning to integrate AI with QR code campaigns (vendor survey).

25–40% — claimed increase in scan rates for branded or AI-designed codes versus plain ones (vendor claim).

Be sceptical of that last one. It compares a deliberately designed asset against an undesigned one, which measures design effort and placement as much as it measures the code's appearance. It's also exactly the number a company selling design tools would want to be true. We looked at what actually holds up in AI and artistic QR codes.

Security

The security figures come from the strongest sources in this article — security vendors and platform operators measuring attacks they detected — and they're the most volatile.

7.6 million → 18.7 million — monthly QR code phishing attacks from January to March 2026, a 146% increase (measured telemetry, Microsoft Threat Intelligence). March was the highest monthly volume in at least a year.

8.3 million — monthly volume by June 2026, after three consecutive months of decline (same source).

That second number is the one almost every roundup omits, and it changes the story completely. QR phishing did not climb relentlessly through 2026. It spiked, then fell back to mid-2025 levels following the disruption of a major phishing-as-a-service platform, whose linked volume dropped 92% from its pre-disruption baseline.

Anyone citing the +146% without the subsequent decline is quoting a peak as a trend.

Other figures worth having:

70% — malicious PDFs containing QR codes; 56% for malicious Microsoft 365 documents (measured, Barracuda, from an analysis of over 3.1 billion emails).

73% — users who scan QR codes without verifying the destination (survey research).

~400% — increase in image-based phishing attacks heading into 2025 (Anti-Phishing Working Group).

12–12.4% — share of all phishing incidents now using image-based payloads (security research).

90% — high-volume phishing campaigns using phishing-as-a-service kits in 2025, up from 30% in 2024 (measured, Barracuda). This is arguably the most consequential number in the security section: it's the industrialisation of phishing, and QR lures are one feature among many in those kits.

34% — organisations experiencing at least one account takeover incident per month (measured).

The defensive implications are in quishing at work.

Regulation — the numbers that will matter most

These are the hardest figures in the whole article, because they're dates in published legislation rather than estimates.

18 February 2027 — the date a digital product passport becomes mandatory for EV batteries, light-transport batteries and industrial batteries above 2 kWh placed on the EU market (EU Batteries Regulation 2023/1542). This is the first firm DPP deadline and it will not move.

20 July 2026 — the date the EU's Digital Product Passport Registry went live (European Commission).

10 years — the minimum period manufacturers must maintain DPP data after a product is placed on the market (ESPR, Regulation (EU) 2024/1781).

31 December 2027 — the GS1 Sunrise 2027 target for retail point-of-sale systems to read 2D barcodes, covering 48 countries representing roughly 88% of global GDP (GS1).

If you only track one section of this article, track this one. Market forecasts drift; legislated dates don't. Between them, these commitments will put a QR code on a very large share of physical products sold in Europe within a few years — background in our guides to GS1 Sunrise 2027 and the EU Digital Product Passport.

Adoption by sector

Sector-level figures are patchier than headline market numbers, and much of what circulates is vendor survey data. What can be said with reasonable confidence:

Hospitality is the most saturated consumer-facing sector, with roughly 75% of restaurants worldwide using QR codes in some capacity (vendor survey) — menus overwhelmingly, then ordering, payment and reviews.

Pharmaceutical is further ahead than most people realise, and for regulatory rather than marketing reasons. The EU Falsified Medicines Directive and US DSCSA already mandate 2D codes on prescription packaging. That existing infrastructure is why pharma is well positioned for the digital product passport wave — the codes are already there; the work is extending what they resolve to.

Food and beverage is the largest category by sheer number of product lines and the earliest mover on GS1 Digital Link piloting. EU wine labelling rules already require a digital carrier for nutrition and ingredient information.

Cosmetics is running ahead of the official retail timeline, driven by ingredient-transparency expectations, with public pilots from several of the largest groups.

Education shows up mainly in the security data, unfortunately: Microsoft's threat reporting has flagged well over 15,000 QR-bearing phishing emails per day targeting the education sector alone (measured telemetry). Large user populations, limited security budgets, and a culture of scanning codes on campus signage.

What's missing from almost every sector breakdown is small business, which is probably the largest user base by headcount and the smallest by revenue — precisely because those codes are free and therefore invisible to the vendors doing the counting.

Consumer behaviour

102.6 million Americans projected to scan a QR code during 2026 (market research, eMarketer).

~2.7 billion scans per day globally (aggregated platform estimates).

73% scan without verifying the destination first (survey research).

That last figure is the one worth sitting with, because it cuts both ways. It's the reason quishing works. It's also, less comfortably, the reason QR codes work at all commercially — a technology that required everyone to carefully inspect a URL before proceeding would have far lower conversion than the one we actually have.

The honest reading is that QR codes trade verification for friction reduction, and that trade is the product. Security guidance that asks users to reverse it is fighting the mechanism that makes the thing useful. This is why the effective defences are architectural rather than behavioural — a point we go through in quishing at work.

What the numbers don't tell you

Four things worth holding onto.

Static usage is invisible. Every scan figure in existence undercounts, because a static code opened by a native camera app leaves no trace on any platform's dashboard. The measurable share of the QR world is the commercial share, which is not the same as the actual share.

Scan counts aren't outcomes. The 98%-positive / 12%-measuring gap is the whole problem in miniature. A hundred scans that bounce are worth less than one that converts.

Regional skew. Most English-language statistics describe North America and Western Europe. The largest QR ecosystem by volume and value is in Asia, and it behaves differently — payments-first, app-mediated, far higher per-capita usage.

Security volume is not security risk. Attack volume fell sharply in Q2 2026. The structural weakness that makes the attack work — the scan executing on an unmanaged device — did not change at all. Volume responds to enforcement; architecture doesn't.

Nobody separates print from screen. Almost every published figure lumps together codes scanned off paper and codes scanned off a display, despite those being different behaviours with different failure rates and different design constraints. If you're deciding how to spend a print budget, no public statistic answers your actual question.

The short version

  • The market is growing at roughly 16–17% a year, on models that disagree with each other.
  • Roughly a trillion scans a year, undercounted, concentrated in payments.
  • Marketing sentiment is overwhelmingly positive and almost entirely unmeasured.
  • QR phishing spiked hard in early 2026 and then fell back after a platform takedown.
  • The genuinely load-bearing numbers are the regulatory dates, and they're close.

If you cite any of these, cite the tier along with the figure. A number is only as useful as the method behind it — and in this field, that method is usually a press release.


Figures compiled August 2026 from publicly available sources including Microsoft Threat Intelligence quarterly email threat reports, Barracuda email threat research, Mordor Intelligence and eMarketer market estimates, vendor industry surveys, GS1 published guidance and EU regulatory texts. Market projections are models, not measurements; vendor survey figures reflect self-reported sentiment. Verify against the primary source before using any figure in your own work.

All articles

QR Code Statistics 2026: The Numbers, and Which Ones to Trust | VixQR