Can Someone Reprogram Your NFC Business Card?
Here is a question almost nobody asks before sticking an NFC tag on something public: what stops the next person who walks past from writing their own link onto it?
For most tags sold online, the answer is nothing at all. A blank NTAG sticker is writable by design. Any phone with a free NFC writer app can hold itself against your tag and replace what is on it in about two seconds, with no login, no tools and no trace. If that tag is on a property board outside a house, on a reception desk, or on a table in a venue, that is a real exposure rather than a theoretical one.
Why This Suddenly Matters More
Scanning something in the physical world used to feel safe because the physical world felt accountable. That has changed fast. QR code phishing, now widely called quishing, rose sharply through 2025 and into 2026, and the tactic that made it work was the least technical one available: cover the real code with a sticker carrying a different one.
The consequence is that people have become warier. Roughly four in ten smartphone users now say they hesitate before scanning a code they did not print themselves. If you are asking strangers to tap or scan something you left in a public place, you are asking them to spend trust they are increasingly reluctant to spend.
How a Tag Is Actually Protected
The NTAG213, NTAG215 and NTAG216 chips used for business cards and object tags have a password feature built into the chip. You can set a password and configure the tag so that writes require it. Reading stays open, which is what you want: anybody should be able to tap the tag and get your card. Only changing it is restricted.
The catch with doing this manually is that it is fiddly, easy to get wrong, and easy to forget on the one tag that ends up somewhere public. A tag you protected is only useful if you protected all of them.
AtlasLinq applies the password in the same tap that writes the card. There is no separate step to remember and no setting to leave switched off, because a security control that depends on the user remembering it is a security control that fails on a Friday afternoon. When you later want to change what is on that tag, the app lifts the password, rewrites, and reapplies it. If you want the tag back to blank, only the account that wrote it can erase it.
What This Does Not Protect Against
It would be dishonest to stop there, because password protection solves exactly one problem and people tend to assume it solves more.
It does not stop someone physically removing your tag and sticking their own next to it. It does not stop someone covering a printed QR code with a different printed QR code. Nothing in software prevents either of those, and anybody selling you a tag as tamper-proof is selling you a story.
What it does prevent is the silent version, and the silent version is the one that actually happens: your tag stays exactly where you put it, looking exactly as it did, while pointing somewhere else entirely. That attack leaves no trace for you to notice on a walk past. A replaced or covered tag, by contrast, is something you can see.
So the sensible posture is both. Use protected tags, and physically check the ones in public places on the same rhythm you would check anything else you left outdoors.
Where It Is Worth Caring About
The risk scales with how public and how unattended the tag is, and with how much a hijack would be worth to somebody.
A tag in your wallet that you tap for people you are standing next to is low risk. You are there, you would notice. A tag on a reception desk is moderate: semi-public, but staffed. A tag on a property board on a street is the high end. It is unattended for weeks, the traffic it receives is exactly the audience a competitor wants, and redirecting it to another agent's listing is a genuinely tempting thing for a dishonest person to do.
The same reasoning applies to anything you leave installed: a card on a piece of equipment, a tag in a hotel room, a code on a display in a shop. If nobody is watching it and it carries real traffic, protect it.
NFC Against QR on This One Axis
People usually compare these two on convenience, which we have written about separately. On tamper resistance specifically they behave differently, and it is worth knowing which way.
A printed QR code cannot be rewritten, because it is ink. But it can be covered, and covering it is trivial and cheap. An NFC tag cannot be covered usefully, because a second tag stacked on the first tends to stop either one reading reliably, but it can be rewritten unless it is protected.
In other words, each has one weakness, and only one of the two weaknesses can be closed in software. That is the case for protecting the tag: it is the half of the problem you can actually do something about.
The Short Version
A blank NFC tag is a public whiteboard. Anyone can write on it. Once a tag is password protected as it is written, it stops being a whiteboard and starts being yours, and the people you are asking to tap it are spending a little less trust than they were.
If you are about to put tags somewhere the public can reach, that difference is worth the zero extra effort it costs. And if you want the card behind the tag to keep working after the details change, that is what writing your profile to a tag is for.