Quishing, the QR code scam explained
A customer scans the square stuck to a table on your terrace. Instead of the menu, a page asks for their card number. That code isn't yours: it's quishing, a blend of QR code and phishing.
The subject gets plenty of press coverage, so your customers have heard about it. That's all the more reason to stay in control of what you put on your tables, not a reason to give up on it.
What is a QR code?
A QR code is an image containing text, usually a web address. The camera reads the code and offers to open the page. It's a shortcut, nothing more: it installs nothing and runs no program. If you're curious about how it works under the hood, we covered it in our article on how a QR code works.
What is quishing?
Quishing is standard phishing with a code in place of the link. Criminals create a fake code that redirects the user to a site imitating a well-known brand. The page then asks for personal data, logins, passwords or bank details.
The difference with email phishing is simple: nobody can read a square of pixels with the naked eye. The usual reflex, hovering over a link before clicking, no longer applies. That blind spot is exactly what the fraud exploits.
Where do these fraudulent QR codes turn up?
Almost always in public places, on something nobody is watching all the time. The method never varies: a malicious sticker is placed over a legitimate code, or a fake letter lands in the letterbox.
Car parks, pay-and-display machines and charging points
This is the most common case. A sticker is applied to the parking meter or charging point, and the payment page copies the local council's interface. Victims pay for parking that doesn't exist and hand over their card details in the process. Councils affected issue warnings about these scams on a regular basis.
Health service, tax office and public bodies
Scams impersonating public services arrive by letter or text. The message announces a refund waiting to be claimed or a card that needs renewing. The code leads to a fake government page asking for a national insurance number and bank details. No public body ever asks for your bank details this way.
Classified ads, letters and deliveries
On classified ad sites, a fake buyer sends a supposedly secure payment code. The victim scans it and in reality approves a transfer to whoever created the code. The same logic applies to missed-delivery cards slipped into the letterbox.
Your menu QR code is a different animal
A menu code points to your own page, hosted by your provider, with no form and no payment. It asks for no identity, no card, no password. The only real risk is someone sticking their own label over yours, and that's dealt with through physical materials, not technology.
| Criterion | Fraudulent QR code | Menu QR code you control |
|---|---|---|
| Where the code came from | Added sticker, letter from nowhere | Printed or engraved by you |
| Address it opens | Shortened URL or lookalike domain | Your domain, always the same |
| Data requested | Bank card, passwords, identity | None |
| What a scan leads to | Fraud, unauthorised payments, identity theft | The menu appears |
In practice, incidents in the dining room never come from the QR code itself: they come from a flimsy holder, stuck on in a hurry, that anyone can cover up in ten seconds.
How to spot a fake QR code
Teach your team these signs. They cover almost every case, and they work just as well for your customers.
- A sticker sitting on top of another surface: lift a corner and check what's underneath.
- A shortened address or an approximate domain name: when in doubt, don't scan it.
- A page asking for bank details when all you wanted was a menu or opening hours.
- A sense of urgency: a fine to settle, a parcel on hold, an account suspended.
On most phones, the address appears before the page opens. Check the first part of the domain, the bit before the first slash. That's what tells you where you're really going, and we explain it in our guide to scanning a QR code safely.
Five habits that protect your customers in the dining room
QR code security in a restaurant is a matter of physical materials and routine, not IT.
- Choose an engraved table stand, a laminated sticker or a code printed into the menu rather than a bare sticker.
- Walk the room once a week: a covered code is obvious within thirty seconds.
- Put your logo and the name of your restaurant around the code, so there's no confusion.
- Scan two random tables yourself every morning, when you open.
- Never ask for personal data or payment through that code: your customers will learn that in your restaurant, a scan only ever opens a menu.
The same principle applies to the other codes in your restaurant, including the one for your customer wifi access.
What to do if you or a customer is caught out
Act fast: most fraudulent payments can be stopped within a few hours. Contact the bank to block the card, change any passwords reused elsewhere, then report the scam through the official channels.
In the dining room, if you find a fake code, remove the holder, photograph it and warn the customers present. Filing a police report is still worth it, even with no money lost: those reports are how series of malicious stickers get traced across a neighbourhood.
The QR code remains a neutral tool. Properly placed and properly checked, it carries none of the risks these fraud cases describe.














