In this article
Somewhere on a terrace, in a food hall, or at a window table, someone is pasting a sticker over a QR code that was already there. Not on a parking meter this time — on the code your guests use to open the menu, place an order, or pay the bill. The question isn't whether that can happen. It's how often it already does, why almost nobody notices, and what it really costs against what the fix costs.
Four years ago, almost no restaurant had a QR code on the table. Today, the majority has at least one: for the menu, for ordering, and at a growing number of venues, for paying the bill too. That shift happened fast, and almost nobody has stopped to ask a simple question along the way: how does a guest actually know the sticker they're scanning is really yours?
The honest answer is: they don't. A QR code is a black-and-white pattern with no recognisable sender attached — no logo, no address bar to check, none of the "does this look right?" instinct a suspicious link in an email triggers. That's exactly what makes it the perfect target for what cybersecurity researchers call "quishing": QR code plus phishing.
This article isn't about the benefits of QR ordering — that's already covered elsewhere on this site, and those benefits are real. It's about what happens when someone other than you pastes a sticker on your own table, and it's the physical counterpart to the site's existing cybersecurity guide, which covers hardening your own systems — this is the attack that never touches your Wi-Fi or your POS, only the piece of paper on table 4.
Seven numbers, in this order: why this is only a problem now, how the swap actually plays out, why your guests can't see it, what one scanned sticker costs on average, the arithmetic that makes it worth a criminal's time, what police and regulators already say about it, and the fix that costs almost nothing.
Why "it's just a sticker" keeps the problem alive
Most venues have no routine at all for checking their own QR codes, for the same reason as with a diner who walks out without paying: it's never been explicitly thought through. A sticker gets put up once, at opening, and after that nobody looks at it again — except when it peels or gets dirty.
That's precisely the window this fraud lives in. A replacement sticker, printed in the same colour and roughly the same size as the original, doesn't stand out during a busy service — not to the guest, not to the server carrying four plates at once, and not to the owner who's running the floor instead of inspecting every table.
The rest of this article builds on what's actually known: why the attack surface only exists now, how the swap plays out in practice, what it costs when it goes wrong, and the one habit that cuts the risk fastest — not a new system, but a QR code that isn't easy to replace.
Free guide Everything digital, in one guide From QR ordering to cybersecurity — the complete guide to the digital side of your restaurant. Read the guide7 numbers most venues have never looked up
Every number below stands on its own, and comes from an official source or a published report — none of it is this site's own estimate. Together they explain why a QR sticker isn't decoration, but a piece of payment infrastructure that deserves the same attention as your POS.
1. Why this is only a problem now
Before 2020, the attack surface barely existed: QR codes on restaurant tables were a curiosity, not infrastructure. That's changed. Worldwide, 75% of restaurants now run a QR code for the menu, ordering, or payment — a shift that happened in under five years.
Every QR code you add is another piece of trust you're asking a guest to extend, without any way for them to verify where it leads. With one sticker on the table, that's a contained risk. With a menu code, an ordering code and a payment link, it's three separate chances for a criminal to take.
That's not a reason to abandon QR codes — the convenience and cost savings are real, and this site has covered them separately. It is the reason the rest of this article is worth reading: the attack surface is new, and at most venues, the habits to secure it aren't yet.
Four numbers, each from a separate source — together, the reason a QR sticker is a more attractive target today than it was five years ago.
Sources: KeepNet Labs / CNBC (July 2025) for the growth and detection figures; restaurant QR-adoption research, 2025.
2. How the swap actually plays out
The method is strikingly simple, and that's exactly what makes it work: a criminal prints a sticker carrying their own QR code, in roughly the same size and on similar material as the original, and simply pastes it directly over the existing code. No break-in, no technical knowledge of your systems required — just enough access to the table for the time it takes to stick on a label.
Belgium's own Federal Police issued an explicit warning after parking meters in Brussels were targeted this exact way: a fake sticker over the real QR code, redirecting scanners to a lookalike payment page. The US FTC and the NYC Department of Transportation issued near-identical warnings after similar incidents on parking meters and EV chargers.
Restaurant tables sit on that same list of targets, alongside menus, posters and payment terminals — anywhere a QR code can go unwatched for a while. The mechanism is always the same: the guest scans what they believe is the original, and lands on a page built to look exactly like it.
3. Why your guests can't see it
A QR code doesn't reveal its destination before you scan it. With a link in an email, you can hover your mouse and see the real URL — with a black-and-white square on a sticker, you simply can't. Phones also trust a link opened via the camera more readily than the same link in an email, precisely because scanning a QR code feels like a physical, "safe" action.
Consumer research on quishing, analysed by CNBC using FBI, FTC and state-agency data, found that only 39% of people can spot a tampered QR code before scanning it. In other words: 61% see no difference at all between your real sticker and the one someone pasted over it.
This isn't about inattentive guests. A sticker that looks identical, sits in the same place and gives off the same "scan me" signal is designed to exploit exactly that trust — on a careful guest just as effectively as a distracted one.
4. What one scanned sticker costs on average
When a guest scans the fake code, one of two things happens. The page looks like a payment screen and asks for card details that go straight to the criminal — so the bill is never actually paid to you, while the guest believes they've paid. Or the page mimics your menu or ordering system and quietly collects login credentials or personal information used for identity fraud later.
An analysis by CNBC of FBI, FTC and state-agency data (July 2025) puts the average loss per quishing victim at $1,225 — roughly €1,150. That's per successful scan, not per venue: one vulnerable table can be hit more than once before anyone notices.
For your restaurant, the damage is double. The bill "paid" through the fake page never reaches your own account — and the guest who feels defrauded blames you, not the criminal who put up the sticker. That second piece, the guest's trust, appears in no accounting ledger, but it's often the heavier cost.
5. The arithmetic that makes it worth a criminal's time
Printing and laminating a fake sticker costs a criminal barely a few euros — the same paper and printer used for a real one. Against an average loss of over a thousand euros per successful scan, that's a return few other forms of fraud can match.
That arithmetic also explains why quishing is growing so fast. Figures from cybersecurity firm KeepNet Labs, cited by CNBC, show quishing attacks up 587% since 2023 — flagged by the FBI itself as the fastest-growing form of phishing. Meanwhile, 26% of all malicious links are now delivered via a QR code rather than a traditional phishing email.
For a criminal, a table QR code in a restaurant is exactly the right target: cheap to forge, hard to tell apart from the original, and guaranteed to be scanned by several people during a single service.
What the fraud costs a criminal, against what it costs a victim — with protection somewhere in between.
The last bar is the average loss per successful quishing scan (CNBC, July 2025), converted to your own currency. The first two are illustrative order-of-magnitude figures, not an exact price list.
6. What police and regulators already say about it
This isn't a hypothetical scenario invented by this site — it's a problem governments explicitly recognise. The US FBI first warned in January 2022 about criminals tampering with QR codes to redirect victims to malicious websites, and has repeated that warning several times since, most recently in 2025.
Closer to home, Belgium's Federal Police issued an explicit "quishing" warning after parking meters in Brussels were targeted this way, and the FOD Economie (Belgium's economic affairs authority) published its own consumer page on QR codes used to "pay" a fake invoice. Both name restaurant tables, parking meters and payment terminals in the same breath as vulnerable spots.
That level of official recognition is itself a number worth noting: when the US FBI and the Belgian Federal Police independently describe the exact same method, this isn't an isolated incident — it's an established fraud pattern your venue should be prepared for.
7. The fix that costs almost nothing
The cheapest protection is the simplest: stop leaving your QR code as a replaceable sticker. Laminate it into the tabletop, engrave it into a stand, or print it directly on the menu instead of as a loose sticker — any form that makes a sticker placed over it visibly obvious does most of the work.
The second layer costs no materials, only a habit: add "check the table QR codes" to your opening and closing round. This site has already covered that routine separately — it's exactly the kind of short, recurring check that routine exists for, and a sticker pasted over another one stands out immediately to a targeted glance.
The third option, for venues that still prefer loose stickers: a dynamic QR code that changes per order or per day, generated straight from your own POS instead of printed once and reused for years. A code that's no longer valid tomorrow is no longer an attractive target for a criminal.
Run the numbers for your own venue
Fill in your own figures. The incident-rate field defaults to a conservative assumption — there's no reliable per-restaurant frequency for this specific fraud, so this is a thinking exercise, not a forecast.
This isn't accounting: the point isn't the exact number, it's whether the "exposure" column beats the "protection" column under assumptions that are realistic for your own venue.
Annual exposure against the cost of preventing it
Fill in your own numbers — the rest calculates itself.
—
Default incident rate: 1% of weeks — a conservative assumption, not a measured frequency. Replace it with your own judgement.
This is a thinking exercise with your own numbers, not an accounting guarantee — replace every assumption with your own experience.
What the tool doesn't measure: the trust a guest loses when they feel defrauded and blame your venue, not the criminal who placed the sticker. See number 4 above — that piece of the damage appears in no accounting ledger.
And what it never replaces: number 7 above holds regardless of what the calculation says — a QR code that isn't easy to replace costs less than the protection in this tool alone, in every scenario.
How to fix this tomorrow, without a whole new system
Three steps, in this order — not because the rest doesn't matter, but because these three have the fastest effect on what a fake QR code actually costs you.
1. Make every QR code hard to replace
- Laminate, engrave, or print your QR codes directly onto the material — never as a loose sticker you once stuck on in a hurry.
- Do the same for every code outside the table itself: menus, posters, and the payment terminal.
- A code that's visibly damaged if something is pasted over it is instantly a less attractive target.
2. Fold the check into a routine that already exists
- Add "check the QR codes" to your opening and closing round — see the checklist above.
- One quick glance per table while setting up is enough; a pasted-over sticker stands out immediately.
- Repeat the same check on posters and payment terminals, not just the tables.
3. Weigh the cost against protection, not against one incident
- Use the calculator above with your own order volumes and average bill.
- Compare that number against what lamination, engraving, or a dynamic code from your POS would cost.
- Repeat the sum whenever your share of QR orders or payments grows noticeably.
The short answer
A tampered QR code on your table isn't a far-fetched scenario — it's a fraud pattern the FBI, Belgium's Federal Police and the FOD Economie have each independently confirmed, and it's growing precisely because restaurants themselves have moved to QR codes en masse.
The damage is double: the bill that never reaches you, and the guest who loses trust in a venue that had nothing to do with it. Both pieces count, even though only one shows up in a ledger.
The fix is small compared to what it prevents: make your QR codes hard to replace, and fold checking them into a round you already walk.