You sit down at a restaurant and notice there’s no paper menu. Instead, there’s a small sticker on the table that says, “Scan to view our menu.” You point your phone at it, tap the link, and the menu opens. It feels completely normal.
And most of the time, it is. But QR codes have also become a convenient way for scammers to get people to visit malicious websites, and restaurant tables can be an easy place to pull off the trick.
Why QR Codes Are a Perfect Scam Vehicle

A QR code is basically a shortcut to a website or link. The problem is that you can’t see the actual destination just by looking at the code.
When someone sends you a suspicious website address, you can often spot something strange in the URL. With a QR code, you don’t get that same warning before scanning it. You have to scan it first to see where it takes you.
That’s what makes QR codes attractive to scammers.
This type of QR-based phishing attack is commonly known as “quishing,” a combination of QR and phishing.
How the Restaurant Table Scam Actually Works
The trick itself isn’t particularly complicated.
- A scammer creates a sticker containing a malicious QR code.
- They place it over the legitimate QR code or put it somewhere nearby, such as a table stand or sign.
- You scan it expecting to see the restaurant menu.
- Instead, you’re taken to a fake website that may look like a payment page, booking form, loyalty program, or another legitimate restaurant service.
The physical setting makes the scam more convincing. You’re sitting inside a real restaurant, surrounded by staff and other customers, so you naturally assume the QR code on the table must be legitimate.
That’s exactly the kind of trust scammers want you to have.
What a Malicious Menu QR Code Can Actually Do
What happens after you scan the code depends on where it sends you. Sometimes it may simply be an annoying scam page, but in other cases the consequences can be much more serious.
- Fake payment pages can ask for your card details to pay a bill, add a tip, or make a small prepayment. That information can then go directly to the scammer.
- Credential-stealing pages can imitate restaurant apps or login pages and ask for your username and password.
- Malicious app downloads may be presented as a restaurant rewards or loyalty app but could actually contain malware.
- Browser exploits are less common, but outdated phones or browsers can sometimes be exposed to attacks simply by visiting a malicious website.
Red Flags to Watch For
There are a few things that should make you stop before scanning or interacting with a restaurant QR code.
- The sticker looks different from the restaurant’s other branding, appears crooked, or looks like it has been placed over another sticker.
- The page asks for your password, card number, or other personal information before showing you the menu.
- The link takes you somewhere completely unrelated, such as a prize claim, gift-card offer, or software download.
- The website address in your browser doesn’t appear to have any connection to the restaurant.
How to Protect Yourself
- Take a close look at the sticker. If it appears to have been taped over, peeled back, or placed on top of another QR code, don’t scan it. Ask the staff for a menu instead.
- Check the link before opening it. Your phone will usually show you a preview of the destination after scanning. If the address looks unfamiliar, shortened, or suspicious, don’t continue.
- Never enter payment or login information just because a QR code asks for it. If you’re unsure, close the page and ask the restaurant how payments or account logins are normally handled.
- Use your phone’s built-in QR scanner. The camera app on most modern iPhones and Android phones can scan QR codes without requiring a separate app. There’s little reason to install a random QR scanner that may request unnecessary permissions.
- When you’re unsure, ask the staff. You can also search for the restaurant yourself and find its official website or menu instead of relying on a sticker on the table.

QR codes aren’t dangerous by themselves. The real problem is that they can hide the destination of a link until after you’ve scanned it.
That makes them useful to scammers, especially in places like restaurants where people naturally trust the information placed in front of them.
You don’t need to stop using QR codes altogether. Just take a few seconds to check where the link is taking you before opening it, and never enter sensitive information simply because a QR code tells you to.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Not sure about a QR code? Take a clear photo of it and ask ChatGPT whether the code or the link appears legitimate before you open it or enter any personal information.





