Security & privacy
Fake menu QR scams — table-tent swaps in restaurants
A fraudster replaces the QR code on a table tent with a sticker leading to a fake menu or ordering page that harvests card details. Tables are rarely audited, so swaps go unnoticed for days. Diners should check the domain before paying; owners should count and inspect table codes daily.
The attack
Since menu codes became standard, every table in a restaurant is a small unattended kiosk. The scam is a sticker overlay: the attacker sits down, swaps the code on the table tent, and leaves. The replacement leads to one of:
- a cloned menu with ordering, which takes a card payment that never reaches the restaurant;
- a phishing page ("sign in to order", "verify your card to open a tab") that harvests credentials or card details;
- occasionally just a malicious link with no food theme at all, relying on the diner trusting whatever the table offers.
A browse-only menu code — one that opens a PDF or a webpage with no payment step — is a much smaller prize, which is why "order and pay at table" venues are the real target.
Why restaurants are exposed
- Nobody audits tables. Staff wipe them, straighten them, and never scan them. A swapped tent in a 20-table room is 1 code in 20 — and each table is its own attack surface that can sit compromised through hundreds of covers.
- The environment is trusted. A diner who would hesitate at a lamp-post sticker will scan whatever their table presents.
- Table tents are removable. The whole tent can be substituted, not just the code — no sticker edge to feel.
- Payment on an unfamiliar domain feels normal, because every venue uses a different ordering platform.
What diners can do
- Compare with the venue. Does the domain on the preview banner match the platform the restaurant says it uses? If the staff hand you a printed menu and the table code claims you must order online, ask.
- Read the domain before paying — the ten-second check applies at the table exactly as anywhere else.
- Treat login requests as a stop sign. A menu does not need your password or a card "verification" before showing food.
- If a page feels wrong, decode the code without opening it with a client-side scanner, or simply order with a human.
The owner's checklist
- Count and inspect daily. You know how many table tents you own. A one-minute scan of one table's code at opening — rotating tables through the week — catches swaps within days rather than weeks.
- Use tamper-evident labels on tents and fixed table stickers, so peeling the original is visibly destructive.
- Print your domain on the tent ("menu.yourvenue.example") so diners can compare it with their preview banner.
- Fix codes into the furniture where possible — a laminated insert in a holder is easier to swap than a code printed on a mounted plaque.
- Brief the floor staff. They handle every tent every day; tell them what an overlay looks like and to bring any loose or doubled-up sticker to a manager.
- Keep the source file. If you generate the menu code yourself and keep the artwork, replacing a compromised tent costs minutes. Static codes are free to regenerate and never expire.
A single compromised table that takes one fraudulent payment costs more than a year of tamper-evident labels for the whole room.
FAQ
Are QR code menus safe to scan?
Generally yes — a browse-only menu is one of the lowest-risk scans there is. The risk concentrates in order-and-pay flows, where a swapped code can route your card details to a fraudster. Check the domain before paying.
How would I know if a restaurant's QR code was swapped?
You mostly cannot tell from the code, which is the problem. Tells are a domain that does not match the venue's stated platform, a login or card-verification request before showing the menu, and staff who seem unaware of the "online ordering" the table demands.
How often should a restaurant check its table QR codes?
Daily is proportionate for order-and-pay venues — one rotating table per day at opening covers a room within the week. Browse-only menus can be checked weekly. Any refit, deep clean or furniture move should trigger a full re-check.
Should restaurants stop using QR menus because of this?
No. The scam targets payment flows, not menus as such, and the countermeasures — tamper-evident labels, printed domains, daily rotation checks — are cheap. Venues that only link a browse-only menu carry very little risk.
Try it — free, no signup
Related
- Are QR codes safe? — Scanning a QR code is safe in itself — it decodes text and nothing else. The risk is entirely in what you do next. A code cannot install software, dial,…
- QR code stickers placed over real ones — the overlay attack — The cheapest QR attack is a printed sticker pasted over a genuine code. Why it works, where it happens, and what venues can do to make overlays obvious.
- Parking QR code scams — how they work and how to avoid them — Fake QR stickers on parking meters lead to card-harvesting payment pages. What the FTC and FBI have warned about, and the rules for drivers and operators.
- Tamper-evident QR labels — Destructible vinyl, void laminates and holographic overlays make QR sticker swaps visible for pennies per label — if you pair them with a physical audit routine.