Quishing: the phishing hidden in the menu QR code
How restaurants become card-theft vectors through fake QR codes stuck to tables.
Audience: Companies and Operations · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
A restaurant discovers customers are being sent to a fake payment page when scanning the menu QR code — card data was captured over the course of one night.
How the scam works
Attackers place tampered QR codes over the originals. When scanned, the customer lands on a page that mimics the payment system and captures data before redirecting to the real site.
Common mistake
Treating the table QR code as decoration, with no daily audit.
Impact
Customers get cards cloned, a Procon complaint, local reputation loss and falling platform ratings.
What works
A digital menu served via NFC or your own domain with visible HTTPS, daily validation and staff training.
Protection checklist
- Validate QR codes on every table daily
- Serve the menu from your own domain with HTTPS
- Train waitstaff to identify fraud
- Warn customers with a table notice
- Initiate takedown of fake pages
- Monitor complaints on Google Reviews
- File a police report in confirmed cases
Editorial sources
- Banco Central do Brasil — Orientações oficiais sobre golpes e Pix
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
Your digital menu is the front door. Protect it as carefully as the kitchen.