Blindfy — Digital Protection

Quishing: the phishing hidden in the menu QR code

How restaurants become card-theft vectors through fake QR codes stuck to tables.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

A restaurant discovers customers are being sent to a fake payment page when scanning the menu QR code — card data was captured over the course of one night.

How the scam works

Attackers place tampered QR codes over the originals. When scanned, the customer lands on a page that mimics the payment system and captures data before redirecting to the real site.

Common mistake

Treating the table QR code as decoration, with no daily audit.

Impact

Customers get cards cloned, a Procon complaint, local reputation loss and falling platform ratings.

What works

A digital menu served via NFC or your own domain with visible HTTPS, daily validation and staff training.

Protection checklist

  • Validate QR codes on every table daily
  • Serve the menu from your own domain with HTTPS
  • Train waitstaff to identify fraud
  • Warn customers with a table notice
  • Initiate takedown of fake pages
  • Monitor complaints on Google Reviews
  • File a police report in confirmed cases

Editorial sources

Your digital menu is the front door. Protect it as carefully as the kitchen.

← All risk analyses · Blindfy initial assessment