What You’re Actually Scanning at That Restaurant Table

You’ve just landed after a six-hour flight, you’re hungry, and the café near your gate has a QR code propped up on the table instead of a paper menu. You scan it without thinking. That moment - tired, rushed, slightly disoriented - is exactly when a particular scam lands most effectively.

The scam is called Quishing, a portmanteau of QR and phishing, and it works by replacing or covering legitimate QR codes with fake ones that redirect to fraudulent websites. The fake page may copy the colours, layout, and branding of a real company so closely that nothing looks wrong until you’ve already typed in your credit card number. No hacking required, no broken hardware - just a printed sticker placed over a real code.

How the Mechanics Actually Work

A scammer doesn’t need sophisticated tools. They print a fake QR sticker and place it directly over the real code on a parking meter, restaurant table, hotel notice board, or transit machine. The surrounding sign still looks official. The logo still looks familiar. When the fake page opens, it may ask you to pay for parking, confirm a hotel check-in, or settle a toll balance. What it’s actually doing is collecting your credit card number, password, phone number, licence plate, email address, or other personal data.

The U.S. Federal Trade Commission has specifically warned that scammers hide harmful links in QR codes to steal personal information, including by placing fake QR codes over real ones on parking meters. The FTC has also flagged a related tactic: fake traffic violation texts that open with a QR code and pressure recipients into paying a fabricated unpaid balance. The urgency is deliberate. Panic shortens the pause between scanning and paying.

The Three Places Fake Codes Show Up Most

Restaurant Tables and Café Menus

Post-pandemic, QR code menus became standard across Europe, Southeast Asia, North America, and beyond. Most are legitimate. The red flag isn’t the code itself - it’s what the page requests. A menu QR code should show a menu. It should not ask for your passport number, banking login, hotel room number, or any password. Before scanning, look at the physical surface. Is the code printed directly into the table card or menu holder, or does it sit on top as a separate sticker? A raised edge, a slight tilt, or a code that sits proud of the surface around it are all worth pausing over.

Parking Meters, Tolls, and Rental Car Payments

This is where Quishing causes the most direct financial damage. Travelers unfamiliar with local payment systems are more likely to follow whatever instructions a sign provides. A fake QR code on a parking meter sends you to a site that looks like the city’s official payment portal - same color scheme, similar layout - and captures your card details before you’ve even found your spot. Rental car return stations and toll payment kiosks carry the same risk. When using any pay-by-phone parking system abroad, cross-reference the URL with the one printed elsewhere on the machine or posted on nearby signage.

Airports, Train Stations, Hotels, and Transit Areas

High foot traffic and time pressure make transit hubs particularly useful for this scam. A fake check-in QR at a hotel front desk, a fraudulent Wi-Fi registration page in a departure lounge, or a fake ticketing machine at a train station - each scenario puts travelers in a position where they’re moving fast and trusting official-looking infrastructure. Hotel lobby scams are especially effective because guests assume anything displayed at reception is vetted by staff.

One sentence matters here: any QR code that arrives unsolicited via text or email, claiming to be a fine, toll, ticket, or check-in request, should be treated as suspect until verified through the official website directly.

The Four-Step Check Before You Scan

Pause before you scan. Thirty seconds of attention before scanning is a reasonable trade against potential credit card fraud.

Check the physical code. Look at the sticker or printed surface. Is it crooked, raised, or layered over something else? Run a fingernail lightly across the edge. A fake sticker often sits above the surface of the original material. A code printed directly onto a sign or table card is harder to fake.

Check the URL before entering anything. When your phone camera reads a QR code, it usually previews the link before opening it. Read that URL. Does it match the official domain of the business or service? A parking payment portal for the city of Barcelona should look like a Barcelona city government address - not a string of random characters with a .info or .xyz suffix. If you’re already on the page, look at the address bar before typing a single character.

Go directly to the official site or app if anything feels off. Close the page. Open a browser and type the address manually, or use the company’s official app. This adds ninety seconds to your transaction and eliminates the risk entirely.

If You Already Scanned a Suspicious Code

Don’t wait to see what happens. If you’ve scanned a code that opened an unexpected page, close the browser immediately - before entering any information. If you entered card details before realizing something was wrong, contact your bank or card issuer as soon as possible to freeze the card and dispute any unauthorized charges. Change any passwords you may have typed into the page. Report the fake code to the business or venue so it can be removed, and where possible, report it to local consumer protection authorities.

The FTC recommends reporting scams at ReportFraud.ftc.gov. In the EU, national consumer protection agencies handle these reports. In the UK, Action Fraud is the relevant body.

Should You Stop Using QR Codes Altogether?

That would be impractical and unnecessary. The majority of QR codes travelers encounter are completely legitimate, and in many countries they are now the primary interface for menus, transit payments, and hotel services. Avoiding them entirely would create more friction than the scam itself.

What changes the calculation is habit. The pause-check-pay sequence takes under a minute and works at any scan point, anywhere in the world. Restaurants, parking meters, hotels, airports - the same three steps apply. Check the physical code. Read the URL preview. Enter information only when the domain matches what you’d expect.

A raised sticker edge on a parking meter in Lisbon or a misaligned QR on a café table in Bangkok is worth thirty seconds of scrutiny. Credit card fraud resolution, by contrast, can take weeks - and some international transactions are significantly harder to dispute than domestic ones, particularly when the card was used abroad on a foreign-registered fraudulent site.