QR Code Fraud: 7 Numbers Behind the Fake Sticker on Your Table (2026 Numbers) | HappyChef
Digital & Data

QR Code Fraud: 7 Numbers Behind the Fake Sticker on Your Table

The sticker on your table looks exactly like it did last week. That's exactly why nobody checks it.

In this article
  1. Why "it's just a sticker" keeps the problem alive
  2. 7 numbers most venues have never looked up
  3. Run the numbers for your own venue
  4. How to fix this tomorrow, without a whole new system
  5. The short answer

Somewhere on a terrace, in a food hall, or at a window table, someone is pasting a sticker over a QR code that was already there. Not on a parking meter this time — on the code your guests use to open the menu, place an order, or pay the bill. The question isn't whether that can happen. It's how often it already does, why almost nobody notices, and what it really costs against what the fix costs.

Four years ago, almost no restaurant had a QR code on the table. Today, the majority has at least one: for the menu, for ordering, and at a growing number of venues, for paying the bill too. That shift happened fast, and almost nobody has stopped to ask a simple question along the way: how does a guest actually know the sticker they're scanning is really yours?

The honest answer is: they don't. A QR code is a black-and-white pattern with no recognisable sender attached — no logo, no address bar to check, none of the "does this look right?" instinct a suspicious link in an email triggers. That's exactly what makes it the perfect target for what cybersecurity researchers call "quishing": QR code plus phishing.

This article isn't about the benefits of QR ordering — that's already covered elsewhere on this site, and those benefits are real. It's about what happens when someone other than you pastes a sticker on your own table, and it's the physical counterpart to the site's existing cybersecurity guide, which covers hardening your own systems — this is the attack that never touches your Wi-Fi or your POS, only the piece of paper on table 4.

Seven numbers, in this order: why this is only a problem now, how the swap actually plays out, why your guests can't see it, what one scanned sticker costs on average, the arithmetic that makes it worth a criminal's time, what police and regulators already say about it, and the fix that costs almost nothing.

Why "it's just a sticker" keeps the problem alive

Most venues have no routine at all for checking their own QR codes, for the same reason as with a diner who walks out without paying: it's never been explicitly thought through. A sticker gets put up once, at opening, and after that nobody looks at it again — except when it peels or gets dirty.

That's precisely the window this fraud lives in. A replacement sticker, printed in the same colour and roughly the same size as the original, doesn't stand out during a busy service — not to the guest, not to the server carrying four plates at once, and not to the owner who's running the floor instead of inspecting every table.

The rest of this article builds on what's actually known: why the attack surface only exists now, how the swap plays out in practice, what it costs when it goes wrong, and the one habit that cuts the risk fastest — not a new system, but a QR code that isn't easy to replace.

Free guide Everything digital, in one guide From QR ordering to cybersecurity — the complete guide to the digital side of your restaurant. Read the guide

7 numbers most venues have never looked up

Every number below stands on its own, and comes from an official source or a published report — none of it is this site's own estimate. Together they explain why a QR sticker isn't decoration, but a piece of payment infrastructure that deserves the same attention as your POS.

1. Why this is only a problem now

Before 2020, the attack surface barely existed: QR codes on restaurant tables were a curiosity, not infrastructure. That's changed. Worldwide, 75% of restaurants now run a QR code for the menu, ordering, or payment — a shift that happened in under five years.

Every QR code you add is another piece of trust you're asking a guest to extend, without any way for them to verify where it leads. With one sticker on the table, that's a contained risk. With a menu code, an ordering code and a payment link, it's three separate chances for a criminal to take.

That's not a reason to abandon QR codes — the convenience and cost savings are real, and this site has covered them separately. It is the reason the rest of this article is worth reading: the attack surface is new, and at most venues, the habits to secure it aren't yet.

Why this is a problem right now

Four numbers, each from a separate source — together, the reason a QR sticker is a more attractive target today than it was five years ago.

75% of restaurants worldwide now run a QR code for menu, ordering, or payment Before 2020, this attack surface barely existed
587% rise in quishing attacks since 2023 Flagged by the FBI itself as the fastest-growing form of phishing
26% of all malicious links are now delivered via a QR code Rather than a traditional phishing email
61% of people can't spot a tampered QR code before scanning it Same sticker, same size — no visible signal at all

Sources: KeepNet Labs / CNBC (July 2025) for the growth and detection figures; restaurant QR-adoption research, 2025.

2. How the swap actually plays out

The method is strikingly simple, and that's exactly what makes it work: a criminal prints a sticker carrying their own QR code, in roughly the same size and on similar material as the original, and simply pastes it directly over the existing code. No break-in, no technical knowledge of your systems required — just enough access to the table for the time it takes to stick on a label.

Belgium's own Federal Police issued an explicit warning after parking meters in Brussels were targeted this exact way: a fake sticker over the real QR code, redirecting scanners to a lookalike payment page. The US FTC and the NYC Department of Transportation issued near-identical warnings after similar incidents on parking meters and EV chargers.

Restaurant tables sit on that same list of targets, alongside menus, posters and payment terminals — anywhere a QR code can go unwatched for a while. The mechanism is always the same: the guest scans what they believe is the original, and lands on a page built to look exactly like it.

3. Why your guests can't see it

A QR code doesn't reveal its destination before you scan it. With a link in an email, you can hover your mouse and see the real URL — with a black-and-white square on a sticker, you simply can't. Phones also trust a link opened via the camera more readily than the same link in an email, precisely because scanning a QR code feels like a physical, "safe" action.

Consumer research on quishing, analysed by CNBC using FBI, FTC and state-agency data, found that only 39% of people can spot a tampered QR code before scanning it. In other words: 61% see no difference at all between your real sticker and the one someone pasted over it.

This isn't about inattentive guests. A sticker that looks identical, sits in the same place and gives off the same "scan me" signal is designed to exploit exactly that trust — on a careful guest just as effectively as a distracted one.

4. What one scanned sticker costs on average

When a guest scans the fake code, one of two things happens. The page looks like a payment screen and asks for card details that go straight to the criminal — so the bill is never actually paid to you, while the guest believes they've paid. Or the page mimics your menu or ordering system and quietly collects login credentials or personal information used for identity fraud later.

An analysis by CNBC of FBI, FTC and state-agency data (July 2025) puts the average loss per quishing victim at $1,225 — roughly €1,150. That's per successful scan, not per venue: one vulnerable table can be hit more than once before anyone notices.

For your restaurant, the damage is double. The bill "paid" through the fake page never reaches your own account — and the guest who feels defrauded blames you, not the criminal who put up the sticker. That second piece, the guest's trust, appears in no accounting ledger, but it's often the heavier cost.

5. The arithmetic that makes it worth a criminal's time

Printing and laminating a fake sticker costs a criminal barely a few euros — the same paper and printer used for a real one. Against an average loss of over a thousand euros per successful scan, that's a return few other forms of fraud can match.

That arithmetic also explains why quishing is growing so fast. Figures from cybersecurity firm KeepNet Labs, cited by CNBC, show quishing attacks up 587% since 2023 — flagged by the FBI itself as the fastest-growing form of phishing. Meanwhile, 26% of all malicious links are now delivered via a QR code rather than a traditional phishing email.

For a criminal, a table QR code in a restaurant is exactly the right target: cheap to forge, hard to tell apart from the original, and guaranteed to be scanned by several people during a single service.

The arithmetic in three bars

What the fraud costs a criminal, against what it costs a victim — with protection somewhere in between.

What the fake sticker costs a criminal to print
€1
What a secured QR code costs you, per month
€15
What one successful scan costs a victim on average
€1,150

The last bar is the average loss per successful quishing scan (CNBC, July 2025), converted to your own currency. The first two are illustrative order-of-magnitude figures, not an exact price list.

6. What police and regulators already say about it

This isn't a hypothetical scenario invented by this site — it's a problem governments explicitly recognise. The US FBI first warned in January 2022 about criminals tampering with QR codes to redirect victims to malicious websites, and has repeated that warning several times since, most recently in 2025.

Closer to home, Belgium's Federal Police issued an explicit "quishing" warning after parking meters in Brussels were targeted this way, and the FOD Economie (Belgium's economic affairs authority) published its own consumer page on QR codes used to "pay" a fake invoice. Both name restaurant tables, parking meters and payment terminals in the same breath as vulnerable spots.

That level of official recognition is itself a number worth noting: when the US FBI and the Belgian Federal Police independently describe the exact same method, this isn't an isolated incident — it's an established fraud pattern your venue should be prepared for.

7. The fix that costs almost nothing

The cheapest protection is the simplest: stop leaving your QR code as a replaceable sticker. Laminate it into the tabletop, engrave it into a stand, or print it directly on the menu instead of as a loose sticker — any form that makes a sticker placed over it visibly obvious does most of the work.

The second layer costs no materials, only a habit: add "check the table QR codes" to your opening and closing round. This site has already covered that routine separately — it's exactly the kind of short, recurring check that routine exists for, and a sticker pasted over another one stands out immediately to a targeted glance.

The third option, for venues that still prefer loose stickers: a dynamic QR code that changes per order or per day, generated straight from your own POS instead of printed once and reused for years. A code that's no longer valid tomorrow is no longer an attractive target for a criminal.

Run the numbers for your own venue

Fill in your own figures. The incident-rate field defaults to a conservative assumption — there's no reliable per-restaurant frequency for this specific fraud, so this is a thinking exercise, not a forecast.

This isn't accounting: the point isn't the exact number, it's whether the "exposure" column beats the "protection" column under assumptions that are realistic for your own venue.

Annual exposure against the cost of preventing it

Fill in your own numbers — the rest calculates itself.

Estimated annual exposure
Under these assumptions, over 52 weeks
Cost of protection, per year
At the monthly cost entered
Net difference, per year
Exposure minus protection cost

Default incident rate: 1% of weeks — a conservative assumption, not a measured frequency. Replace it with your own judgement.

This is a thinking exercise with your own numbers, not an accounting guarantee — replace every assumption with your own experience.

What the tool doesn't measure: the trust a guest loses when they feel defrauded and blame your venue, not the criminal who placed the sticker. See number 4 above — that piece of the damage appears in no accounting ledger.

And what it never replaces: number 7 above holds regardless of what the calculation says — a QR code that isn't easy to replace costs less than the protection in this tool alone, in every scenario.

How to fix this tomorrow, without a whole new system

Three steps, in this order — not because the rest doesn't matter, but because these three have the fastest effect on what a fake QR code actually costs you.

1. Make every QR code hard to replace

  • Laminate, engrave, or print your QR codes directly onto the material — never as a loose sticker you once stuck on in a hurry.
  • Do the same for every code outside the table itself: menus, posters, and the payment terminal.
  • A code that's visibly damaged if something is pasted over it is instantly a less attractive target.

2. Fold the check into a routine that already exists

  • Add "check the QR codes" to your opening and closing round — see the checklist above.
  • One quick glance per table while setting up is enough; a pasted-over sticker stands out immediately.
  • Repeat the same check on posters and payment terminals, not just the tables.

3. Weigh the cost against protection, not against one incident

  • Use the calculator above with your own order volumes and average bill.
  • Compare that number against what lamination, engraving, or a dynamic code from your POS would cost.
  • Repeat the sum whenever your share of QR orders or payments grows noticeably.

The short answer

A tampered QR code on your table isn't a far-fetched scenario — it's a fraud pattern the FBI, Belgium's Federal Police and the FOD Economie have each independently confirmed, and it's growing precisely because restaurants themselves have moved to QR codes en masse.

The damage is double: the bill that never reaches you, and the guest who loses trust in a venue that had nothing to do with it. Both pieces count, even though only one shows up in a ledger.

The fix is small compared to what it prevents: make your QR codes hard to replace, and fold checking them into a round you already walk.

Frequently Asked Questions

What exactly is quishing?

Quishing is QR code plus phishing: a criminal pastes a fake QR code over a real one, so anyone who scans it lands on a fake payment or login page instead of the real destination. See the article above for how that plays out in a restaurant.

How common is QR code fraud in restaurants?

An exact per-restaurant frequency doesn't exist, but the pattern is officially confirmed: the FBI, Belgium's Federal Police and the FOD Economie have each warned about this exact method on tables, parking meters and payment terminals. See number 6 above.

How can I spot a fake QR code?

Often, not with the naked eye at all — only 39% of people can tell before scanning. The most reliable check isn't looking for a code that seems off, it's checking whether a sticker has been placed over another one: feel the edges, or use a code that can't be swapped out as a loose sticker in the first place. See numbers 3 and 7 above.

How much does QR code fraud cost a restaurant?

The average loss per successful scan is about $1,225 (CNBC, July 2025), roughly €1,150 — plus the bill that never reaches your own account when the fake code leads to a payment page, and the trust of a guest who blames your venue for the fraud. See number 4 above, and run your own numbers through the calculator.

Is it safe to use a QR code for payment in a restaurant?

Yes, as long as the code itself can't be swapped out by a loose sticker. The risk isn't in QR-code technology itself, but in a code anyone can paste over unnoticed. A laminated, engraved or dynamically generated code largely removes that risk. See number 7 above.

What helps most to prevent QR code fraud?

Two things together: make the code physically hard to replace (lamination, engraving, or printing directly instead of a loose sticker), and fold checking it into a routine you already walk, like your opening and closing round. See number 7 above.

Who is liable if a guest is defrauded through a tampered QR code?

That depends on the circumstances and varies by country — this isn't legal advice. What's certain in practice: the guest often blames the venue they were sitting in, regardless of who is legally liable. That reputation risk is exactly why prevention is cheaper than explaining afterwards.