By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

I Took a Closer Look at the Sticker
After pointing out the suspicious QR code to the restaurant manager, we examined it together.
At first, it looked like the original code printed on the table stand.
But when the manager carefully lifted one corner of the sticker, another QR code appeared underneath.
The genuine QR code had been completely covered.
The fake one was simply placed on top of it.
It was such a simple trick.
Yet it could have fooled almost anyone.
The Fake Website Was Surprisingly Convincing
I compared the fake website with the restaurant’s real website.
The differences were almost impossible to notice.
The criminals had copied:
- The restaurant’s logo.
- Its colours.
- Food photographs.
- Menu categories.
- Contact details.
If someone had visited the page for only a few seconds, they probably would have believed it was genuine.
That is exactly what the attackers wanted.
Why Ask Me to Sign In?
The fake website wasn’t interested in showing me the menu.
Its real purpose was collecting information.
By asking customers to sign in using their Google, Apple or Facebook accounts, the attackers hoped people would enter their usernames and passwords into a fake login page.
This type of attack is known as phishing.
When phishing uses QR codes instead of emails or text messages, it’s often called “quishing.”
The QR code becomes the bait that directs victims to a fraudulent website.
The Scam Didn’t End With Login Pages
Not every fake QR code asks for usernames and passwords.
Some fake QR codes may attempt to:
- Redirect visitors to phishing websites.
- Encourage the download of malicious applications.
- Display fake payment pages.
- Collect personal information through online forms.
The objective depends on the criminal’s plan.
The QR code is simply the first step.
Why QR Codes Are So Effective
Most people trust QR codes.
We use them for:
- Restaurant menus.
- Parking payments.
- Event tickets.
- Airline boarding passes.
- Public transport.
- Product information.
Because QR codes have become part of everyday life, many people scan them without asking where they lead.
Criminals know this.
Instead of persuading victims to type a suspicious web address, they simply encourage them to scan a code.
The phone does the rest.
The Restaurant Had No Idea
The manager thanked me for reporting the issue.
They immediately inspected every table in the restaurant.
Several fake QR code stickers were removed that evening.
The staff explained that they hadn’t noticed the tampering because the stickers blended in almost perfectly with the original table displays.
That made me realise something important.
Sometimes businesses become victims too.
The restaurant wasn’t trying to scam its customers.
Someone had secretly modified their tables without permission.
One Small Habit Protected Me
Looking back, one simple habit saved me.
When the website asked me to log in before viewing a menu, I paused instead of continuing.
That short pause gave me time to question what I was seeing.
A restaurant menu shouldn’t normally require me to sign into my personal accounts.
That small moment of curiosity exposed the entire scam.
QR Codes Aren’t Dangerous—Blind Trust Is
QR codes themselves aren’t malicious.
They’re simply another way of sharing information.
The real danger comes from scanning a code without considering where it might lead.
Just as we shouldn’t automatically trust every email link, we shouldn’t automatically trust every QR code we see in public.
Technology wasn’t the problem.
Blind trust was.
In the final part of this article, I’ll explain the biggest warning signs of fake QR code scams, share practical tips for scanning QR codes safely, and reveal the simple rule I now follow every time my phone detects a QR code in a public place.
Continue Reading: The QR Code on the Restaurant Table Was Fake (Part 3)









