forumNew topic

How can I learn about QR code security — what are the risks for a business?

Doki ekibiDoki team
Job title
Official account
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
310
#1

We run a 6-branch cafe and restaurant business. Two years ago, we ditched paper menus and put QR code stickers on acrylic stands across all tables. Customers scan the code with their phones to view the menu, and they can even complete payments right through that screen if they choose.

Last week at one of our locations, an attentive customer noticed a very professionally made transparent sticker placed directly over the table's QR code. When scanned, it loaded an exact replica of our menu page and asked for credit card details before placing an order. We immediately checked all 140 tables across our branches and found similar stickers on three other tables.

This has made us incredibly nervous; customer trust took a hit and we narrowly dodged a severe reputational disaster. As a business, how can we ensure QR code security both technically and operationally? What specific types of risk are we facing, and how can we train our staff to counter these threats?

AAycan D***MemberCommunity member
Joined
Oct 2024
Message
240
Most Helpful#2

Short answer: The primary risk with QR codes isn't the code itself but someone tampering with the destination URL or slapping a malicious sticker over the physical code. Mitigating this requires a combination of physical inspection routines, a dynamic routing backend and domain verification protocols.

What you experienced is known in cybersecurity as a QR code phishing attack (quishing). Because QR codes cannot be read by the human eye customers will easily fall for a fake page unless they carefully verify the landing URL. Attackers typically register typo-squatted domains that look nearly identical to the business's real domain, replicate the UI and siphon payment details.

On the technical side the first thing you need to do is move away from static URLs to a centrally managed dynamic redirect setup. That way you can change the target URL on the fly, or cut the link instantly if unusual traffic or redirections are detected. Also, make sure your menu page has fully configured security certificates and add small visual indicators showing customers what the verified domain and green padlock should look like in their browser.

Operationally you have to lock down physical security. Switching from sticker-friendly paper or acrylic to laser-engraved wood or metal QR codes on the tables is the most definitive fix. On top of that make it standard operating procedure for floor staff to physically touch and inspect the QR codes at the start of every shift and whenever wiping down tables.

MMelis Ç***Expert
Job title
System support specialist
Sector
Energy
Organization type
two-branch business
Joined
Apr 2025
Message
4
#3

First thing tomorrow morning, rip out those acrylic stands. Get metal plates laser-engraved directly on the tables. Even if someone slaps a sticker on top, you'll feel the raised edge instantly with a finger swipe. It costs maybe 40-50 TL per table, but it'll save you from massive legal and financial nightmares.

SSultan Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
early-stage startup
Joined
Feb 2023
Message
10
#4

Check the domain the attackers used immediately and file an abuse report with the relevant registrar. Also add strict security headers to your menu site; enable frame-ancestors / clickjacking protection policies so no other server can clone your site and serve it inside an iframe.

NNuri G***Member
Job title
Purchasing manager
Sector
Agriculture
Organization type
early-stage startup
Joined
Mar 2023
Message
62
#5

Drill these 3 rules into your staff: 1) Run a finger over the code surface while clearing tables to check for stickers. 2) Scan table codes with a random phone at least once a day to verify the browser address bar. 3) If anything looks off or points to a domain other than yours, take that table out of service immediately.

TTuğçe U***Expert
Job title
Production planning
Sector
Electrical-electronics
Organization type
40-person manufacturing company
Joined
Jan 2023
Message
174
#6

We had the exact same issue across room service QR codes in 45 rooms at our boutique hotel. Within two weeks, 3 of our guests had their cards cloned. We had them laser-engraved onto the tables and restricted our redirect links so they could only be accessed via the local network. We haven't had a single incident in two years.

EEmine A***MemberCommunity member
Joined
Mar 2025
Message
1
#7

Were there any customers who actually entered their credit card details on the phishing page and suffered losses? If anyone lost money your business could face legal liability due to negligence. Have you consulted an IT law attorney immediately?

GGökhan D***Member
Job title
Business Owner
Sector
Machinery manufacturing
Organization type
40-person manufacturing company
Joined
Oct 2025
Message
416
#8

u cant expect customers to check the address bar when scanning a menu no one pays attention. only solution is making physical tampering impossible, just engrave it on the table and be done with it.

PPınarExpert
Job title
Analytics Specialist
Joined
Jan 2024
Message
198

Doki · Mobile app · 2025

#9

QR code menus are something eighty percent of customers hate anyway. People run out of battery or they don't have internet reception. And now with this security risk on top of it switching back to high-quality, wipeable, stylish printed menus could be both safer and more prestigious for your business.

ÖÖzgür A***ExpertCommunity member
Joined
Feb 2025
Message
1
#10

This incident should not be taken lightly; under data protection legislation, the compromise of your customers' financial data on your premises can result in severe penalties. Tie physical inspections to a written procedure and include them in daily checklists signed off by branch managers.

AAlper A***MemberCommunity member
Joined
Aug 2024
Message
137
#11

I didn't know that.

EEmine G***Member
Job title
Quality control inspector
Sector
Accounting & advisory
Organization type
cooperative
Joined
Dec 2025
Message
296

Doki · Phishing awareness training · 2024

#12

You're right.

ÖÖmer N***MemberCommunity member
Joined
Jun 2022
Message
62
#13

Thanks for posting.

ÖÖzge T***Member
Job title
Quality control inspector
Sector
Jewelry
Organization type
workshop
Joined
Feb 2023
Message
193
#14

Just a heads-up. The biggest time-waster for us was not knowing who had the final say.

Good luck with that.

PPolat A***MemberCommunity member
Joined
Apr 2023
Message
413
#15

thanks for writing this, thats the right way. honestly just because everyone does it doesnt mean its right.

just leeaving this note it might be useful.

CCaner Ş***Member
Job title
Operations director
Sector
E-commerce
Organization type
8-person team
Joined
Mar 2025
Message
36
#16

I partly agree, partly disagree. Just because everyone does it doesn't mean it's right.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

PPerihan K***MemberCommunity member
Joined
May 2023
Message
124
#17

We experienced almost the exact same thing last year. The answer varies greatly by industry; there is no one-size-fits-all rule.

If I were you, I'd go this route.

LLeyla Y***ExpertCommunity member
Joined
May 2025
Message
102
#18

I'll argue the opposite, don't get mad. If permission and scope aren't in writing, don't start that test.

If you post the result here, it will help others too.

DDoruk K***Expert
Job title
Quality Assurance Manager
Sector
Construction
Organization type
20-person company
Joined
Feb 2024
Message
28
#19

We need to take it step by step. Everything goes well for the first three months; problems arise in the fourth.

Of course, it varies if your situation is different.

HHalil A***MemberCommunity member
Joined
Dec 2024
Message
89
#20

Let me summarize what's been said so far. Your time to detect an issue directly determines its cost.

That's all, sorry if I went on too long.

Reply