QR codes and phishing

A fake QR code is impersonating your business: what to do about menus, payments, and reviews

A sticker or image can replace a restaurant, parking, event, or counter’s authentic QR code and send customers to a fake site for payment, login, software

Leer en español

A sticker or image can replace a restaurant, parking, event, or counter’s authentic QR code and send customers to a fake site for payment, login, software download, or data collection.

EXECUTIVE SUMMARY

What decision-makers should know

A sticker or image can replace a restaurant, parking, event, or counter’s authentic QR code and send customers to a fake site for payment, login, software

    Stop use and preserve the code

    If a sticker covers a menu, parking meter, table, sign, ticket, or checkout QR code, prevent further scans. Photograph the code in context, including adhesive, surface, date, and location, then remove it without destroying it when safe. Do not scan it with an employee’s phone to investigate.

    Use security personnel or an appropriate isolated tool to decode the URL without visiting the destination. Preserve the domain, path, parameters, and redirects only through safe methods. Compare them with the official link and determine whether a physical code was replaced or a digital file, email, PDF, or company account was altered.

    Inspect every equivalent placement, including other branches, tables, signs, invoices, flyers, and posts. Assign each code an identifier and record who verified it. Do not publish the suspicious QR image as a warning: a clear screenshot may remain scannable and turn the warning into another route to the scam.

    • Photo and location of the QR code
    • Decoded URL without opening it
    • Authentic code and domain
    • Inspection date and scope
    • Reported payments or data

    Understand the customer risk

    The FTC warns that a QR code can lead to a copied site that steals credentials or installs malware and has documented false codes covering parking meters. The FBI advises caution with random or visibly altered codes and pages requesting passwords after scanning. Physical placement inside a business does not establish authenticity.

    Identify what the destination requested: payment, card details, password, authentication code, download, permissions, identity document, or review. A code redirecting to a different review page can affect reputation; payment collection is a financial incident; software installation requires technical response. Each risk involves different providers and warnings.

    Do not blame an employee, competitor, or visitor without evidence. Preserve relevant camera footage and records under applicable rules, limit access, and separate facts from theories. Personal data, payment, or malware exposure should involve security, privacy, finance, and qualified support appropriate to the country.

    Help anyone who scanned it

    Someone who opened the page but entered nothing should close it, avoid downloads, and obtain security guidance if permissions were granted. Anyone who entered a password should change it from a clean device, review sessions, and enable additional authentication. An installed app or profile requires device-specific help.

    Anyone who paid or disclosed card data should immediately contact the bank or provider through a verified number, preserve the amount, time, merchant, and reference, and follow its instructions. In the United States, the FBI accepts fraud reports through IC3 and the FTC through ReportFraud.ftc.gov; Spain, Mexico, and other countries have their own channels. Recovery is not guaranteed.

    The business should collect only necessary information through a secure channel. Never request full card numbers, passwords, identity documents, or unredacted screenshots. Record how many people reported the problem, which action they took, and which provider was notified. This guide does not determine breach or notification duties.

    Repair, report, and prevent recurrence

    Replace codes only after verifying the domain and test each with a controlled device. Use a short official page that clearly displays the brand and destination, inventory all placements, and add inspection to opening and closing routines. Avoid opaque shorteners when seeing the domain helps customers verify it.

    Report each related domain, host, payment account, advertisement, or profile separately and preserve references. Publish a dated notice on the website and premises identifying authentic locations and domains without showing the false code. Explain which information you never request and how a menu or payment can be verified.

    ReputationGeo.ai can organize evidence, map domains, prepare bilingual reports and warnings, and monitor reappearances. Hosts, registrars, banks, platforms, and authorities decide independently. We do not guarantee removal, identification, financial recovery, or timing. Responsible response combines physical and digital security, privacy, and reputation.

    How to turn this guidance into a responsible plan

    Begin with evidence, not assumptions. Save the exact URLs, screenshots, publication dates, search phrases, review profiles and AI answers that are creating concern. Record where each item appears, who controls the source and whether the information is inaccurate, outdated, private, misleading or simply unfavorable. These distinctions matter because removal, correction, response, suppression and monitoring are different remedies. A credible adviser should explain those differences before recommending work or discussing timing.

    Next, define the audience and the decision at risk. A result seen by prospective clients in Spain may require different language, sources and local signals from a result affecting investors in the United States. Decide which names, brands, locations and search questions matter most. Prioritization prevents a campaign from becoming a vague attempt to control the internet and turns it into a measurable program focused on accuracy, trust and discoverability.

    Evidence, people and measurements to prepare

    Create a baseline before changes begin. It can include the first two pages of Google for agreed searches, ratings and review volume, visibility of owned pages, recurring themes in AI answers and the status of platform or publisher requests. Keep personal data to the minimum necessary and share sensitive documents only through an agreed secure process. If a legal right may apply, involve qualified counsel in the relevant jurisdiction; reputation strategy does not replace legal advice.

    Assign an owner for approvals, factual verification and customer responses. Review progress consistently, but do not judge the program by one daily ranking. Useful measures include corrected or removed items, response completion, the share of credible owned and independent sources, search-result composition, branded query trends and whether public information answers real questions. The objective is a more accurate and resilient digital record, not an artificial promise that criticism will disappear.

    Keep a decision record, not just a list of links

    For every material item, record the exact source, the factual concern, the person responsible for verification, the proposed route and the reason that route is proportionate. Include the date of any request, response deadline, platform reference number and next review date. This record prevents duplicate or contradictory reports and helps a new decision-maker understand why an item was corrected, challenged, answered, monitored or left alone.

    A sound record also separates confirmed facts from interpretations. Label legal questions for qualified counsel, service failures for operational owners and public explanations for communications review. If an item changes, preserve the before-and-after evidence without collecting more personal data than necessary. This discipline is especially important when search engines and AI systems update unpredictably: it shows what actually changed and avoids claiming credit for movements that may have several causes.

    • Source, URL, date and affected search or prompt
    • Verified facts, disputed claims and supporting evidence
    • Chosen route, owner, status and next review date
    • Privacy, amplification and escalation risks

    Related ReputationGeo.ai services

    Use these service pages to distinguish image removal, broader content removal and search delisting before choosing a route.

    Frequently asked questions

    Official sources and further reading

    Rules and procedures change. Check the current official guidance before submitting a request.

    The practical next step

    Document the relevant URLs, searches and facts before acting. A responsible plan should separate what can be corrected or removed from what needs response, suppression or monitoring. The correct approach depends on the source, market and evidence.

    Apply the guide to your specific situation.

    Send the public links and the market affected. We will explain the realistic options and dependencies.

    Protected by a hidden spam-control field. No advertising trackers are loaded with this form.