The Guardia Civil has issued a warning to diners about the potential dangers of scanning QR codes to access restaurant menus.
The force urged people to take a few seconds to check the code before opening it amid the risk that criminals could use fraudulent QR codes to direct victims to malicious websites.
In a cybersecurity warning published on Saturday, the Guardia Civil used the familiar scenario of sitting down at a restaurant terrace and scanning the QR code on the table to view the menu.
The force advised customers to first check whether a sticker has been placed over the restaurant’s original QR code.
Criminals can potentially place their own QR code over a legitimate one, meaning customers who believe they are opening a menu are instead directed elsewhere.
Three things to check
The Guardia Civil urged diners to inspect the physical QR code before scanning it, particularly for signs that another sticker has been placed on top.
Customers should then check the web address that opens on their phone and make sure it appears legitimate.
And if the resulting website unexpectedly begins requesting personal or financial information, users should leave it.
‘If it starts asking for information that doesn’t make sense, get out,’ the Guardia Civil warned in its message.
It summed up the risk with a play on restaurant terminology, warning that ‘even a menu can come with ‘ingredients’ you didn’t order.’
The advice forms part of the force’s wider efforts to educate the public about cybercrime and online fraud.
The Guardia Civil maintains dedicated online safety and anti-scam guidance for the public.
The warning does not mean restaurant QR codes themselves are unsafe.
The risk arises when a legitimate code has been tampered with or replaced, or when a QR code directs the user to a fraudulent website designed to obtain information.
