Why Customers Hesitate Before Scanning Your QR Code
QR Codes

Why Customers Hesitate Before Scanning Your QR Code

03 Sept 2026 8 min read

In the first three months of 2026, QR codes became the fastest-growing way to deliver a phishing attack by email. Microsoft's telemetry counted 7.6 million attacks carrying a QR code in January and 18.7 million in March — a 146% rise in a single quarter, while classic malicious attachments were sliding to around 5% of attacks.

Then something less widely reported happened: it went back down. Across the second quarter the same telemetry recorded 17.4 million in April, 10.8 million in May and 8.3 million in June. QR codes pasted into the body of an email, which had surged 336% in March, effectively vanished. The codes had moved inside attachments instead — PDFs accounted for 58% of QR payloads by June, Word documents for 40%, according to Microsoft’s own quarterly breakdown.

The attack did not stop working. It changed shape. And it left behind something no security report measures: a lot of people who now pause for a second before pointing a phone at a square in the real world. That pause is not a security problem. It is a small-business problem, and it belongs to the café, the market stall and the restaurant that printed an honest code.

The trust you never spent is the trust you now pay

A customer standing at your table cannot inspect a QR code. There is no hover preview, no address bar to read before committing, no way to tell a code that leads to your menu from a code that leads to a credential-harvesting page dressed as your menu. The decision takes about two seconds and it is made entirely on context: does this code look like part of the place, does it say where it is going, and does what happens next match what was promised?

That is why the physical version of the attack is so cheap to run. The US Federal Trade Commission described it in a consumer alert back in December 2023, and the example it used has become the canonical one: scammers cover a legitimate QR code with a sticker of their own, on parking meters and in other places where people expect to scan and pay. A sticker costs cents. It only has to survive one shift.

Nothing about that requires sophistication, which is precisely the point. The defence is not technical either. It is physical, editorial, and mostly about habits.

The sticker test

Ask one question about every code you have in the world: how long would it take someone to cover this with their own? If the answer is under five seconds and nobody would notice until closing time, that code is doing your reputation a favour it cannot afford.

What raises the cost of the attack: codes printed into the material rather than stuck onto it — on the menu card itself, on the laminated table talker, etched into the acrylic stand, part of the packaging artwork. A code that is visibly integral to the object is hard to overlay convincingly. A code on a plain white label is not.

Then make the check cheap for your own staff. Photograph each code when it goes out, so there is a reference image to compare against. Know how many codes you have and where they are — most venues do not. Add one line to the closing routine: look at the codes. A member of staff who knows the code should be printed, not stuck, spots an overlay in a glance.

Say where it goes, before it is scanned

The single most effective trust signal costs nothing to print: words next to the code that name the destination. “Scan for today's menu — ourplace.com” tells the customer what to expect and gives them something to check against once the page opens. A code with no label asks for blind faith, which is exactly what a scam asks for too.

This is also the argument for keeping the address readable. If your code resolves to a random string of characters, nobody can confirm anything. If it resolves to something recognisable — your own domain, or a short link with a slug that names what it is — the address itself carries the message. On paid plans you can serve the page from a subdomain you own, so the address in the customer's browser is your brand rather than ours.

One more thing that belongs on the label: what happens next. “Menu”, “Wine list”, “Leave a review”. A code that promises a menu and delivers a menu is a trust deposit. A code that promises a menu and asks for an email address is a withdrawal.

Nothing behind a table code should ask for a card or a password

This is the rule with the widest gap between how obvious it sounds and how often it is broken. Every time a legitimate business puts a payment form or a login behind a QR code in a public place, it teaches customers that this is normal — and that lesson is the entire business model of the parking-meter scam.

Keep the two things apart. A QR code on a table is for information: the menu, the allergen list, the wine list, the booking page on your own domain. Payment belongs to your point of sale, or to a provider the customer already recognises, initiated by a member of staff. If you genuinely need pay-at-table, put it behind something a scammer cannot replicate with a sticker and a printer.

A dead code teaches the same lesson as a scam

Printed things outlive the URLs printed on them. Menus get reorganised, seasonal pages come down, sites get rebuilt, and the code on the table keeps pointing wherever it was pointing in 2024. A customer who scans and lands on a 404 learns something specific: the codes here do not work. That is functionally the same conclusion as the codes here are not safe, and it arrives without any attacker involved.

Which is why the choice between a static and a dynamic code is a trust decision, not a technical one. A static code has the destination baked into the pattern: it works with no service behind it and nothing can be logged, but it can never be corrected and you cannot see whether anyone scanned it. A dynamic code points at a link you control, so the destination can be maintained for as long as the printed object exists. We wrote up the trade-off in detail in static vs dynamic QR codes, and the practical version for anything already printed is on editable QR codes after printing.

What we check, and what we cannot

Honesty is part of the trust argument, so here is where ours ends. Every destination shortened through ShareCut is screened against Google Safe Browsing at the moment it is created, and a URL that comes back flagged is refused rather than shortened. That is a real check and it is not a guarantee: a page that is clean today can be compromised next month, and no scan-time badge can promise otherwise.

A code that points at a ShareCut table page or a menu can have its contents rewritten by the owner at any time, on the free plan included — dishes, prices, sections. That is the case where you never reprint, because the address never changes and the content does. Re-pointing a plain short link at a different destination is available through the API on the Business plan; in the web editor the destination of an existing short link stays fixed today, which is deliberate but worth knowing before you print. And a static code — a Wi-Fi payload, a plain text code — has nothing to update and nothing to monitor. That is the trade you accept in exchange for depending on nobody.

The five-minute check, once a month

  1. Walk the room and look at every code you own. Sticker, or printed into the material?
  2. Scan three of them yourself, from a phone that is not logged into anything of yours.
  3. Read the address that appears before you tap through. Is it the one you expect?
  4. Confirm the page still loads, still looks current, and still asks for nothing.
  5. Check the code still scans at the distance customers actually use — across a table, through a window, under a dim light.

Five minutes. It is the same routine whether you have four codes or four hundred, and it is the only part of QR trust that nobody can do for you.

Questions we get

Can you change a QR code link after it has been printed?

Only if the code points at a link you control rather than at the destination itself. A static code has the address inside the pattern and cannot be changed once printed. A code built on a short link keeps working while the destination behind it is maintained — see editable QR codes after printing.

Is a QR code less safe than a link?

The code is not the risk; the missing preview is. A link on a screen can be read before it is clicked, and a printed code cannot. That is the whole difference, and it is why the label next to the code does so much work.

Should small businesses stop using QR codes?

No. Scans still convert better than typing an address, and the 2026 numbers describe email campaigns rather than table cards. What changed is that the burden of proof moved to you: the code has to look trustworthy before it is scanned, not after.

Does a tracked code tell me whether someone tampered with it?

Not directly, but the pattern shows. Scans that stop dead on one code while the others keep going is worth a walk to that table. Click and scan data is per link, alongside country, device and referrer.

If you want to start from a code that is maintainable rather than one you will have to reprint, the QR generator is free and produces both kinds — dynamic when the destination may change, static when it must not depend on anyone. Plans and limits are on the pricing page.

#qr codes#small business#restaurants#trust#security