NFC Solutions

Are NFC Tags Safe? A Security Guide for Review Cards, Menus and QR Codes in South Africa

IT-Support-SA Team 10 min read
In this article
  1. 01 The Short Answer
  2. 02 What an NFC Tag Actually Is (and Is Not)
  3. 03 The Four Real Risks
  4. 04 NFC vs QR Codes: Which Is Safer?
  5. 05 Check Your Own Tags
  6. 06 How to Lock Down Your Tags
  7. 07 What About Tap-and-Pay Cards?
  8. 08 If You Think a Tag Has Been Tampered With
  9. 09 How IT-Support-SA Handles It
  10. 10 Mistakes That Leave Tags Exposed
  11. 11 Conclusion

Are NFC tags safe? It is the question a careful business owner asks before putting a review card on the counter or a menu tag on every table, and it deserves a straight answer. For almost everything a business uses them for, yes, provided a few things are done properly. The risk is rarely the tag itself. It is the address the tag points to, who can change it, and whether anyone can slip a different tag or QR code in front of your customers. This guide explains what an NFC tag actually is, the four real risks, how NFC compares with QR codes (including the scam known as quishing), a seven-question safety check for your own tags and exactly how to lock them down.

The Short Answer

An NFC tag is a passive chip that stores a web address. It cannot carry a virus, it cannot hold a payment card number, and it only works from a few centimetres away. The real risks are an unprotected tag being rewritten, a fake tag or QR code being stuck over yours, the domain behind the tag lapsing and being taken over, and an insecure page behind the tag. Fix them by password-protecting every tag, pointing it at a domain you own with auto-renew on, mounting it where nothing can be stuck over it, and tapping each public tag once a month.

What an NFC Tag Actually Is (and Is Not)

A review card or menu tag contains a tiny chip and an antenna. It has no battery and no processor. When a phone comes within a few centimetres, the phone’s own signal powers the chip for a moment, the chip hands back the web address stored in it, and the phone opens that address. That is all it does.

That simplicity is the good news:

  • It cannot run code. There is nothing on the tag that can infect or take over a phone.
  • It holds no secrets worth stealing. The address on a review or menu tag is public by design. There is no card number, no password and no personal data on it.
  • It needs to be close. A criminal cannot read or trigger a tag from across the room.

Which leaves the question that matters: what happens when the address is wrong, or someone else controls it? That is where the four real risks come in.

The Four Real Risks

1. Someone rewrites the tag

Most tags can be written to as well as read. Unless the tag is protected, anyone with a phone and a free NFC app can overwrite it in a few seconds and point it at their own page. A card sitting on a counter or a tag on a table is in public, so this is the first thing to prevent.

The fix is built into common chips. NTAG213, NTAG215 and similar chips support a write password, so only whoever holds the password can change the address. A tag can also be locked permanently, but that is irreversible, which is why a password is usually the better choice.

2. Someone sticks a different tag or QR code over yours

This needs no technology at all. A criminal fixes their own tag or QR code over the genuine one, and your customers tap or scan theirs instead. It is an old trick with QR codes, and the same logic applies to NFC.

Mount public tags where a sticker cannot simply be added on top: laminated into a card, behind an acrylic cover, or inside a table stand. Then check them regularly, because the only defence against a tag you never look at is looking.

3. The address behind the tag is taken over

This is the most overlooked risk, and the one that does the most damage over time. A tag points at a web address. If you let that address lapse, anyone can register it, and from that moment they decide what every tag you have printed shows. The same goes for a free link-shortening service or a free QR service that changes its terms, expires or is hijacked: every tag stuck to it goes with it.

The cure is to point every tag at a domain you own, registered in your business’s name with automatic renewal switched on, and to redirect from there to the real page. That also means you can change the destination later without touching a single tag.

4. The page behind the tag is insecure

If a menu tag opens a page that takes orders, bookings or contact details, that page now holds personal information, and POPIA applies. An old order form left running on a neglected system is a ready-made way in. Keep the page on HTTPS, collect only what you need and maintain it like any other system that holds customer details. Our POPIA IT compliance checklist covers what reasonable security looks like.

NFC vs QR Codes: Which Is Safer?

Neither is safe or unsafe on its own, because both do the same job: send a phone to an address. The differences are small but real.

  • NFC works only at close range and can be password-protected so that only you can change it.
  • A printed QR code cannot be rewritten, but it can be covered with a fake one in seconds, and it hides the address until scanned.
  • QR codes can arrive by email or PDF, where they can slip past email filters that are built to read links, not pictures. This is called quishing, short for QR phishing, and it has become a standard criminal tool. Fake QR stickers fixed over genuine ones, on parking meters and restaurant tables for example, have been reported in several countries.

The sensible position for a business is the one we recommend for menus anyway: NFC as the main route, a QR code printed beside it as a fallback, and both pointing at an address you own. If you handle supplier payments, the same habit of checking where a link goes is exactly what stops fake banking-details emails — see our guide to invoice fraud and fake banking details emails.

Check Your Own Tags

Answer seven questions about the tags you use or are thinking of buying. Your result updates as you go.

INTERACTIVE CHECK
How safe are your tags?
Answer seven quick questions about your review cards, menu tags or QR codes. Your result updates as you go.
Are the tags protected against rewriting?
Is the address registered in your name, with auto-renew on?
Where do the tags point?
Are the tags in a holder or under a cover, so nothing can be stuck over them?
Does the page behind the tag collect personal details (orders, bookings, forms)?
How often do you tap-check the tags?
Where do the tags sit?
RESULT · EXPOSED Exposed: fix the top items first 54/100 risk One or more of these gaps could send customers to a page you did not choose. Start at the top of the list.
  1. 1 Ask your supplier to password-protect every tag. Without that, anyone with a phone and a free app can overwrite an unprotected tag in seconds and send your customers somewhere else.
  2. 2 Confirm that the domain behind your tags is registered in your business’s name and set to renew automatically. If it lapses, someone else can register it and show whatever they like at the address printed on every tag.
  3. 3 Point your tags at your own domain and redirect from there. A free shortener or QR service can expire, change its terms or be hijacked, and then every tag you have printed is stuck with it.
  4. 4 Mount public tags under laminate, inside an acrylic stand or behind a cover. A criminal’s tag or QR sticker can otherwise be fixed over yours, which is the oldest trick there is.
  5. 5 Tap every public tag once a month and look for anything stuck over it. It takes minutes and is how most tampering is caught.

The start-up answers describe a typical small-business setup: tags that nobody has checked for write protection, an address and domain whose ownership has never been confirmed, and no routine for looking at them. If that sounds familiar, the fixes in the next section take an afternoon.

How to Lock Down Your Tags

  1. Password-protect every tag when it is programmed, and keep the password with whoever manages the tags. Test one with a free NFC app to confirm you cannot overwrite it without the password.
  2. Point every tag at your own domain, not a free shortener or a free QR service, and redirect to the real page from there.
  3. Register that domain in your business’s name with automatic renewal on, and send the registrar’s reminders to an address that is read.
  4. Mount public tags under laminate, behind acrylic or in a stand, so nothing can be fixed over them and they cannot be peeled off.
  5. Keep a register of your tags: where each one is, what address it opens and who checks it. A single page is enough.
  6. Tap-check every public tag once a month, on an iPhone and an Android, and look for anything stuck on top.
  7. Use HTTPS-only pages behind the tags, and keep any page that collects details patched and maintained.
  8. Think before locking permanently. A permanent lock cannot be undone, so use it only for a tag whose address will genuinely never change.

Our guide to NFC for takeaways and restaurants applies the same points to queue tags and packaging stickers, and the buyer’s guide to choosing an NFC card supplier lists the questions to ask before you buy.

What About Tap-and-Pay Cards?

A review or menu tag is not a payment card. Contactless bank cards use a different, secure chip designed for transactions, with limits and protections controlled by your bank. A review tag holds a public web address and nothing that can be used to take money, so anxiety about contactless payment fraud does not carry over to it. If you have worries about your own bank cards, your bank’s controls and alerts are the place to start.

If You Think a Tag Has Been Tampered With

  1. Cover or remove the tag so no more customers use it.
  2. Tap it and see where it goes, without entering anything on the page. Take a screenshot of the address.
  3. Replace it with a fresh, password-protected tag, and check for a fake tag or sticker stuck over the original.
  4. Check the domain: who it is registered to, when it expires and whether the redirect still goes where you set it.
  5. Tell your staff, so they know what to look for, and check your other tags.
  6. If the page collected details, treat it as a possible data incident and see the response steps in our POPIA checklist.

How IT-Support-SA Handles It

Every tag we program is password-protected against rewriting and points at an address you control, so the destination can be changed without touching the tag. We tap-test each one on an iPhone and an Android in the position it will actually sit, mount public tags in holders, stands or under laminate, and give you a simple register of what is where. Installation is on site, with travel outside our main service areas quoted upfront. IT-Support-SA is an IT support company first, so the security side is not an afterthought: the same people who set up your network and Microsoft 365 set up your tags. See our Google Review NFC Cards page or send us an enquiry.

Mistakes That Leave Tags Exposed

  • Buying unprotected tags because they were cheap. Ask whether each one is write-protected.
  • Pointing tags at a free shortener or a free QR service that you do not control.
  • Letting the domain lapse because the renewal email went to someone who left.
  • Never looking at the tags after the day they were installed.
  • Locking tags permanently and then having to replace every one when a link changes.
  • Leaving an old order or booking page running on a system nobody maintains.
  • Treating the tag as the risk when the real risk is the address and the page behind it.

Conclusion

NFC tags are safe for the jobs businesses give them, because there is almost nothing on the tag to attack. What needs protecting is the thing around it: the write access, the physical spot, the domain and the page. Password-protect every tag, point it at an address you own, register that address properly, mount tags where nothing can be fixed over them, and tap each one once a month. Do that and the whole risk fits in an afternoon and a calendar reminder.

If you would like review cards, menu tags or guest hubs set up that way from the start, contact IT-Support-SA. We supply and install NFC cards and tags across Pietermaritzburg, the KZN Midlands, Durban, Ladysmith, Johannesburg, Cape Town and all 9 provinces of South Africa.

Frequently Asked Questions

Are NFC tags safe to use in my business?
Yes, when they are set up properly. An NFC tag is a small passive chip that stores a web address, so it cannot carry a virus or a payment card number. The real risks are about the address: who can change it, whether the domain behind it stays yours, and whether someone can stick a different tag over yours. Password protection, an address you own and a monthly tap-check cover all three.
Can an NFC tag be hacked or infect my phone?
A tag cannot infect a phone by itself. It has no battery and no processor, it only holds a small amount of data, and it only works from a few centimetres away. What it can do is send a phone to a web address, so the danger is a tag that points somewhere bad, not a tag that hacks the phone. Phones show or open the address, so look at where a tag takes you.
Can someone change what my NFC review card links to?
If the tag is not write-protected, yes: anyone with a phone and a free NFC app can overwrite it in seconds. Common chips such as NTAG213 support a write password, so only you can change the link. Ask your supplier to confirm that every tag is password-protected, and test one yourself with a free NFC app.
Is NFC safer than a QR code?
Neither is safe or unsafe by itself, because both just send a phone to an address. NFC has two advantages: it works only at close range, and a tag can be password-protected against rewriting. A printed QR code cannot be rewritten, but it is easy to cover with a fake one, and QR codes that arrive by email can slip past email filters. Whichever you use, own the address behind it.
What is quishing?
Quishing is phishing done with a QR code. A criminal puts a fake QR code on a poster, sticker or email, and anyone who scans it lands on a page built to steal a password or a payment. Stickers placed over genuine QR codes, for example on parking meters and restaurant tables, have been reported in several countries. Treat a QR code like a link in an email: check where it goes before you enter anything.
What happens if the domain behind my tags expires?
Anyone can register it once it lapses, and from then on they decide what every one of your tags shows. This is one of the most overlooked risks. Register the domain in your own business's name, switch on automatic renewal and keep the registrar's emails going to an address someone reads. Pointing tags at your own domain and redirecting from there also means you can change the destination without touching a single tag.
Should I lock my NFC tags permanently?
Usually not. A permanently locked tag can never be changed, even by you, so if your Google review link or menu address changes you would have to replace every tag. A write password gives you most of the protection while keeping the option to update, and pointing the tag at your own redirect means the destination can change without reprogramming at all. Lock a tag permanently only if its address will genuinely never change.

Need help with your IT?

Get a free IT audit from South Africa's trusted IT partner — no obligation, no jargon, just straight answers.

Related Articles