How we took down a QR code scam in 24 hours
Tabla de contenido
Why the scam started on paper
Fraudsters ran a fake investment advertisement in several national newspapers, carrying a major airline’s name and logo alongside a QR code that sent anyone who scanned it to a scam site. Print was a shrewd choice, because a QR code in a trusted newspaper inherits that trust in a single scan: there is no sender address to check and no link to preview on hover, just a printed square that lands the reader on a live web page. It hat short hop from paper to browser is the whole point of the tactic.
How we mapped the scam
Working from the flagged site, we mapped the operation end to end. We decoded the QR code circulating in the newspaper ads and traced its redirect chain through the shortener to the live page it served: a form hosted on Netlify, asking for name, phone number and email. That is a lead-collection form, and it matches the “call list” harvesting that feeds investment fraud. Victims hand over their details expecting a callback about an opportunity; what they get is unfortunately, a pipeline into a scam.
To rule out a false positive, we checked the hosting infrastructure against external threat intelligence. The IP address had already been reported as malicious ten times, by six independent sources. We documented the finding as a confirmed 3/4 Major incident and delivered the report to the client with everything needed to act.
| Indicator | Detail |
| Redirector (dynamic QR) | qrco[.]de/bgqORu |
| Phishing landing page | heartfelt-sable-2583f7[.]netlify[.]app |
| Alojamiento | Netlify |
| Registrar | Name.com, Inc. |
| Reputation | IP flagged malicious 10x across 6 independent sources |
| Categoría | Domain threat, phishing, fraud |
| Severity | 3/4 Major |
How we took it down in under 24 hours
We built the case on evidence, focusing on: the redirect chain, the harvesting form, the fraud pattern and the corroborating reputation data, submitted together as a single, documented request. In under 24 hours the page was gone, as you can see below it now returns a plain “Site not found.”
But overall what really matters here is speed, in the case of malicious activity that targets your brand. In all cases like the above our remediation team moves fast, taking down 95% of malicious domains without customer intervention, and cuts average time to takedown by 85% compared with self-managed processes. In this case, that meant hours rather than weeks for this particular takedown, and a harvesting form collecting victims’ details for a day less than it otherwise would have.
Why QR code scams are on the rise
This was not a one-off. QR code phishing, known as quishing, has moved from a niche trick to a mainstream fraud vector: UK Action Fraud recorded a 587% rise in quishing reports between 2023 and 2025, and Europol’s 2026 Internet Organised Crime Threat Assessment names it the fastest-rising payment-initiation attack in the EU.
Two things stand out in this example. Firstly it is that the vector is moving into trusted, offline channels, from printed ads to letters to stickers placed over real codes; trust is the payload. The second is that the scam pages increasingly drop brand impersonation altogether, because a generic, brand-free landing page is harder to flag and harder to take down, and that is precisely the point.
The economics explain the growth of these scams. There is a documented clear division of labor behind these campaigns: some actors build the sites and codes, some run the data collection, some handle the money, and some resell the harvested data. It is cheap to run, and it scales.
How one analyst closed the case in a day
From the moment our monitoring flagged the domain to the final takedown, we were able to own this case: decoding the code, tracing the redirect, classifying the threat, corroborating it against outside intelligence, and assembling the evidence a host would act on.
Nuestro Protección de marca customers can task our analysts directly on a specific threat like this one and stay in the loop at each step. We flagged it, we investigated it, and we drove it to removal in a day.
How to protect your brand from QR code scams
There are a few essential takeaways to stay safe when you are worrying about brand impersonation on or offline.
On a basic level these should include:
- Treating QR codes like links, because a printed code deserves the same “where does this actually go?”
- Checking you would give an unexpected email link.
- Expecting the harder cases to need human investigation as removing it depends on someone who can decode the redirect, prove the intent and make the case to the host.
- Making sure that someone can move quickly, because with these campaigns the gap between live and removed is where the damage happens.
If a scam is trading on your brand, our analysts can find it and drive the takedown.
Frequently asked questions
Quishing is phishing that uses a QR code in place of a clickable link. The code hides the destination URL inside an image, so email filters and readers cannot see where it leads until it is scanned. Attackers place these codes in emails, PDF invoices, office signage and printed ads. UK Action Fraud recorded a 587% rise in quishing reports between 2023 and 2025.
Yes. A takedown does not depend on a copied logo or a brand name in the domain. When neither is present, the case is built on evidence instead: the redirect chain, the data-harvesting form, the fraud pattern and third-party reputation data on the hosting infrastructure. That is how we removed the page in this incident, which carried no brand keyword and no visual impersonation.
Yes. Fake profiles that impersonate your brand run fraudulent giveaways, post fake discount codes and push followers toward phishing pages. Brand Protection detects impersonator accounts across the major social platforms and reports them with the detail needed for a platform takedown request, alongside fraudulent domains and rogue mobile apps.
t varies by registrar and host, but speed is the metric that matters. Our remediation team takes down 95% of malicious domains without customer intervention and cuts average time to takedown by 85% compared with self-managed processes. In this case, the page was offline in under 24 hour
