QR code program fraud: every attack, and the control that stops it
Every QR program leaks. The question is how much, through which mechanism, and whether the control you are about to add costs more in blocked honest members than it saves. Zero leakage is achievable and always too expensive, because the controls required suppress genuine participation harder than they suppress fraud.

The nine common QR program attacks are pre-sale bulk scanning at the counter, photographed code sharing, sequential code guessing, GPS spoofing, device farms, recycled or unprinted codes, insider code leaks, collusive rings, and counterfeit product carrying cloned codes. Placement of the code inside the pack removes the largest single loss; the rest need tunable detection with review rather than hard blocking.
The nine attacks
| Attack | How it works | Primary control |
|---|---|---|
| Pre-sale bulk scanning | Counter staff scan cartons before sale | Move the code inside the primary pack — placement, not detection |
| Photographed code sharing | Codes circulate in WhatsApp groups | Single-use codes bound to the first valid claimant |
| Sequential guessing | Codes incremented and claimed | Sparse non-sequential keyspace with a check digit |
| GPS spoofing | Location faked to defeat geo rules | Device attestation, network-derived location, velocity across claims |
| Device farms | Many virtual devices claiming at scale | Device fingerprinting, behavioural timing analysis |
| Unprinted or rejected codes | Valid codes that never reached a product | Reconcile generated, printed and shipped; invalidate rejects |
| Insider leaks | Code lists exported from inside the chain | Access logging, hashed storage, no bulk export without approval |
| Collusive rings | Dealer, member and sometimes a field executive coordinating | Network analysis on shared devices, VPAs, accounts, locations |
| Cloned codes on fakes | Real code reprinted onto counterfeit product | Scan-count monitoring; treat invalid clusters as intelligence |
Placement beats detection — and most budgets get this backwards
Pre-sale harvesting is usually the single largest loss category, and it is a packaging problem. A code under a cap or inside a primary pack eliminates it at essentially zero ongoing cost. An anomaly engine watching an externally printed code is expensive, imperfect, and generates false positives against honest members. Fix the physical design first and use analytics for the residue.
Detecting bulk scanning
The signature is distinctive once you look for it. Genuine field scanning is irregular — a plumber scans in bursts as he works, moves between sites, and takes breaks. Counter bulk-scanning produces:
- Machine-like intervals — scans spaced within a second or two of each other, repeatedly.
- Static location across hundreds of scans, resolving to shop coordinates.
- Sequential batch mapping — codes from one carton scanned in production order.
- No installation lag. Real scanning is spread over hours; a carton scanned end to end in four minutes was not installed.
- Recurrence at the same coordinates month after month, across supposedly different members.
Setting an acceptable leakage rate
| Program type | Acceptable leakage | Dominant risk |
|---|---|---|
| Influencer scan-to-earn, internal codes | 3–5% of pool | Bulk scanning with dealer collusion |
| Influencer scan-to-earn, external codes | 8–15% of pool | Pre-sale harvesting — fix placement |
| Retailer invoice-linked | 1–3% of pool | Claim concentration, cross-territory arbitrage |
| Installer registration | 4–8% of pool | Ghost claims, evidence reuse |
| High-value milestones | < 2% of value | Coordinated rings; worth manual verification |
Decide the number before launch, measure monthly, and treat a breach as a design question rather than an enforcement one. Leakage of 14% on an internally coded program means something structural is wrong that a stricter rule will not fix.
Intervene without damaging the program
- Hold, do not block. Mark the reward pending and explain why, in the member's language. A member stopped mid-job in front of a customer becomes a story that circulates for months.
- Investigate before clawback. Reversing a credited reward without explanation is the most damaging action available to a program operator.
- Give a human appeal route. Genuine edge cases exist — a large contract job, a member helping a colleague scan.
- Explain outcomes. Honest members judge the program by how the accused are treated, and they compare notes.
- Fix the cause. Every confirmed pattern should end in a design change, not only an enforcement action.
The dividend nobody counts
A well-instrumented QR program produces a live map of where invalid codes are being scanned — which is where counterfeit product is circulating, often months before the sales team hears about it. Route those clusters to brand protection weekly and the fraud system stops being purely a cost centre. More in anti-counterfeit plus loyalty in one QR and the general framework in loyalty program fraud prevention.
Frequently asked questions
How do you stop bulk scanning of QR codes at the counter?
Primarily by moving the code inside the primary pack or under a cap so it cannot be reached before sale — this is a packaging fix, not a detection one, and it removes the largest loss category at near-zero ongoing cost. Then add geo-clustering, velocity caps and dealer-pattern detection for the residue.
How can you tell bulk scanning from genuine field scanning?
Genuine scanning is irregular, spread over hours, and moves between locations. Bulk scanning shows machine-like intervals of a second or two, a static location resolving to shop coordinates, codes scanned in carton production order, no installation lag, and recurrence at the same coordinates month after month.
What leakage rate is acceptable in a QR program?
Typically 3 to 5% of pool for influencer programs with internal codes, 1 to 3% for retailer invoice-linked schemes, and 4 to 8% for installer registration. Externally coded influencer programs often run 8 to 15%, which is a signal to change the packaging rather than tighten the rules.
Can GPS location be faked in a loyalty app?
Yes, GPS spoofing is straightforward on Android. Defences include device attestation, cross-checking network-derived location against GPS, and analysing velocity across successive claims — a member cannot plausibly scan in two districts within an hour regardless of what the GPS reports.
Should fraudulent claims be blocked automatically?
No. Hold them as pending with a clear explanation in the member's language and route them to human review. Blocking an honest member mid-job in front of a customer produces a story that circulates for months and costs more participation than the disputed amount is worth.
What should happen to invalid code scans?
They should be logged, mapped and routed to brand protection weekly rather than simply rejected. Clusters of invalid scans in a geography indicate counterfeit product carrying cloned or fabricated codes, and the loyalty program is usually the earliest detection system a brand has.