Risk & Fraud

QR code program fraud: every attack, and the control that stops it

Every QR program leaks. The question is how much, through which mechanism, and whether the control you are about to add costs more in blocked honest members than it saves. Zero leakage is achievable and always too expensive, because the controls required suppress genuine participation harder than they suppress fraud.

Scan patterns being analysed for fraud across a QR code program

The nine common QR program attacks are pre-sale bulk scanning at the counter, photographed code sharing, sequential code guessing, GPS spoofing, device farms, recycled or unprinted codes, insider code leaks, collusive rings, and counterfeit product carrying cloned codes. Placement of the code inside the pack removes the largest single loss; the rest need tunable detection with review rather than hard blocking.

The nine attacks

AttackHow it worksPrimary control
Pre-sale bulk scanningCounter staff scan cartons before saleMove the code inside the primary pack — placement, not detection
Photographed code sharingCodes circulate in WhatsApp groupsSingle-use codes bound to the first valid claimant
Sequential guessingCodes incremented and claimedSparse non-sequential keyspace with a check digit
GPS spoofingLocation faked to defeat geo rulesDevice attestation, network-derived location, velocity across claims
Device farmsMany virtual devices claiming at scaleDevice fingerprinting, behavioural timing analysis
Unprinted or rejected codesValid codes that never reached a productReconcile generated, printed and shipped; invalidate rejects
Insider leaksCode lists exported from inside the chainAccess logging, hashed storage, no bulk export without approval
Collusive ringsDealer, member and sometimes a field executive coordinatingNetwork analysis on shared devices, VPAs, accounts, locations
Cloned codes on fakesReal code reprinted onto counterfeit productScan-count monitoring; treat invalid clusters as intelligence

Placement beats detection — and most budgets get this backwards

Pre-sale harvesting is usually the single largest loss category, and it is a packaging problem. A code under a cap or inside a primary pack eliminates it at essentially zero ongoing cost. An anomaly engine watching an externally printed code is expensive, imperfect, and generates false positives against honest members. Fix the physical design first and use analytics for the residue.

Detecting bulk scanning

The signature is distinctive once you look for it. Genuine field scanning is irregular — a plumber scans in bursts as he works, moves between sites, and takes breaks. Counter bulk-scanning produces:

  • Machine-like intervals — scans spaced within a second or two of each other, repeatedly.
  • Static location across hundreds of scans, resolving to shop coordinates.
  • Sequential batch mapping — codes from one carton scanned in production order.
  • No installation lag. Real scanning is spread over hours; a carton scanned end to end in four minutes was not installed.
  • Recurrence at the same coordinates month after month, across supposedly different members.

Setting an acceptable leakage rate

Program typeAcceptable leakageDominant risk
Influencer scan-to-earn, internal codes3–5% of poolBulk scanning with dealer collusion
Influencer scan-to-earn, external codes8–15% of poolPre-sale harvesting — fix placement
Retailer invoice-linked1–3% of poolClaim concentration, cross-territory arbitrage
Installer registration4–8% of poolGhost claims, evidence reuse
High-value milestones< 2% of valueCoordinated rings; worth manual verification

Decide the number before launch, measure monthly, and treat a breach as a design question rather than an enforcement one. Leakage of 14% on an internally coded program means something structural is wrong that a stricter rule will not fix.

Intervene without damaging the program

  1. Hold, do not block. Mark the reward pending and explain why, in the member's language. A member stopped mid-job in front of a customer becomes a story that circulates for months.
  2. Investigate before clawback. Reversing a credited reward without explanation is the most damaging action available to a program operator.
  3. Give a human appeal route. Genuine edge cases exist — a large contract job, a member helping a colleague scan.
  4. Explain outcomes. Honest members judge the program by how the accused are treated, and they compare notes.
  5. Fix the cause. Every confirmed pattern should end in a design change, not only an enforcement action.

The dividend nobody counts

A well-instrumented QR program produces a live map of where invalid codes are being scanned — which is where counterfeit product is circulating, often months before the sales team hears about it. Route those clusters to brand protection weekly and the fraud system stops being purely a cost centre. More in anti-counterfeit plus loyalty in one QR and the general framework in loyalty program fraud prevention.

Frequently asked questions

How do you stop bulk scanning of QR codes at the counter?

Primarily by moving the code inside the primary pack or under a cap so it cannot be reached before sale — this is a packaging fix, not a detection one, and it removes the largest loss category at near-zero ongoing cost. Then add geo-clustering, velocity caps and dealer-pattern detection for the residue.

How can you tell bulk scanning from genuine field scanning?

Genuine scanning is irregular, spread over hours, and moves between locations. Bulk scanning shows machine-like intervals of a second or two, a static location resolving to shop coordinates, codes scanned in carton production order, no installation lag, and recurrence at the same coordinates month after month.

What leakage rate is acceptable in a QR program?

Typically 3 to 5% of pool for influencer programs with internal codes, 1 to 3% for retailer invoice-linked schemes, and 4 to 8% for installer registration. Externally coded influencer programs often run 8 to 15%, which is a signal to change the packaging rather than tighten the rules.

Can GPS location be faked in a loyalty app?

Yes, GPS spoofing is straightforward on Android. Defences include device attestation, cross-checking network-derived location against GPS, and analysing velocity across successive claims — a member cannot plausibly scan in two districts within an hour regardless of what the GPS reports.

Should fraudulent claims be blocked automatically?

No. Hold them as pending with a clear explanation in the member's language and route them to human review. Blocking an honest member mid-job in front of a customer produces a story that circulates for months and costs more participation than the disputed amount is worth.

What should happen to invalid code scans?

They should be logged, mapped and routed to brand protection weekly rather than simply rejected. Clusters of invalid scans in a geography indicate counterfeit product carrying cloned or fabricated codes, and the loyalty program is usually the earliest detection system a brand has.

Want this running for your brand?

Unotag mirrors your channel structure in a sandbox within 48 hours — your SKUs, your slabs, your states.

Related reading