Webiste with AI Videos, misleading KBO Numbers, and Paid Google Ads: How Modern Times Scams Rise to the Top with a help of Aps.
Scammed by a Quishing-Deepfake: My Heating Oil Fraud Experience with an AI Website. A Sophisticated Modern Scam for Security Professionals and Financial Institutions.
A fall doesn’t erase years of practice; it just reminds you to get back up.
Digital illustration symbolizing AI-driven scams, deepfakes, and QR code fraud in the modern cyber landscape.
Disclaimer: All facts shared here are true and reflect my personal experience. This post is for informational purposes only and is not legal, financial, or professional advice. This detailed account offers a candid breakdown of a sophisticated modern scam involving QR codes, deepfakes, and AI identity theft. It is an essential read for security professionals and financial institutions who need to understand the latest fraud tactics and the systemic challenges faced by victims.
Detailed analysis of a 664 Euro fraud case involving a fake framer website, QR code payment, and a Bunq refund attempt. Protect yourself from “quishing” attacks.
How secure are instant or fast payment methods, like QR codes?
What is the reliability of a company website based solely on a valid Chamber of Commerce number (KBO)?
How can we reliably verify the identity of the recipient before making a payment? OR What mechanisms are in place to ensure we pay the intended recipient?
Security questions about modern financial fraud. Quishing-Deepfake
The greatest threat lies in the fusion of technologies. The Quishing-Deepfake tactic leverages a secure-looking QR code to bypass bank safeguards, while relying on AI-driven impersonation to establish trust.
In August 2025 I was a victim of a fraud. Online order of Heating oil in a value of 664 euros never delivered. Here are the steps I took.
Jwoil.com: Was the first in Google Search Ads section.
€0.19 €1.13 is the CPC according to Google Ads Keyword planner.
Warning about potential risks of clicking Google Ads, emphasizing safety and verifying purchases.
Payment was done via QR code from BNP PARIS bank
When I realized that I had paid someone other than JW Oil, I called BNP PARIBAS to stop the transaction. While the transaction was still pending and the money still in my account, BNP couldn’t do anything.
Fraudulent interaction
Was done via WhatsAPP, business account. WA Account data are not visible. Supposedly, since I was one of the first victims, they said they would issue me a refund via bank transfer. They claimed on Friday it would be processed in a batch.
Fake refund attempt directed to me via BUNQ
Report fraud to Cyber Security service SafeOnWeb Belgium
The very same day I reported the issue to SafeOnWeb (Belgium) at https://safeonweb.be/nl
The answer tomorrow:
Beste,
De missie en het mandaat van het CCB omvatten alle veiligheidsaspecten van cyberveiligheid en meer bepaald de preventie/remediëring. Het vermelde incident betreft oplichting via een valse webshop, ons mandaat geeft ons enkel de bevoegdheid om actie te ondernemen als het misdrijf computers en netwerken treffen als doelwit.
Wij raden aan om volgende acties uit te voeren:
Contacteer Cardstop en je bank Als je credit- of bankkaartgegevens hebt doorgegeven, contacteer onmiddellijk je bank voor het blokkeren van jouw rekening. Op deze website kan je de telefoonnummers per bank terugvinden: https://cardstop.be/nl-be/home/wat-blokkeren . Voor het blokkeren van je kaart kan je terecht bij Cardstop op 078/170.170.
Dien klacht in bij de politie Wij raden je aan om een klacht in te dienen bij je lokaal politiekantoor. De politie heeft de bevoegdheid om een onderzoek op te starten. Voor meer info kan je hier terecht: https://www.safeonweb.be/nl/een-aangifte-doen-bij-de-politie
Meld fraude bij het meldpunt Wij raden je aan om alle vormen van fraude te melden bij het meldpunt voor fraude: https://consumerconnect.be/nl
We’re writing to let you know that we reviewed your report (ID 299145047649627840).
Here’s what we found
We decided not to take this ad down. We found that the ad doesn’t go against Google’s policies, which prohibit certain content and practices that we believe to be harmful to users and the overall online ecosystem.
(If you have additional information that might help us reverse this decision, you can let us know by reporting this ad again within six months, or you can learn about your other options to dispute this decision.)
Called again the BNP Bank and they suggested since there is a communication going on between us to hold for a Bank fraud report and wait 3 days.
File Fraud Report at Police Station. Report Scam Face-to-Face
I went to the police station in Mol, Belgium in the morning, and explained the early stage of the fraud. Even though I was already scammed, I asked if they could act to prevent further harm. He just said: Make an appointment online.
I went home and earliest appointment was in two weeks.
ECC Belgium – European Consumer Centre Belgium – consumer rights
I called them and explaining the case- Answer:
Since is Belgian KBO (crossroads bank for enterprises ) number they are not entitled to do any further investigation.
They advised me to file a report via Police on Web (Belgian online police service).
Error Submitting Online Fraud Case – Police Website
Users encounter an error while trying to submit a fraud report through the police website. It may be necessary to report the case in person at the local station.
I tried two times to send.
When not successful I contacted them via the btn in the red DIV.
Answer came tomorrow
Kopie van uw aanvraag
Goeiedag,
Hieronder vindt u een kopie van uw aanvraag dat u via het contactformulier van Police on Web hebt verstuurd. Bedankt dat u dit formulier hebt gebruikt om ons te helpen het probleem dat zich heeft voorgedaan op te lossen. Als uw aangifte vandaag nog in behandeling moet worden genomen, neem dan contact op met uw lokale politie.
Beste, ik heb geprobeerd het formulier in te vullen, maar er klopt iets niet. Ik hoop dat de transcriptie bij deze e-mail zit. Als ik op verzenden druk, komt de melding contacteer ons. Mvg Slaven Fanfani
Met vriendelijke groeten, Het Police on Web team
When I asked did I send and fraud report they answer me:
Beste,
Helaas zijn wij niet bevoegd om uw aangifte te verwerken. Wij staan gewoon in voor het technisch aspect van de website.
Wij onderzoeken nog waarom u een foutmelding ontvangt. Tot nu toe kunnen we hier nog geen antwoord op geven.
Wij contacteren u terug begin volgende week indien wij de oorzaak van uw probleem hebben kunnen vinden.
Anders zal u inderdaad het best uw aangifte rechtstreeks bij de politie in Mol doen.
Alvast een fijn weekend,
Met vriendelijke groeten,
Het Police on Web team
They are just investigating an error.
Report Scam Website on Framer
When I reported the JWOIL to the Framer since is build on their platform I got an answer.
D**** from Framer
5 Sept 2025, 16:53
from support@framer.com
Hi Slaven! Thank you for reaching out to us. It appears that no account or subscription is associated with the provided email address. If you used a different email address for your account, kindly inform us so that we can assist you accordingly. Best regards, D*** E******* Visit Academy or Help
Users can report scam or fraudulent websites hosted on Framer to help prevent fraud and protect other users but first pay for it.
At the very end I did started via
Bank BNP Protect yourself from fraud and phishing
I called them again and submitted a fraud case so they can start doing an inspection.
Wij hebben uw verzoek om informatie goed ontvangen en grondig doorgenomen.
De Consumentenombudsdienst bemiddelt bij geschillen tussen consumenten en ondernemingen. Met de medewerking van beide partijen zoeken wij naar een oplossing voor een geschil. Alles staat of valt met de bereidwilligheid van de partijen om tot een oplossing te komen. Wij kunnen niets verplichten.
Wij geven geen juridisch advies en spreken ons niet vooraf uit over een zaak om onze onpartijdigheid en neutraliteit te waarborgen. Mocht u later besluiten een beroep op ons te doen, dan zullen wij uw dossier voorleggen aan de tegenpartij en hun reactie afwachten. Vervolgens zullen we proberen een oplossing te vinden, uiteraard met inachtneming van de geldende wetgeving.
Wij zijn niet gemachtigd om te beoordelen of bepaalde handelspraktijken oneerlijk zijn, het algemene functioneren van een onderneming te onderzoeken, of hier acties tegen te ondernemen. Dit valt onder de bevoegdheid van de Economische Inspectie, die eventueel een onderzoek kan openen en administratieve sancties kan opleggen. U kan hen inlichten via ConsumerConnect. (wat u reeds deed).
Voor specifieke informatie over uw rechten en plichten als consument of de interpretatie van de wet, kan u terecht bij ConsumerConnect of op het gratis nummer 0800 120 33.
Als u gratis juridische hulp of informatie wenst, kunt u terecht bij advocaat.be.
European Consumer Centre Belgium – Not their jurisdiction since is KBO Belgian
https://www.federaalombudsman.be/nl – Related Just for the Government cases.
Consumentenombudsdienst –
ConsumerConnect – reporeted and verified
Google Trust & Safety Team – Two reports/ Denied
Bank paying QR Codes maybe Not Safe to Use – Security Risks Explained by BNP Paris bank.
QR codes can be exploited by scammers to redirect users to malicious websites or install malware. Exercise caution before scanning unknown QR codes.
When you make wire transfers trough our app or website there will be an automatic check if the name that you give in for the beneficiary corresponds with the name that is actually on the account of the beneficiary. This is however not the same as you do a a payment with QR code
Kind regards, Written Media Officer
Google Ads payed by
Learn how scammers can pay for Google Ads to promote fraudulent schemes. Discover tips to identify and avoid ads funded by scammers to protect yourself online.
When I follow the link to ConsumerConnect, I get an error saying the report does not exist or that I don’t have sufficient permission to view the page.
I have also reported them to BUNQ and they say wait two days, they never came back to me. However, they did confirm that a bank can stop a transaction while it’s still pending.
Mazout Fraud in the news
I got a cover page photo next to the GVA and full 3rd page.
Read the article in GVA by Stijn Janssen foto: JOREN DE WEERDT
If this can happen to me, it can happen to anyone—stay informed, stay cautious, and report scams when you see them. Don’t blindly trust Google Ads or bank QR codes. Like I did.
Q&A
Why not paying with creditcard? Then is insured you i….!
Minimum quantity 1000L will be always over 500Euros
The Website is fraud, you can see it.
The website had everything to be trustworthy
KBO number
Reviews
Videos and images
Jobs opening with related information about the topic
etc…
How is it possible that you’ve been in IT so long and this still happens!?
If you fall after riding all your life, it’s not failure — it’s just another lesson on the road. Would you stand up and embarrass yourself in front of an audience, publicly saying, “I was tricked”? Well I did, read the news article.
How did you find it?
Click the first result on Google. Since Google Ads cannot be misleading—or at least Google tries to prevent it.
Did you contact BUNQ?
Yes directly via e-mail. They also asked me to OPEN an account to start chating with them.
Hello Slaven,
Thank you for reaching out with your inquiry.
I understand you would like to verify the validity and executability of the transaction details you provided. For security reasons and to ensure your personal information stays safe, we can only review and discuss transaction details through our secure in-app chat.
Please log into your bunq app and ping us there so that we can take a closer look and guide you through the necessary steps. This way, we can provide you with more detailed information regarding your transaction and any actions that may be required.
Thank you for your understanding.
Best regards, bunq support
APP Chat
I’ll need to ask a colleague for help with this situation, but first I need to make sure I completely understand what’s happening so I can connect you with the right person.
Since this payment was made from your BNP Paribas account (not from a bunq account), bunq cannot process a chargeback or dispute for this transaction.
AI assistant for bunq support.
Option 1: Contact BNP Paribas First
Since the payment originated from your BNP Paribas account, start there:
Contact BNP Paribas immediately and request a payment recall
Explain that you sent money to the wrong recipient or were defrauded
They may be able to initiate a recall through the SWIFT network
This is often the fastest route for external bank transfers
BUNQ report a fraud
Important Notes:
bunq cannot guarantee money recovery as it depends on recipient cooperation
If this was fraud, report it to both banks and consider filing a police report
Keep all documentation of your attempts to recover the funds
Start with BNP Paribas first since they processed your original payment – they have the most direct ability to help you recover funds sent from your account.
The fraud team typically reviews these types of cases within approximately 2 business days. This specialized team is better equipped to address fraud situations and provide guidance on next steps.
A fraud specialist will review your case and contact you within approximately 2 business days with an update.
No reply / No response
bunq.me links can become inactive for several reasons – they might expire, be deactivated by the recipient, or become invalid after a payment is completed.
If this payment was related to a bunq.me link that’s now showing an error, the link becoming inactive doesn’t change where the money went – it would still show in your BNP Paribas transaction history.
After the BUNQ QR went offline, did they have another payment option?
Yes — wire transfer to a German or Italian IBAN…
I asked BUNQ.
If the recipient deletes the transaction ID/reference on their side, can bunq still trace the payment? Can you (or the police) obtain the transaction logs afterwards?
Yes, absolutely. Here are the key points about transaction tracing:
bunq’s Records Are Permanent
Once a payment leaves your bunq account, we maintain complete and permanent records that cannot be altered or deleted by anyone – including the recipient. These records include all transaction details, timestamps, and routing information.
What the Recipient Cannot Delete
The recipient has no ability to delete or modify:
bunq’s transaction logs
The SEPA payment trail between banks
Our system’s record of sending the payment
Banking network routing information
Even if they delete information on their own banking system, this doesn’t affect the permanent trail that exists in the broader banking network.
Law Enforcement Access
Banks like bunq maintain transaction records in compliance with legal obligations (WWFT and European legislation). Law enforcement can access these records through proper legal channels when investigating fraud cases.
Your Specific Situation
Given the fraud case you’ve been discussing, all the evidence you’ve shared – the payment details, company connections, and transaction records – exists permanently in our systems. This information would be available to support any investigation, regardless of what actions the recipient companies might take on their end.
The banking system is designed with these permanent audit trails specifically to prevent fraud and support investigations when needed
Ultimately, this case provides a valuable, candid breakdown of a sophisticated modern scam. The difficulty in obtaining recourse highlights the urgent need for security professionals and financial institutions to implement stronger protections against AI fraud and ‘quishing’ attacks
Disclaimer
The information shared here reflects my personal experiences and factual events as I observed them. It is intended for informational purposes only and does not constitute legal, financial, or professional advice.
While I have aimed to provide accurate information, readers should verify facts independently. Any references to financial institutions, transactions, or ongoing investigations are based on my own experience and publicly available information.
I am not providing confidential or proprietary information, and I am not speaking on behalf of any organization. For guidance regarding ongoing legal or financial matters, or before taking any action based on this content, please consult a qualified professional.