Scam was on me

Webiste with AI Videos, misleading KBO Numbers, and Paid Google Ads: How Modern Times Scams Rise to the Top with a help of Aps.

Scammed by a Quishing-Deepfake: My Heating Oil Fraud Experience with an AI Website. A Sophisticated Modern Scam for Security Professionals and Financial Institutions.

A fall doesn’t erase years of practice; it just reminds you to get back up.

A dark, cyberpunk-style digital artwork depicting a glowing QR code surrounded by red warning icons, a holographic AI face, and shadowy human silhouettes — symbolizing AI-driven scams, deepfakes, and QR code fraud.
Digital illustration symbolizing AI-driven scams, deepfakes, and QR code fraud in the modern cyber landscape.

Disclaimer: All facts shared here are true and reflect my personal experience. This post is for informational purposes only and is not legal, financial, or professional advice. This detailed account offers a candid breakdown of a sophisticated modern scam involving QR codes, deepfakes, and AI identity theft. It is an essential read for security professionals and financial institutions who need to understand the latest fraud tactics and the systemic challenges faced by victims.

Detailed analysis of a 664 Euro fraud case involving a fake framer website, QR code payment, and a Bunq refund attempt. Protect yourself from “quishing” attacks.


Link to News Article in Dutch

  • How secure are instant or fast payment methods, like QR codes?
  • What is the reliability of a company website based solely on a valid Chamber of Commerce number (KBO)?
  • How can we reliably verify the identity of the recipient before making a payment? OR What mechanisms are in place to ensure we pay the intended recipient?

The greatest threat lies in the fusion of technologies. The Quishing-Deepfake tactic leverages a secure-looking QR code to bypass bank safeguards, while relying on AI-driven impersonation to establish trust.

In August 2025 I was a victim of a fraud. Online order of Heating oil in a value of 664 euros never delivered.
Here are the steps I took.


Jwoil.com: Was the first in Google Search Ads section.

€0.19 €1.13 is the CPC according to Google Ads Keyword planner.

Payment was done via QR code from BNP PARIS bank

When I realized that I had paid someone other than JW Oil, I called BNP PARIBAS to stop the transaction.
While the transaction was still pending and the money still in my account, BNP couldn’t do anything.

Fraudulent interaction

Was done via WhatsAPP, business account. WA Account data are not visible.
Supposedly, since I was one of the first victims, they said they would issue me a refund via bank transfer. They claimed on Friday it would be processed in a batch.

Report fraud to Cyber Security service SafeOnWeb Belgium

The very same day I reported the issue to SafeOnWeb (Belgium) at https://safeonweb.be/nl

The answer tomorrow:

Beste,

De missie en het mandaat van het CCB omvatten alle veiligheidsaspecten van cyberveiligheid en meer bepaald de preventie/remediëring.
Het vermelde incident betreft oplichting via een valse webshop, ons mandaat geeft ons enkel de bevoegdheid om actie te ondernemen als het misdrijf computers en netwerken treffen als doelwit.

Wij raden aan om volgende acties uit te voeren: 

Contacteer Cardstop en je bank
Als je credit- of bankkaartgegevens hebt doorgegeven, contacteer onmiddellijk je bank voor het blokkeren van jouw rekening. Op deze website kan je de telefoonnummers per bank terugvinden: https://cardstop.be/nl-be/home/wat-blokkeren .
Voor het blokkeren van je kaart kan je terecht bij Cardstop op 078/170.170. 

Betwist de aankoop (enkel voor Visa & Mastercard)
Betwist de aankoop via https://mijnkaart.be/nl/home/kunnen-we-je-helpen/services/aankoop-betwisten.html

Dien klacht in bij de politie
Wij raden je aan om een klacht in te dienen bij je lokaal politiekantoor. De politie heeft de bevoegdheid om een onderzoek op te starten. Voor meer info kan je hier terecht: https://www.safeonweb.be/nl/een-aangifte-doen-bij-de-politie

Meld fraude bij het meldpunt
Wij raden je aan om alle vormen van fraude te melden bij het meldpunt voor fraude: https://consumerconnect.be/nl

Hoe kan je dit voorkomen?
Het ECC, de organisatie die instaat voor hulp en advies aan consumenten in Europa, helpt u bij het herkennen van een echte webshop. 
https://www.eccbelgie.be/themas/onlineaankopen/doe-de-webshopcheck

Tips voor het herkennen van een valse webshop:
https://www.safeonweb.be/nl/shop-veilig-online

Met vriendelijke groeten,

Google Trust & Safety Team – report scam ads

29.8.2025

Dear Slaven,

We’re writing to let you know that we reviewed your report (ID 299145047649627840).

Here’s what we found

We decided not to take this ad down. We found that the ad doesn’t go against Google’s policies, which prohibit certain content and practices that we believe to be harmful to users and the overall online ecosystem.

(If you have additional information that might help us reverse this decision, you can let us know by reporting this ad again within six months, or you can learn about your other options to dispute this decision.)

Called again the BNP Bank and they suggested since there is a communication going on between us to hold for a Bank fraud report and wait 3 days.

File Fraud Report at Police Station. Report Scam Face-to-Face

I went to the police station in Mol, Belgium in the morning, and explained the early stage of the fraud. Even though I was already scammed, I asked if they could act to prevent further harm.
He just said:
Make an appointment online.

I went home and earliest appointment was in two weeks.

ECC Belgium – European Consumer Centre Belgium – consumer rights

I called them and explaining the case-
Answer:


Since is Belgian KBO (crossroads bank for enterprises ) number they are not entitled to do any further investigation.

They advised me to file a report via Police on Web (Belgian online police service).

Error Submitting Online Fraud Case – Police Website

I tried two times to send.

When not successful I contacted them via the btn in the red DIV.

Answer came tomorrow

Kopie van uw aanvraag

Goeiedag,

Hieronder vindt u een kopie van uw aanvraag dat u via het contactformulier van Police on Web hebt verstuurd.
Bedankt dat u dit formulier hebt gebruikt om ons te helpen het probleem dat zich heeft voorgedaan op te lossen. Als uw aangifte vandaag nog in behandeling moet worden genomen, neem dan contact op met uw lokale politie.

NaamSlaven Fanfani
E-mailadressfanfani@gmail.com
BerichtBeste, ik heb geprobeerd het formulier in te vullen, maar er klopt iets niet. Ik hoop dat de transcriptie bij deze e-mail zit. Als ik op verzenden druk, komt de melding contacteer ons. Mvg Slaven Fanfani

Met vriendelijke groeten,
Het Police on Web team

When I asked did I send and fraud report they answer me:

Beste,

Helaas zijn wij niet bevoegd om uw aangifte te verwerken. Wij staan gewoon in voor het technisch aspect van de website.

Wij onderzoeken nog waarom u een foutmelding ontvangt. Tot nu toe kunnen we hier nog geen antwoord op geven.

Wij contacteren u terug begin volgende week indien wij de oorzaak van uw probleem hebben kunnen vinden.

Anders zal u inderdaad het best uw aangifte rechtstreeks bij de politie in Mol doen.

Alvast een fijn weekend,

Met vriendelijke groeten,

Het Police on Web team

They are just investigating an error.

Report Scam Website on Framer

When I reported the JWOIL to the Framer since is build on their platform I got an answer.

D**** from Framer5 Sept 2025, 16:53

from support@framer.com

Hi Slaven! 👋
Thank you for reaching out to us.
It appears that no account or subscription is associated with the provided email address. If you used a different email address for your account, kindly inform us so that we can assist you accordingly.
Best regards, D*** E*******
Visit Academy or Help

Users can report scam or fraudulent websites hosted on Framer to help prevent fraud and protect other users but first pay for it.

At the very end I did started via

Bank BNP Protect yourself from fraud and phishing

I called them again and submitted a fraud case so they can start doing an inspection.

Submitting a fraud case at

ConsumerConnect and I got a report nr.

The Consumer Mediation Service Belgium

When reported this is the answer.

Aan Slaven Fanfani, 

Wij hebben uw verzoek om informatie goed ontvangen en grondig doorgenomen. 

De Consumentenombudsdienst bemiddelt bij geschillen tussen consumenten en ondernemingen. Met de medewerking van beide partijen zoeken wij naar een oplossing voor een geschil. Alles staat of valt met de bereidwilligheid van de partijen om tot een oplossing te komen. Wij kunnen niets verplichten.  

Wij geven geen juridisch advies en spreken ons niet vooraf uit over een zaak om onze onpartijdigheid en neutraliteit te waarborgen. Mocht u later besluiten een beroep op ons te doen, dan zullen wij uw dossier voorleggen aan de tegenpartij en hun reactie afwachten. Vervolgens zullen we proberen een oplossing te vinden, uiteraard met inachtneming van de geldende wetgeving. 

Wij zijn niet gemachtigd om te beoordelen of bepaalde handelspraktijken oneerlijk zijn, het algemene functioneren van een onderneming te onderzoeken, of hier acties tegen te ondernemen. Dit valt onder de bevoegdheid van de Economische Inspectie, die eventueel een onderzoek kan openen en administratieve sancties kan opleggen. U kan hen inlichten via ConsumerConnect.  (wat u reeds deed).

Voor specifieke informatie over uw rechten en plichten als consument of de interpretatie van de wet, kan u terecht bij ConsumerConnect of op het gratis nummer 0800 120 33. 

Als u gratis juridische hulp of informatie wenst, kunt u terecht bij advocaat.be.  

Hopend u hiermee van dienst te zijn geweest. 

Met vriendelijke groeten, 

Met vriendelijke groeten

Called & e-mailed:

  • FOD Economie, K.M.O., Middenstand en Energiehttp://www.economie.fgov.be/nl
  • European Consumer Centre Belgium – Not their jurisdiction since is KBO Belgian
  • https://www.federaalombudsman.be/nl – Related Just for the Government cases.
  • Consumentenombudsdienst –
  • ConsumerConnect – reporeted and verified
  • Google Trust & Safety Team – Two reports/ Denied

Bank paying QR Codes maybe Not Safe to Use – Security Risks Explained by BNP Paris bank.

When you make wire transfers trough our app or website there will be an automatic check if the name that you give in for the beneficiary corresponds with the name that is actually on the account of the beneficiary. This is however not the same as you do a a payment with QR code

Kind regards,
Written Media Officer

Google Ads payed by

Screenshot example of scammer paying for Google Ads
Learn how scammers can pay for Google Ads to promote fraudulent schemes. Discover tips to identify and avoid ads funded by scammers to protect yourself online.

When I follow the link to ConsumerConnect, I get an error saying the report does not exist or that I don’t have sufficient permission to view the page.

I have also reported them to BUNQ and they say wait two days, they never came back to me. However, they did confirm that a bank can stop a transaction while it’s still pending.

Mazout Fraud in the news

I got a cover page photo next to the GVA and full 3rd page.


Read the article in GVA by Stijn Janssen foto: JOREN DE WEERDT

Mollenaar voor honderden euro’s opgelicht bij aankoop stookolie: “Dat ik er als ervaren IT’er ben ingetrapt, bewijst hoe professioneel de daders te werk gaan”

LInk:

If this can happen to me, it can happen to anyone—stay informed, stay cautious, and report scams when you see them.
Don’t blindly trust Google Ads or bank QR codes. Like I did.

Q&A

Why not paying with creditcard? Then is insured you i….!

bunq app is fraud

Minimum quantity 1000L will be always over 500Euros

The Website is fraud, you can see it.

The website had everything to be trustworthy

  • KBO number
  • Reviews
  • Videos and images
  • Jobs opening with related information about the topic
  • etc…

How is it possible that you’ve been in IT so long and this still happens!?

If you fall after riding all your life, it’s not failure — it’s just another lesson on the road. Would you stand up and embarrass yourself in front of an audience, publicly saying, “I was tricked”? Well I did, read the news article.

How did you find it?

Click the first result on Google. Since Google Ads cannot be misleading—or at least Google tries to prevent it.

Did you contact BUNQ?

Yes directly via e-mail. They also asked me to OPEN an account to start chating with them.

Hello Slaven,

Thank you for reaching out with your inquiry.

I understand you would like to verify the validity and executability of the transaction details you provided. For security reasons and to ensure your personal information stays safe, we can only review and discuss transaction details through our secure in-app chat.

Please log into your bunq app and ping us there so that we can take a closer look and guide you through the necessary steps. This way, we can provide you with more detailed information regarding your transaction and any actions that may be required.

Thank you for your understanding.

Best regards,
bunq support
 

APP Chat

  • I’ll need to ask a colleague for help with this situation, but first I need to make sure I completely understand what’s happening so I can connect you with the right person.
  • Since this payment was made from your BNP Paribas account (not from a bunq account), bunq cannot process a chargeback or dispute for this transaction.


AI assistant for bunq support.

Option 1: Contact BNP Paribas First

Since the payment originated from your BNP Paribas account, start there:

  • Contact BNP Paribas immediately and request a payment recall
  • Explain that you sent money to the wrong recipient or were defrauded
  • They may be able to initiate a recall through the SWIFT network
  • This is often the fastest route for external bank transfers

BUNQ report a fraud

Important Notes:

  • bunq cannot guarantee money recovery as it depends on recipient cooperation
  • If this was fraud, report it to both banks and consider filing a police report
  • Keep all documentation of your attempts to recover the funds
  • Start with BNP Paribas first since they processed your original payment – they have the most direct ability to help you recover funds sent from your account.
  • The fraud team typically reviews these types of cases within approximately 2 business days. This specialized team is better equipped to address fraud situations and provide guidance on next steps.

A fraud specialist will review your case and contact you within approximately 2 business days with an update.

No reply / No response

bunq.me links can become inactive for several reasons – they might expire, be deactivated by the recipient, or become invalid after a payment is completed.

  • If this payment was related to a bunq.me link that’s now showing an error, the link becoming inactive doesn’t change where the money went – it would still show in your BNP Paribas transaction history.

After the BUNQ QR went offline, did they have another payment option?

Yes — wire transfer to a German or Italian IBAN…

I asked BUNQ.

If the recipient deletes the transaction ID/reference on their side, can bunq still trace the payment? Can you (or the police) obtain the transaction logs afterwards?

Yes, absolutely. Here are the key points about transaction tracing:

bunq’s Records Are Permanent

Once a payment leaves your bunq account, we maintain complete and permanent records that cannot be altered or deleted by anyone – including the recipient. These records include all transaction details, timestamps, and routing information.

What the Recipient Cannot Delete

The recipient has no ability to delete or modify:

  • bunq’s transaction logs
  • The SEPA payment trail between banks
  • Our system’s record of sending the payment
  • Banking network routing information

Even if they delete information on their own banking system, this doesn’t affect the permanent trail that exists in the broader banking network.

Law Enforcement Access

Banks like bunq maintain transaction records in compliance with legal obligations (WWFT and European legislation). Law enforcement can access these records through proper legal channels when investigating fraud cases.

Your Specific Situation

Given the fraud case you’ve been discussing, all the evidence you’ve shared – the payment details, company connections, and transaction records – exists permanently in our systems. This information would be available to support any investigation, regardless of what actions the recipient companies might take on their end.

The banking system is designed with these permanent audit trails specifically to prevent fraud and support investigations when needed

Ultimately, this case provides a valuable, candid breakdown of a sophisticated modern scam. The difficulty in obtaining recourse highlights the urgent need for security professionals and financial institutions to implement stronger protections against AI fraud and ‘quishing’ attacks

Disclaimer

The information shared here reflects my personal experiences and factual events as I observed them. It is intended for informational purposes only and does not constitute legal, financial, or professional advice.

While I have aimed to provide accurate information, readers should verify facts independently. Any references to financial institutions, transactions, or ongoing investigations are based on my own experience and publicly available information.

I am not providing confidential or proprietary information, and I am not speaking on behalf of any organization. For guidance regarding ongoing legal or financial matters, or before taking any action based on this content, please consult a qualified professional.

Slaven Fanfani
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.