Skip to content
Back to blog
Security10 min

How to Spot Fake Event Tickets

Warning signs, what the Criminal Code and the Unfair Competition Act say, and which controls stop a fake ticket reaching your event's door.

by Ulises Rodríguez

Tech Lead

Quick answer

A fake ticket isn't spotted by looking at it, but by validating it against the system that issued it. The early warning signs are a price well below market rate, payment outside the official channel via bank transfer or instant payment apps, and a seller with no verifiable contact details. At the door, what settles it is real-time duplicate detection.

A fake ticket isn't spotted by looking at it, but by validating it against the system that issued it. The early warning signs are a price well below market rate, payment outside the official channel via bank transfer or instant payment apps, and a seller with no verifiable contact details. At the door, what settles it is real-time duplicate detection.

The problem has a technical name and a public catalogue. The OWASP Foundation classifies the automated hoarding of limited-availability goods as threat OAT-005 "Scalping", defined as "obtain limited-availability and/or preferred goods/services by unfair methods", and it explicitly names the ticketing sector: "Ticket scalping; Ticket resale; Ticket touting; Secondary ticketing." A fake ticket is the final link in that chain: first the supply is hoarded or scarcity is faked, then something that doesn't exist gets sold.

What are the warning signs of a suspicious ticket?

Spotting a fake ticket isn't always straightforward, but there are indicators that can help you catch potential fraud before it reaches your event's doors.

  • Low-quality or pixelated QR codes that don't scan properly
  • Tickets sold well below market price, a classic sign of concert ticket fraud
  • Sellers who refuse to provide verifiable contact details
  • Multiple tickets with the same design but small variations
  • Tickets offered through unofficial channels with no guarantee of authenticity

The most consistent signal isn't on the ticket itself, but in the payment. In a real case documented by INCIBE involving fraudulent resale of tickets for a well-known singer's concert, contact starts on Instagram, moves to WhatsApp and ends with an instant transfer to a private individual; the scammer then claims a transaction error to get paid twice before blocking the victim. INCIBE's recommendation is direct: "Use reliable, verified platforms that offer buyer protection in cases of fraud." It also flags something organisers often forget to mention in their own warnings: instant transfers to individuals typically can't be reversed.

There's a variant that doesn't even need tickets to exist. In another real case, INCIBE describes how a fake ticket giveaway is used to steal WhatsApp accounts: the prize is offered from a fake Instagram profile, the victim is asked for the verification code received by SMS, and that code is used to hijack the account and ask their contacts for money. If your event runs a ticket giveaway, say so clearly through your official channels and repeat that you'll never ask for a verification code.

How many fake tickets are actually out there?

There's no public Spanish statistic that measures this. No official body publishes what percentage of secondary-market tickets are fake, so any round figure circulating without a source should be treated as a marketing claim rather than data. What does exist are official case files, documented incidents and one clear statement from the regulator.

Spain's competition authority, the CNMC, reviewed the draft Sustainable Consumption Bill under reference IPN/CNMC/053/25 and, in its public statement of 11 March 2026, recommends "prioritising measures to improve the transparency and reliability of ticket resale services before imposing direct price limits." Translated into what an organiser can act on: the regulator believes the secondary-market problem is better tackled through traceability and reliable channels than through price caps, and that's exactly the lever you control without waiting for any new law.

The other verifiable data point is operational. INCIBE documents a case involving fraudulent ticket sales and bot-driven seat blocking, combining two attacks at once: fake websites copying "logos and elements of its corporate identity" and bots that block seats en masse to make an event look sold out. The countermeasures it recommends are standard practice for any exposed web application: traffic filtering, CAPTCHA and purchase limits per IP address, alongside gathering evidence, reporting it and issuing a public warning through the organiser's own channels.

What does Spanish law say about fake tickets and bots?

Selling a fake ticket is fraud. Article 248 of the Criminal Code punishes anyone who, for financial gain, brings about an act of property disposal through deception, to another's detriment. The ticket doesn't need to be printed: charging for access that doesn't exist is enough.

Mass bot purchasing has its own recent rule. Article 27.6 of Law 3/1991, of 10 January, on Unfair Competition classes as an aggressive practice any conduct that "consists in reselling event tickets to consumers or users where the trader acquired them using automated means to bypass any limit imposed on the number of tickets a person may purchase, or any other rule applicable to ticket purchases" ("consistan en la reventa de entradas de espectáculos a los consumidores o usuarios si el empresario las adquirió empleando medios automatizados para sortear cualquier límite impuesto al número de entradas que puede adquirir cada persona o cualquier otra norma aplicable a la compra de entradas"). That clause was added by Royal Decree-Law 24/2021 and has been in force since 28 May 2022. In other words: the per-buyer limit you set on your primary sale isn't a commercial preference, it's the requirement that makes bypassing it unlawful. The full framework is covered in the guide on Spanish ticket resale legislation.

That leaves the question of the deceived buyer. They can't claim a refund from the organiser, because there was never a contract between them: the money went to a third party. It's also worth noting that Article 103.l) of the recast General Law for the Defence of Consumers and Users excludes leisure services from the right of withdrawal where the contract specifies a particular date or period of performance. The buyer's route is a police report and a claim with the payment provider; the organiser's is to be able to show which tickets it issued and which it didn't.

What anti-fraud technology goes beyond the QR code?

A QR code on its own is just a printed number: it can be photographed, forwarded and printed as many times as needed. What stops the fraud isn't the symbol, it's the layers behind it.

  • A unique identifier per ticket, generated cryptographically with no traceable relationship to the others. A sequential number from 1 to 5,000 can be guessed; a signed identifier can't.
  • Online validation against the central database, not against a list downloaded the day before. If the door reader is working from an outdated copy, a second copy of a ticket will get through.
  • Real-time duplicate detection, blocking the second attempt and logging the time and access point where it happened.
  • Named tickets with official transfer of ownership, so legitimate resale happens within the system rather than in a chat.
  • Per-buyer ticket limits and bot controls on primary sales, the measures INCIBE recommends against automated seat blocking.

Set out in a table, each layer closes a different gap:

LayerFraud it stopsWhat happens without it
Signed unique identifierTickets invented from scratchThe code is guessed from the pattern and forged
Online validation with central databasePrinted or forwarded copiesA reader with an outdated list accepts the copy
Duplicate detectionSame ticket used twiceWhoever arrives first gets in and the rightful holder is left outside
Named ticket with official transferUncontrolled resaleThe ticket circulates untracked all the way to the door
Per-buyer limit and bot controlsAutomated hoardingSold-out status is faked and the parallel market is fed

The Futura Tickets app validates a QR code in 1-2 seconds, a speed that matters because the temptation to skip validation shows up the moment a queue forms. None of these layers rely on door staff visually recognising a fake ticket, a skill that simply doesn't exist when the forgery is a perfect screenshot of the original.

Why does ticket traceability matter?

Full traceability of every ticket is essential to fighting fraud. Technologies such as blockchain applied to ticketing have been put forward to strengthen this capability, though in practice a centralised issuer register solves the same problem. When you can follow a ticket's journey from issue through to use at the event, spotting anomalies becomes far simpler. This includes recording who bought the ticket, whether it was transferred, how many times it changed hands, and any failed validation attempts.

  • Recording the full chain of custody
  • Automatic alerts for suspicious behaviour
  • Immediate blocking of compromised tickets
  • Detailed reports for post-event analysis

That traceability is also what the CNMC is calling for when it talks about "transparency and reliability of resale services." A resale marketplace of your own, with a price cap and a registered change of ownership, turns every resale into an auditable transaction instead of a blind exchange between strangers. That's the logic behind controlled resale.

What should you do at the door when a duplicate is flagged?

When the reader flags that a ticket has already been used, there's someone standing in front of you who could be a scammer or a victim, and staff have no way of knowing which. A written protocol, rehearsed before the event, stops the door turning into a trial.

  1. 1Pull the incident out of the main flow. A side resolution point staffed by someone trained for it keeps the queue moving and lowers the tension.
  2. 2Log the attempt with time, access point and code. That record is the proof of which ticket was issued, when it was used, and through which channel it was sold.
  3. 3Check the origin of the purchase. If the ticket came from your system and has already been validated, it's a duplicate; if it never existed in your database, the sale happened elsewhere and the buyer is a victim.
  4. 4Don't accuse or detain anyone. Documenting the incident and, where appropriate, reporting it to the police is the route INCIBE recommends; arguing at the door isn't.
  5. 5Only ask for the data you need. Collecting ID to handle an incident is personal data processing with its own legal basis and retention period, as explained in the guide on GDPR for event organisers.

What best practices should organisers follow?

Alongside having the right technology in place, there are practices every organiser should adopt to minimise the risk of fraud.

  • Use only ticketing platforms with built-in anti-fraud verification
  • Communicate clearly to attendees which channels are official
  • Implement controlled resale policies to discourage the black market
  • Train your access team to recognise suspicious tickets
  • Keep an open channel for attendees to report fraud

Two communication habits are worth adding to that list. First: publish the list of official channels on the same page where you announce the event, and repeat it in every reminder, because a buyer searching for sold-out tickets on Instagram won't visit your website. Second: raise the alarm publicly as soon as you spot a cloned website or a profile impersonating your brand, and report the URLs, which is exactly what INCIBE recommends to affected organisers.

Checklist before opening the doors

Check that your readers validate online, and have a plan for what happens if connectivity drops: pause the queue, run in degraded mode, or defer validation with later syncing.

Rehearse the duplicate scenario with your access team before the event, with a two-line script for the attendee and a named person responsible for handling incidents.

Review the per-buyer ticket limit on your primary sale: it's the measure protected by Law 3/1991 and the one that curbs automated hoarding.

Publish your official channels on the event page, on social media and in reminder emails, with a warning that you'll never ask for verification codes or instant payments to individuals.

Keep the validation log with time and access point: it's what backs up any later police report and any attendee complaint.

Have your crisis communication ready for a cloned website scenario: the message, the channels and who to report it to.

Conclusion

Preventing ticket fraud takes a combination of technology, written processes and constant communication with your audience. There's no such thing as zero fraud, but a system with a unique identifier, online validation and duplicate detection shuts out almost everything that would otherwise reach the door, protecting both your reputation and your attendees' experience. Clarity does the rest: the more visible your official channel is, the less room there is for anyone selling what they don't have. Read up on Spanish ticket resale legislation to strengthen your legal strategy.

Sources

Share

Frequently asked questions

How can you spot a fake ticket before the event?
There are several warning signs: low-quality or pixelated QR codes that don't scan properly, tickets priced well below market rate, sellers who won't provide verifiable contact details, and tickets offered through unofficial channels with no guarantee of authenticity. The signal that keeps coming up in real cases documented by Spain's national cybersecurity institute (INCIBE) is payment outside the official channel, sent directly to an individual by bank transfer or instant payment app.
What anti-fraud technology do ticketing platforms use?
Professional platforms layer several security measures: cryptographically generated unique identifiers, real-time validation against centralised databases, and duplicate-detection systems that flag any attempt to use the same ticket more than once. This goes well beyond a simple QR code.
Why does ticket traceability matter?
Full traceability lets you follow each ticket from issue through to use at the event, making it far easier to spot anomalies. That includes recording who bought the ticket, whether it was transferred, how many times it changed hands, and any failed validation attempts. With named tickets, that record also identifies the holder.
Is selling a fake ticket a criminal offence?
Yes. Selling a ticket that doesn't grant access to the event falls under the offence of fraud in Article 248 of Spain's Criminal Code: obtaining, for financial gain, an act of property disposal through deception. In addition, since 28 May 2022, Article 27.6 of Law 3/1991 on Unfair Competition classes the resale of tickets bought using bots as an aggressive commercial practice.
Can the buyer of a fake ticket claim a refund?
Not from the organiser, because the organiser never sold them anything: the money went to a third party. The route is to file a police report and a claim with the payment provider. It's worth remembering that Article 103.l) of the recast General Law for the Defence of Consumers and Users excludes leisure services with a set date from the right of withdrawal.
Can ticket fraud be eliminated entirely?
There's no such thing as zero fraud, but the amount that reaches the door can be cut drastically. The combination that works is tickets with a unique identifier, online validation with duplicate detection, clearly communicated official channels, and a written protocol for the access team when an issue comes up.

About the author

Ulises Rodríguez

Tech Lead

Tech Lead at Futura Tickets. Keeps the platform running in production: backend (NestJS/Node), the Stripe payments integration, deployments on Google Cloud and the team's code reviews.

Ready to protect your event?

Discover how Futura Tickets can help you eliminate ticket fraud.

Request free demo