tacobellstore[.]shop presents itself as an official Taco Bell merchandise destination.
The site uses Taco Bell trademarks, copied product imagery, and a fabricated support association with the legitimate Taco Shop.
Private Recon findings / Taco BellOuttake connected an active unauthorized Taco Bell merchandise store to copied assets, a prior deployment, shared storage, and concentrated hosting.
Every finding preserves the report's confidence, status, and attribution boundary. Exposure is not attribution, and co-hosting is not campaign size.
The site uses Taco Bell trademarks, copied product imagery, and a fabricated support association with the legitimate Taco Shop.
Shared Cloudflare R2 naming, repeated image paths, and origin timing support the report's same-operator and same-codebase conclusion. The domain was offline during the investigation.
Campaign assets connect to an R2 image origin and hosting at 91[.]246[.]50[.]210 on AS199242. Co-hosting does not attribute every neighboring domain.
Relationship map is sanitized. Sensitive operator and victim details remain off-page.
These are investigation and enforcement paths, not guarantees of removal.
Walk through the source evidence with Outtake and discuss how the same workflow can extend across Yum!'s external surface.