Yum! BrandsPrivate Recon findings / Taco Bell

One impersonation storefront. An earlier deployment. Shared campaign infrastructure.

Outtake connected an active unauthorized Taco Bell merchandise store to copied assets, a prior deployment, shared storage, and concentrated hosting.

Recon Agent / Taco BellMalicious / 0.95
1
ACTIVE DOMAIN
1
OFFLINE DEPLOYMENT
3
INVESTIGATED DOMAINS
61
EVIDENCE FILES
Investigation generated Aug. 24, 2026. Domains shown on this route are defanged.
01 / Sanitized findings

The storefront was one artifact in a connected deployment pattern.

Every finding preserves the report's confidence, status, and attribution boundary. Exposure is not attribution, and co-hosting is not campaign size.

Finding AMalicious / 0.95
Active impersonation storefront

tacobellstore[.]shop presents itself as an official Taco Bell merchandise destination.

The site uses Taco Bell trademarks, copied product imagery, and a fabricated support association with the legitimate Taco Shop.

ActiveTrademark misuseCopied imagery
Preserve evidence and coordinate provider reporting.
Finding BMalicious / 0.95
Original campaign deployment

tacobelltacoshop[.]shop is linked as the earlier deployment of the same storefront kit.

Shared Cloudflare R2 naming, repeated image paths, and origin timing support the report's same-operator and same-codebase conclusion. The domain was offline during the investigation.

OfflineShared R2Same codebase
Pivot on the shared artifacts to identify related deployments.
Finding CCorrelated / 0.95 to 0.99
Infrastructure concentration

Shared storage and hosting create higher-leverage response paths.

Campaign assets connect to an R2 image origin and hosting at 91[.]246[.]50[.]210 on AS199242. Co-hosting does not attribute every neighboring domain.

Shared storageOne hosting IPQualified scope
Validate provider scope before disruption requests.
02 / Investigation replay

One active storefront led back to an earlier deployment and shared dependencies.

tacobellstore[.]shop
Active / malicious 0.95
Legitimate Taco Shop
Image source / victim
tacobelltacoshop[.]shop
Earlier deployment / offline
Shared R2 image origin
Storage correlation
91[.]246[.]50[.]210
Active hosting IP
AS199242
Hosting dependency

Relationship map is sanitized. Sensitive operator and victim details remain off-page.

03 / Response path

Prioritize the dependencies most likely to disrupt shared campaign assets.

These are investigation and enforcement paths, not guarantees of removal.

AS199242 / HOSTING
High
Both confirmed malicious deployments and the active hosting IP
Validate provider scope and prepare a hosting abuse package.
CLOUDFLARE R2
High
Shared product-image origin across both deployments
Validate ownership and report the shared storage asset.
.SHOP REGISTRY
Medium
Both confirmed malicious domains
Coordinate domain-level evidence with registry and registrar paths.
CLOUDFLARE ZONE
Medium
Image subdomain and potential sibling assets
Pivot for related properties before attribution or action.
Private working session

Replay the campaign. Validate scope. Prioritize the next action.

Walk through the source evidence with Outtake and discuss how the same workflow can extend across Yum!'s external surface.

Yum! Brands
Private cybersecurity briefing / detailed findings
Prepared byOuttake