Watch out for ‘scan artists’, public urged


PETALING JAYA: A seemingly harmless QR code scan can lead victims to fake websites, fraudulent payment gateways or malware designed to steal funds and banking credentials.

Bukit Aman Commercial Crime Investigation Department (CCID) director Comm Datuk Rusdi Mohd Isa warned that QR code scams are not limited to a single tactic, as the technology is used to conceal the true destination of a link or transaction. This obscures the threat before a victim scans the code.

This makes it difficult for victims to identify the risks before scanning the code, he said.

“Identified tactics include directing victims to phishing portals that mimic official bank, e-commerce or corporate ­websites to steal user IDs, passwords and card details,” Comm Rusdi said.

He noted that syndicates also deploy fake payment QR codes to divert funds to syndicate accounts.

Furthermore, scammers impersonate bank officers, government officials, couriers or merchants, instructing victims to scan codes under the pretext of account ­verification, prize claims, parcel deliveries or refunds.

The CCID has also recorded cases targeting online sellers. Scammers posing as buyers contact individuals offering goods or services, claiming they wish to make a payment, before tricking the seller into scanning a QR code or opening a link to receive the funds.

Comm Rusdi clarified that ­merchants and individuals receiving money via DuitNow QR only need to present their own code to the buyer.

“Recipients never need to scan a code sent by the payer, enter banking credentials, provide a One-Time Password (OTP) or Transaction Authorisation Code (TAC), pay activation fees or approve debit requests,” he stressed.

Comm Rusdi added that scanning a QR code alone rarely triggers an immediate money transfer.

“Financial loss usually occurs when victims complete follow-up actions requested by scammers, such as entering credentials, approving banking app notifications or downloading malicious software,” he said.

“Among the methods used were directing victims to ­phishing websites, using fake payment gateways to divert money to ­syndicate accounts, requesting card details, OTPs, TACs or ­verification codes, and directing victims to download applications containing malware,” he said.

He added, in cases involving malware, syndicates could gain access to messages, device information or screen content if victims installed the application and granted the requested permissions.

He urged anyone who suspects scam activity or has fallen victim to contact the National Scam Response Centre (NSRC) hotline at 997 immediately.

The public can also verify bank accounts, phone numbers and company names via the CCID SemakMule portal.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Nation

Negri royal row: Exco has no say over Ruler’s position, says ex-MB Aminuddin
Fire breaks out at Ipoh home
Ensuring progress for all M’sians
Tamil schools shine in Cyberjaya ICT contest
Breathing new life into Sandakan
King and Queen extend�Malaysia Day greetings
Increase in number of women abusing drugs
A. Aida cuts daughter’s ‘cable’ claims
‘Set clear boundaries for pacts’
Sabah squad marks Malaysia Day with underwater clean-up

Others Also Read