PETALING JAYA: A seemingly harmless QR code scan can lead victims to fake websites, fraudulent payment gateways or malware designed to steal funds and banking credentials.
Bukit Aman Commercial Crime Investigation Department (CCID) director Comm Datuk Rusdi Mohd Isa warned that QR code scams are not limited to a single tactic, as the technology is used to conceal the true destination of a link or transaction. This obscures the threat before a victim scans the code.
This makes it difficult for victims to identify the risks before scanning the code, he said.
“Identified tactics include directing victims to phishing portals that mimic official bank, e-commerce or corporate websites to steal user IDs, passwords and card details,” Comm Rusdi said.
He noted that syndicates also deploy fake payment QR codes to divert funds to syndicate accounts.
Furthermore, scammers impersonate bank officers, government officials, couriers or merchants, instructing victims to scan codes under the pretext of account verification, prize claims, parcel deliveries or refunds.
The CCID has also recorded cases targeting online sellers. Scammers posing as buyers contact individuals offering goods or services, claiming they wish to make a payment, before tricking the seller into scanning a QR code or opening a link to receive the funds.
Comm Rusdi clarified that merchants and individuals receiving money via DuitNow QR only need to present their own code to the buyer.
“Recipients never need to scan a code sent by the payer, enter banking credentials, provide a One-Time Password (OTP) or Transaction Authorisation Code (TAC), pay activation fees or approve debit requests,” he stressed.
Comm Rusdi added that scanning a QR code alone rarely triggers an immediate money transfer.
“Financial loss usually occurs when victims complete follow-up actions requested by scammers, such as entering credentials, approving banking app notifications or downloading malicious software,” he said.
“Among the methods used were directing victims to phishing websites, using fake payment gateways to divert money to syndicate accounts, requesting card details, OTPs, TACs or verification codes, and directing victims to download applications containing malware,” he said.
He added, in cases involving malware, syndicates could gain access to messages, device information or screen content if victims installed the application and granted the requested permissions.
He urged anyone who suspects scam activity or has fallen victim to contact the National Scam Response Centre (NSRC) hotline at 997 immediately.
The public can also verify bank accounts, phone numbers and company names via the CCID SemakMule portal.
