QR codes have become part of everyday life in Malaysia, appearing everywhere from restaurant tables and retail counters to parking systems, event registrations and digital payments. Their convenience is exactly what makes them attractive to scammers as well. In the first six months of 2026 alone, Malaysians lost RM28.67 million to QR code-related scams, highlighting how quickly this relatively simple technology can be weaponised for fraud.
According to figures provided by Bukit Aman's Commercial Crime Investigation Department, authorities received 5,134 reports between January and June 2026. The latest numbers push the total since January 2023 to 11,919 cases involving RM80.86 million in losses, showing that QR code scams have grown from a relatively minor threat into a significant financial crime problem.
QR Code Scams Have Increased Sharply Since 2023
The growth in reported cases has been dramatic. Police recorded only 223 QR code scam cases in 2023, but the number increased to 655 in 2024 before surging to 5,907 cases in 2025. That means the threat expanded rapidly in only a few years, reflecting both the wider use of QR-based payments and the growing creativity of scammers.
Financial losses followed the same pattern. Malaysians lost RM4.59 million to these scams in 2023, rising to RM6.76 million in 2024 before jumping to RM40.85 million last year. With RM28.67 million already lost in the first half of 2026, the figures suggest that QR-based fraud remains a serious and continuing problem.
The scale of the increase also shows why QR code scams deserve more attention. They are no longer isolated incidents involving a handful of victims. The numbers now indicate a high-volume fraud channel capable of generating substantial losses.
Why QR Codes Are So Attractive to Scammers
The biggest weakness of a QR code is also what makes it useful: the destination is hidden until the code is scanned. Unlike a traditional website link, where users may notice an unusual domain before clicking, a QR code provides almost no visible clue about where it will lead.
A malicious code can direct victims to a fake payment page, fraudulent banking portal or phishing website designed to collect personal and financial information. In other situations, scammers may replace a legitimate payment QR code with their own so money is transferred directly into an account controlled by the fraud network.
This form of QR-based phishing is commonly referred to as "quishing", combining QR codes with traditional phishing techniques. The method works particularly well because many users have become accustomed to scanning codes quickly without thinking much about what happens next.
A Normal-Looking QR Code Can Hide a Fraudulent Website
Scammers do not necessarily need sophisticated hacking skills to carry out this type of fraud. A QR code can be created in seconds and placed almost anywhere, including posters, emails, social media posts, physical notices or messaging apps.
Once scanned, the victim may be taken to a website that closely resembles a legitimate banking, payment or merchant page. The site may ask for banking credentials, card information or approval of a transaction through a banking application. Because the QR code itself looks harmless, users may lower their guard before they even reach the fraudulent site.
That is why the real danger is not the QR code alone. It is the trust users place in whatever appears after scanning it.
Payment Diversion Is Another Common Risk
Not every QR scam relies on stealing passwords. Some simply redirect a payment to the wrong recipient. A fraudulent DuitNow or merchant QR code placed over a legitimate one could result in a payment being sent to a scammer-controlled account instead of the intended business.
This type of attack can be particularly effective in busy environments where customers assume that a displayed QR code belongs to the merchant. Unless the payer checks the recipient name carefully before confirming the transaction, the mistake may only be noticed after the money has already left the account.
It is therefore important to verify the recipient details shown in the banking or e-wallet application before approving any QR-based payment. The presence of a QR code at a legitimate location does not automatically guarantee that the code itself has not been altered.
Police Are Following the Money, Not Just the QR Codes
Investigations into these scams extend beyond identifying whoever created or distributed the fraudulent QR code. Police are also examining how stolen funds move through the financial system and which accounts receive the money.
Bukit Aman Commercial Crime Investigation Department Director Rusdi Mohd Isa said officers work with banks, telecommunications companies and other agencies when tracing fraudulent transactions. This allows investigators to follow the flow of funds and identify people who may have helped scam networks move or conceal the proceeds.
That means enforcement action can potentially reach beyond the person running the phishing page. Organisers, fake website operators, recipient-account holders and other facilitators may all come under investigation.
Account Holders Can Also Face Investigation
One important point is that the bank account receiving scam money may itself become part of the investigation. Individuals who knowingly allow their accounts to be used by criminal networks can potentially face prosecution.
These so-called mule accounts are frequently used to move stolen funds quickly before authorities or banks can freeze them. Scammers may recruit account holders by offering payment in exchange for access to online banking credentials or permission to receive and transfer money.
Some people may view this as an easy way to earn additional income without realising—or choosing to ignore—that the account is being used for fraud. Police are increasingly focusing on these facilitators because scam operations depend heavily on access to accounts capable of receiving victims' money.
Selangor Records the Highest Number of Reports
Selangor recorded the largest number of QR code scam reports, followed by Johor and Kuala Lumpur. Authorities linked this concentration partly to the heavier use of online shopping and digital payments in these locations.
That relationship makes sense. Areas with larger populations, greater commercial activity and higher adoption of digital payment systems naturally create more opportunities for both legitimate QR transactions and fraudulent ones.
However, QR scams are not limited to major urban centres. As digital payments become more common nationwide, the same techniques can be deployed anywhere users rely on QR codes for transactions, registration or accessing online services.
The Convenience of QR Payments Can Encourage Users to Move Too Quickly
One reason QR scams can be effective is that the technology was designed to remove friction. Instead of typing a long web address or manually entering bank details, users simply point a camera at a code and proceed.
That convenience can encourage people to complete transactions quickly without checking the details presented on the next screen. The faster the process feels, the less likely someone may be to stop and question whether the destination is genuine.
Scammers exploit exactly this behaviour. They may also create urgency by claiming that a payment must be made immediately, an account will be suspended or a limited-time offer will disappear unless the user acts quickly.
Urgency Should Always Be a Warning Sign
Police are advising the public to be particularly cautious when QR codes arrive from unknown senders accompanied by pressure to make a payment or provide financial information. Urgency is one of the oldest techniques used in social engineering because it reduces the time victims spend evaluating the situation.
A message might claim that a fine needs immediate payment, a parcel cannot be delivered, an account requires verification or a special offer will expire within minutes. The QR code then provides a convenient path to supposedly resolve the issue.
Whenever a message combines an unfamiliar QR code with pressure to act immediately, users should stop and verify the request through an independent channel before scanning anything.
Check the Source Before You Scan
The simplest defence is to consider where the QR code came from. Codes displayed through an official banking application, trusted merchant website or established physical location generally present less risk than one received unexpectedly through a message or email.
Even physical codes should be examined when possible. Stickers placed over existing merchant QR codes, poor-quality printing or unusual placement can sometimes indicate tampering. For digital codes, users should avoid scanning simply because the message appears to carry a familiar logo.
After scanning, it is equally important to inspect the website or payment details before continuing. A QR code should never be treated as proof that the destination is trustworthy.
Always Verify the Recipient Before Approving Payment
For QR payments, the recipient name displayed by the banking or e-wallet application can provide an important final check. If the name does not match the business or person you expect to pay, the transaction should not be completed until the discrepancy is explained.
Users should also be cautious if a payment QR unexpectedly launches a browser page asking for banking credentials. Normal payment processes usually redirect through established banking or payment applications rather than requiring users to manually enter sensitive login information into unfamiliar websites.
Any request for passwords, PINs, TAC codes or SecureTAC approvals should be treated carefully. Scammers frequently rely on victims unknowingly authorising the transaction themselves.
Businesses Also Need to Protect Their QR Codes
Merchants and organisations using QR codes have a role to play as well. Payment displays should be checked regularly to make sure they have not been replaced or covered by fraudulent stickers.
Where possible, businesses can display the expected merchant name near the QR code so customers know what they should see when confirming payment. Staff should also be trained to recognise tampering and respond quickly if customers report suspicious recipient information.
Digital QR codes distributed through websites or social media should similarly be controlled carefully. If an organisation's online account is compromised, attackers could replace legitimate codes with malicious ones and potentially affect many users at once.
QR Scams Are Really a Trust Problem
The larger issue is not that QR technology itself is inherently unsafe. The problem is that users cannot easily see what a code contains before scanning it, so they must rely heavily on the context surrounding it.
That makes QR fraud another form of social engineering. Criminals are not necessarily defeating sophisticated encryption or banking security. Instead, they convince victims to trust the wrong code, visit the wrong website or approve the wrong transaction.
The most effective defence therefore combines technical safeguards with careful user behaviour.
Final Thoughts
The RM28.67 million lost to QR code scams in just the first half of 2026 shows how rapidly this form of fraud has evolved in Malaysia. With more than 5,000 reports already recorded during the six-month period and total losses since 2023 reaching RM80.86 million, QR-based scams can no longer be treated as a niche cyber threat.
The technology remains extremely useful, but convenience should not replace verification. Before scanning an unfamiliar QR code, users should consider who provided it, why it was sent and whether the request makes sense. Before approving payment, always check the recipient details and be especially cautious when someone is creating pressure to act immediately.
A QR code may take only a second to scan, but taking a few extra seconds to verify where it leads could prevent a very expensive mistake.


Comments 0