Consumer & Retail Banking
Consumer & Retail Banking
Article
2026-01-08

Beware of Quishing: QR Code Phishing Scams You Need to Watch Out For

Digital transformation has made everyday activities easier, including financial transactions through QR Codes. However, behind this convenience, a new form of cybercrime has emerged: Quishing, or QR Code Phishing. This scam exploits people’s trust in QR Codes to steal personal information and, in many cases, drain victims’ funds.

 

Bank Muamalat encourages all customers and the wider community to understand what quishing is, how it works, and what preventive steps can be taken to ensure transactions remain safe and aligned with ethical financial principles.

 

What Is Quishing?

 

Quishing is a type of digital scam that uses fake QR Codes as its main tool. When a victim scans the QR Code, they are redirected to a malicious link that closely resembles an official website of a bank, e-wallet, or other trusted platform.

 

The main goals of quishing include:

  • Stealing sensitive information such as PINs, passwords, OTPs, or card numbers
  • Taking over banking or digital wallet accounts
  • Draining victims’ balances without their knowledge

 

Unlike conventional phishing, which usually comes through emails or text messages, quishing relies on QR Codes that do not visibly display the destination link, making them harder to detect.

 

Why Is Quishing Dangerous?

 

Quishing poses serious risks due to several factors:

  1. Difficult to Detect
    QR Codes do not show the destination URL directly, so users cannot assess whether a link is safe before scanning it.
  2. High Level of Trust
    QR Codes are widely used in restaurants, parking areas, places of worship, donation drives, and daily payments, which lowers people’s guard.
  3. Fast Execution
    With just one scan, victims can be instantly redirected to a fake website and prompted to enter sensitive information.
  4. Real Financial Loss
    Many quishing cases end with unauthorized access to bank accounts and misuse of personal data.

 

Who Is at Risk?

 

Quishing can target anyone, including:

  • Bank customers and mobile banking users
  • QRIS users for daily payments
  • Business owners and cashiers
  • Worshippers or donors in public spaces
  • Anyone accustomed to scanning QR Codes without verification

 

This means even experienced digital users remain vulnerable if they are not careful.

 

When and Where Does Quishing Commonly Occur?

 

Quishing incidents often increase during:

  • Holiday seasons and year-end periods
  • Promotional events, discounts, or large-scale campaigns
  • Times when cashless payments are widely encouraged

 

Locations frequently exploited by scammers include:

  • Restaurants, cafés, and parking areas
  • Public payment terminals
  • Donation posters and social activity boards
  • Social media platforms and messaging groups
  • Flyers or QR Code stickers placed in public spaces

 

In many cases, scammers simply place a fake QR Code sticker over a legitimate one without being noticed.

 

How Does Quishing Work?

 

In general, quishing follows this pattern:

  1. Scammers create a QR Code linked to a fake website.
  2. The QR Code is distributed or placed in strategic locations.
  3. The victim scans the QR Code without verification.
  4. The victim is redirected to a website that looks official.
  5. The victim is asked to enter personal or transaction details.
  6. The information is used to take over accounts or steal funds.

 

In some cases, the fake website may also install malware that extracts data from the victim’s device.

 

Warning Signs of a Quishing QR Code

 

Be cautious if a QR Code:

  • Directs you to a page asking for PINs, OTPs, or passwords
  • Uses an unfamiliar or look-alike website address
  • Promises unrealistic rewards, cashback, or prizes
  • Creates urgency or uses threatening language
  • Does not come from an official or verified source

 

It is important to remember that banks never request confidential information through QR Codes or links.

 

How to Stay Safe from Quishing

 

To protect your digital transactions, Bank Muamalat recommends the following steps:

  1. Verify the QR Code Source
    Make sure the QR Code comes from an official and trusted party.
  2. Never Share Sensitive Information
    Do not enter PINs, OTPs, or passwords after scanning a QR Code.
  3. Use Official Applications
    Always conduct transactions through official apps downloaded from trusted sources.
  4. Be Wary of Unrealistic Offers
    If a promotion sounds too good to be true, it likely is.
  5. Report Suspicious Activity Immediately
    Contact Bank Muamalat as soon as you notice any signs of fraud.

 

Official Bank Muamalat Channels for Verification

 

If you encounter suspicious activity or parties claiming to represent Bank Muamalat, only verify through the official channels below:

  • SalaMuamalat Call Center: 1500016 (domestic) & +6221 8066 8000 (overseas)
  • WhatsApp Bank Muamalat: 0812 8065 1800 (verified account)
  • Email: salamuamalat@bankmuamalat.co.id
  • Website: bankmuamalat.co.id

 

Official Bank Muamalat Social Media Accounts:

 

Frequently Asked Questions (FAQ) About Quishing

  1. What is quishing?
    Quishing is a scam that uses fake QR Codes to steal personal data or funds.
  2. Are QR Codes always safe to use?
    QR Codes are safe when they come from official sources and are used through trusted applications.
  3. Does a bank ever ask for PINs or OTPs via QR Code?
    No. Banks never request PINs, OTPs, or passwords in any form.
  4. What should I do if I accidentally scan a suspicious QR Code?
    Stop immediately, do not enter any information, and contact Bank Muamalat through its official channels.
 
How can I tell the difference between a real and fake QR Code?
Check the context, location, and destination of the QR Code. If it leads to an unofficial website or asks for sensitive data, treat it as suspicious.
 

Baca Juga :