More than 5,000 cases of QR code scams, commonly known as “quishing,” have been reported in the first half of 2026, resulting in nearly RM30 million in losses, according to Malaysia’s Commercial Crime Investigation Department (CCID). The practice involves fraudsters using QR codes to direct victims to fraudulent websites, payment portals, or applications, tricking them into revealing banking credentials or authorizing transactions without their knowledge.

Bukit Aman CCID director Comm Datuk Rusdi Mohd Isa highlighted that the rise in quishing cases reflects the increasing exploitation of QR code technology by criminal syndicates. “The significant increase shows that QR codes are increasingly being used to disguise malicious links and redirect payments,” he said, emphasizing that QR codes, once primarily a convenient payment method, have become a vehicle for various online scams.

Data from the CCID reveals a sharp increase in reported cases and financial losses over recent years. In 2023, 223 cases were recorded with RM4.59 million lost, followed by 655 cases and RM6.76 million in losses in 2024. The trend accelerated considerably in 2025, with 5,907 cases and losses nearing RM41 million. For the first six months of 2026, 5,134 cases were reported, amounting to RM28.67 million in damages. Overall, from January 2023 to June 2026, the CCID documented 11,919 such incidents involving total losses of approximately RM80.86 million.

Geographically, Selangor reported the highest number of cases, followed by Johor and Kuala Lumpur. Comm Rusdi attributed this distribution to the concentration of digital transaction users, e-commerce activities, and widespread cashless payment systems in these regions.

Investigations into quishing scams cover all elements of the criminal network, including the creation and distribution of QR codes, tracking money flows, and identifying recipient or “mule” accounts used to transfer stolen funds. Authorities also analyze digital evidence such as devices, phone numbers, websites, and social media accounts, collaborating with financial institutions, telecommunications providers, and relevant agencies in their efforts.

Comm Rusdi warned that individuals who knowingly lend or rent out their bank accounts to facilitate these scams may also face prosecution, regardless of their level of involvement. “If there is sufficient evidence, prosecution will be initiated whether the individual is the mastermind, operator of a fake website, recipient account owner, or a facilitator,” he said.

In response to the growing threat, the CCID advises the public to exercise caution before scanning QR codes, especially those received from unknown sources or linked to urgent payment requests, refunds, prizes, or account verifications. To help combat the issue, the department has introduced a verification portal, CCID SemakMule, where users can check the legitimacy of bank accounts, phone numbers, and company names.