GCASH, the country’s top wallet and finance super app, has blocked over 6,700 fraudulent merchants using “quishing”—a new tactic where scammers use fake QR codes to steal payments.

As QRPh continues to transform the way Filipinos pay for everyday purchases, scammers are also evolving their tactics to exploit the country’s growing reliance on QR-based transactions, the company warned.

GCash said its fraud monitoring teams have flagged a sharp rise in “quishing” or QR phishing where fake websites mimic legitimate GCash payment pages and use QRPh codes to collect payments.

In these schemes, fraudsters exploit QRPh codes to redirect users to malicious payment pages or steal sensitive information, while misusing official branding to appear credible and deceive users into completing unauthorized transactions.

GCash also noted some cases involving fraudulent QRPh codes being embedded in posters, emails, receipts, or messages.

When scanned, these can redirect users to fake login pages for e-wallets or banks, or even to sites that install harmful software on devices. This results in users unknowingly sending money to illegitimate accounts, even if the transaction appears familiar or routine.

In response, GCash said it has immediately blocked suspicious wallets linked to fraudulent QRPh activity to prevent scammers from receiving stolen payments through the platform, and identified fake websites impersonating official GCash payment pages and escalated them for takedown.

The incident reports are submitted to PH Payments Management Inc. (PPMI) and relevant government authorities to support further investigation and enforcement.

GCash said these efforts form part of a broader collaboration with government agencies, including the Cybercrime Investigation and Coordinating Center (CICC) and the Bangko Sentral ng Pilipinas (BSP), to disrupt scam networks, strengthen consumer protection, and preserve trust in the country’s digital payments ecosystem.

“Scammers are constantly evolving their tactics alongside digital payments, and we are equally committed to staying ahead of these threats,” said Miguel Geronilla, Chief Information Security Officer at GCash. “By proactively blocking suspicious accounts, flagging fraudulent payment pages, and reporting these activities to regulators and law enforcement, we help stop these schemes before they can affect more Filipinos.”

Geronilla added that the firm has zero tolerance for those exploiting digital financial services. “We will continue to strengthen our safeguards while working hand in hand with government and industry partners to keep the country’s digital payments ecosystem safe and secure,” he added.

As scams become more sophisticated, GCash urges users to remain vigilant and practice safe digital habits when using QR-based payments:

• Always check the website URL before making payments and ensure it matches official GCash domains

• Verify the merchant name displayed before confirming any transaction

• Avoid transacting with suspicious or unverified sites

• Be cautious of QR codes from unknown or untrusted sources

• Report suspicious links or payment requests through the GCash Help Center

GCash users can report suspected scams through the GCash Help Center at help.gcash.com by chatting with Gigi and selecting “I want to report a scam”, or by calling the official GCash hotline at 2882. 

Users may also report incidents to the PNP Anti-Cybercrime Group at (02) 8414-1560 / 0998-598-8116 or acg@pnp.gov.ph, and to the Cybercrime Investigation and Coordinating Center (CICC) via hotline 1326, mobile 0991-481-4225, or report@cicc.gov.ph. ▲

Leave a comment

Trending