A QR code placed at a payment counter or donation box may not always belong to the intended merchant or institution. Criminals can replace a legitimate QRIS code with their own code and redirect money to a personal account.
The risk extends beyond physical locations because fake payment pages and altered transaction screenshots can also be used to deceive users and sellers. Checking the recipient name and the actual payment status before completing a transaction is therefore essential.
Bank Indonesia recorded 60.77 million QRIS users as of February 2026. The wider use of digital payments has created more opportunities for fraudsters to exploit familiar-looking codes, payment details, and merchant identities.
Overview of the 5 QRIS Scam Methods
| Scam method | How it works | Main target |
|---|---|---|
| Fake QRIS barcode | A genuine code is replaced with the scammer’s code | Visitors and donors |
| Old transaction screenshot | An earlier payment receipt is edited | Merchants |
| Recipient account switch | Payment is redirected to another account | Buyers |
| Scamming | Promises of rewards pressure users to pay | QRIS users |
| Phishing | A fake website collects data and funds | Payment service users |
1. Fake QRIS Codes in Public Places
Fraudsters may place counterfeit QRIS stickers at busy food outlets, beverage stalls, or other public locations. A code can appear legitimate when it is positioned near the usual payment point.
Donation boxes at mosques may also be targeted when QRIS codes are available in several locations. A scammer can replace a donation barcode so that money goes to a private account instead of the proper manager.
2. Edited Screenshots Used Against Sellers
Sellers may be shown an old payment screenshot that has been modified to match a new purchase amount. The image is intended to create the impression that the payment has already been completed.
Bank Mega Syariah notes that this tactic can be effective when merchants are serving many customers and cannot inspect every transaction closely. A screenshot should not be treated as the only proof that funds have been received.
3. Switching the Intended Payment Recipient
A fraudulent QRIS code can be sent to a buyer while appearing to be connected to a legitimate payment need. The payment may instead be directed to a different account controlled by the scammer.
Users should check the recipient information shown in the payment application before confirming the transaction. The displayed name should match the merchant, seller, or institution that is meant to receive the funds.
4. Scamming Through Promises of Rewards
Scammers can use psychological pressure by claiming to represent an official party and offering prizes or large benefits. The goal is to make the target transfer money through QRIS without taking time to verify the request.
Pressure to pay immediately should be viewed as a warning sign. A legitimate recipient should have a clear identity and a recipient name that can be checked.
5. Phishing Through Imitation Payment Websites
Phishing websites can be designed to resemble official cashless payment services. Victims may be asked to scan a QRIS code or enter personal information without realizing that the page is fraudulent.
Continuing on such a page can expose both personal data and transferred funds. Users should inspect the website address and recipient identity, especially when notified that a payment account has changed.
Practical Checks Before Paying
At a restaurant, store, or donation point, users should make sure that the QRIS poster genuinely comes from the operator. Extra stickers or codes from an unclear source require further verification.
Personal documents and QR codes should not be shared carelessly through printed materials, messages, or social media posts. These materials can be linked to payment information that may be misused.
Source: www.cnnindonesia.com






