Home / Blog / Alert
Alert

Beware of fake Money Packet QR codes

QR codes are part of everyday life in Malaysia, but scammers are exploiting how flexible TNG eWallet is with QR formats to redirect users to phishing pages. Here is how the scam works and how to verify a QR code before scanning.

Beware of fake Money Packet QR codes

QR codes have become part of everyday life in Malaysia, especially during festive seasons such as Hari Raya and Chinese New Year. In the excitement of receiving duit raya or angpau, many users scan QR codes without thinking twice. Unfortunately, this is the exact behaviour that scammers count on.

Cybercriminals are increasingly active in creating fake QR codes and convincing-looking short links. Once scanned, users risk having their data leaked, their accounts taken over, or their money stolen.

One pattern we have been tracking lately involves the TNG Money Packet — the same red angpau feature many Malaysians use to send and receive money during festive seasons.

Why TNG accepts more than DuitNow QR

If you scan the same crafted QR code using a banking app, the app will simply reject it as Invalid QR Code. Banks are strict — they only trust QR codes that follow the DuitNow format.

TNG eWallet handles things a little differently. Beyond DuitNow strings, the app also accepts URLs from QR codes — because the Money Packet feature itself is a URL.

A genuine Money Packet QR points to something like cdn.tngdigital.com.my/s/oauth2/index.html#/moneypacket?p=xxxx. The flexibility that makes Money Packets work is also the gap scammers are now exploiting.

In short

Bank apps reject any QR that is not DuitNow-formatted. TNG accepts URLs too — and that is what scammers take advantage of.

How the scam works

In the cases we have seen, the attacker replaces the URL in a Money Packet QR with their own phishing link, usually a fake Telegram login page. The QR code still looks like a normal angpau, but the destination has been swapped.

  1. The scammer generates a QR code that visually resembles a Money Packet from TNG.
  2. Instead of pointing to TNG's real Money Packet URL, the QR encodes a phishing URL — usually a fake Telegram login.
  3. The user scans the QR using TNG. The app opens the URL in its in-app browser.
  4. The user sees what appears to be a Telegram login page, enters their credentials, and the scammer takes over the account.
Fake QR code that looks like a Money Packet but redirects to a phishing page.
Fake QR code that looks like a Money Packet but redirects to a phishing page.

Pay attention to login screens

A real Money Packet from TNG will never ask you to log in to Telegram, WhatsApp, or any other third-party service. If a Money Packet opens a login screen, close it immediately.

The phishing page that ask for your Telegram phone number
The phishing page that ask for your Telegram phone number

What to watch for

  • A QR code shared in a random chat or social post claiming to be a Money Packet from someone you do not know.
  • After scanning, the page asks you to log in — especially Telegram or WhatsApp.
  • The URL in the in-app browser does not start with tngdigital.com.my.
  • Pressure or urgency in the message: "limited time", "first 100 people", "claim now".

Check the QR code before you scan

To help users reduce this risk, PenipuMY has opened up a feature called URL Analyzer directly on the homepage. With it, you can verify a QR code or any suspicious link before taking any action — no separate page or sign-in required.

  1. Go to the PenipuMY homepage at penipu.my.
  2. On the search bar in the hero section, switch the filter from "All" to URL Analyzer.
  3. If the QR code came through WhatsApp, Telegram, or social media, copy the image (long-press the image and select Copy / Copy Image) and paste it into the search bar. If the image is already saved on your device, you can upload it directly.
  4. Submit. The system will then analyse the QR code automatically and show you a verdict before you scan with TNG.

How to take down a phishing site

If you come across a phishing site impersonating Money Packet — or any well-known service — reporting it to the domain registrar is usually the fastest path. Find the registrar through a WHOIS lookup, then send an abuse report with screenshots and the URL. Most registrars suspend confirmed phishing domains within hours.

Already been scammed?

For users who have fallen victim to a scam, PenipuMY also provides a complete guide at penipu.my/i-have-been-scammed. The guide lists the immediate steps to take, along with the relevant agencies to contact for filing reports.

Initiatives like URL Analyzer give users an additional layer of protection — a quick check before acting, which goes a long way in reducing the risk of falling victim to online fraud during festive seasons or otherwise.

Enlarged image