QR codes are part of everyday life in Malaysia, but scammers are exploiting how flexible TNG eWallet is with QR formats to redirect users to phishing pages. Here is how the scam works and how to verify a QR code before scanning.
3 May 2026•1352 reads•4 min read
QR codes have become part of everyday life in Malaysia, especially during festive seasons such as Hari Raya and Chinese New Year. In the excitement of receiving duit raya or angpau, many users scan QR codes without thinking twice. Unfortunately, this is the exact behaviour that scammers count on.
Cybercriminals are increasingly active in creating fake QR codes and convincing-looking short links. Once scanned, users risk having their data leaked, their accounts taken over, or their money stolen.
One pattern we have been tracking lately involves the TNG Money Packet — the same red angpau feature many Malaysians use to send and receive money during festive seasons.
Why TNG accepts more than DuitNow QR
If you scan the same crafted QR code using a banking app, the app will simply reject it as Invalid QR Code. Banks are strict — they only trust QR codes that follow the DuitNow format.
TNG eWallet handles things a little differently. Beyond DuitNow strings, the app also accepts URLs from QR codes — because the Money Packet feature itself is a URL.
A genuine Money Packet QR points to something like cdn.tngdigital.com.my/s/oauth2/index.html#/moneypacket?p=xxxx. The flexibility that makes Money Packets work is also the gap scammers are now exploiting.
In short
Bank apps reject any QR that is not DuitNow-formatted. TNG accepts URLs too — and that is what scammers take advantage of.
How the scam works
In the cases we have seen, the attacker replaces the URL in a Money Packet QR with their own phishing link, usually a fake Telegram login page. The QR code still looks like a normal angpau, but the destination has been swapped.
The scammer generates a QR code that visually resembles a Money Packet from TNG.
Instead of pointing to TNG's real Money Packet URL, the QR encodes a phishing URL — usually a fake Telegram login.
The user scans the QR using TNG. The app opens the URL in its in-app browser.
The user sees what appears to be a Telegram login page, enters their credentials, and the scammer takes over the account.
Fake QR code that looks like a Money Packet but redirects to a phishing page.
Pay attention to login screens
A real Money Packet from TNG will never ask you to log in to Telegram, WhatsApp, or any other third-party service. If a Money Packet opens a login screen, close it immediately.
The phishing page that ask for your Telegram phone number
What to watch for
A QR code shared in a random chat or social post claiming to be a Money Packet from someone you do not know.
After scanning, the page asks you to log in — especially Telegram or WhatsApp.
The URL in the in-app browser does not start with tngdigital.com.my.
Pressure or urgency in the message: "limited time", "first 100 people", "claim now".
Check the QR code before you scan
To help users reduce this risk, PenipuMY has opened up a feature called URL Analyzer directly on the homepage. With it, you can verify a QR code or any suspicious link before taking any action — no separate page or sign-in required.
Go to the PenipuMY homepage at penipu.my.
On the search bar in the hero section, switch the filter from "All" to URL Analyzer.
If the QR code came through WhatsApp, Telegram, or social media, copy the image (long-press the image and select Copy / Copy Image) and paste it into the search bar. If the image is already saved on your device, you can upload it directly.
Submit. The system will then analyse the QR code automatically and show you a verdict before you scan with TNG.
How to take down a phishing site
If you come across a phishing site impersonating Money Packet — or any well-known service — reporting it to the domain registrar is usually the fastest path. Find the registrar through a WHOIS lookup, then send an abuse report with screenshots and the URL. Most registrars suspend confirmed phishing domains within hours.
Already been scammed?
For users who have fallen victim to a scam, PenipuMY also provides a complete guide at penipu.my/i-have-been-scammed. The guide lists the immediate steps to take, along with the relevant agencies to contact for filing reports.
Initiatives like URL Analyzer give users an additional layer of protection — a quick check before acting, which goes a long way in reducing the risk of falling victim to online fraud during festive seasons or otherwise.
Kod QR telah menjadi sebahagian daripada kehidupan seharian di Malaysia, terutamanya ketika musim perayaan seperti Hari Raya dan Tahun Baru Cina. Dalam keghairahan menerima duit raya atau angpau, ramai pengguna mengimbas kod QR tanpa berfikir panjang. Malangnya, itulah tabiat yang menjadi sasaran penipu.
Penjenayah siber semakin aktif mencipta kod QR palsu dan pautan pendek yang kelihatan meyakinkan. Setelah diimbas, pengguna berisiko kehilangan data, akaun diambil alih, atau wang dicuri.
Satu corak yang kami pantau sejak kebelakangan ini melibatkan TNG Money Packet — ciri angpau merah yang sama digunakan ramai rakyat Malaysia untuk menghantar dan menerima wang ketika musim perayaan.
Mengapa TNG menerima lebih daripada QR DuitNow
Jika anda mengimbas kod QR yang sama menggunakan aplikasi perbankan, aplikasi itu akan terus menolaknya sebagai Invalid QR Code. Bank sangat ketat — mereka hanya mempercayai kod QR yang mengikut format DuitNow.
TNG eWallet pula mengendalikannya dengan sedikit berbeza. Selain rentetan DuitNow, aplikasi ini turut menerima URL daripada kod QR — kerana ciri Money Packet itu sendiri sebenarnya sebuah URL.
Kod QR Money Packet yang sah menghala ke sesuatu seperti cdn.tngdigital.com.my/s/oauth2/index.html#/moneypacket?p=xxxx. Fleksibiliti yang membolehkan Money Packet berfungsi inilah juga celah yang kini disalahgunakan penipu.
Ringkasnya
Aplikasi bank menolak sebarang QR yang bukan format DuitNow. TNG menerima URL juga — dan itulah yang diambil kesempatan oleh penipu.
Bagaimana penipuan ini berfungsi
Dalam kes yang kami temui, penyerang menggantikan URL dalam kod QR Money Packet dengan pautan phishing mereka sendiri, biasanya halaman log masuk Telegram palsu. Kod QR itu masih kelihatan seperti angpau biasa, tetapi destinasinya telah ditukar.
Penipu menjana kod QR yang kelihatan seperti Money Packet daripada TNG.
Daripada menghala ke URL Money Packet sebenar TNG, kod QR itu mengekod URL phishing — biasanya halaman log masuk Telegram palsu.
Pengguna mengimbas kod QR menggunakan TNG. Aplikasi membuka URL tersebut dalam pelayar dalam-aplikasinya.
Pengguna melihat apa yang kelihatan seperti halaman log masuk Telegram, memasukkan maklumat log masuk mereka, dan penipu pun mengambil alih akaun itu.
Kod QR palsu yang kelihatan seperti Money Packet tetapi mengalihkan ke halaman phishing.
Perhatikan skrin log masuk
Money Packet sebenar daripada TNG tidak sekali-kali akan meminta anda log masuk ke Telegram, WhatsApp, atau mana-mana perkhidmatan pihak ketiga. Jika Money Packet membuka skrin log masuk, tutup dengan segera.
Halaman phishing yang meminta nombor telefon Telegram anda.
Perkara yang perlu diberi perhatian
Kod QR yang dikongsi dalam sembang rawak atau hantaran media sosial yang mendakwa ia Money Packet daripada seseorang yang anda tidak kenali.
Selepas diimbas, halaman itu meminta anda log masuk — terutamanya Telegram atau WhatsApp.
URL dalam pelayar dalam-aplikasi tidak bermula dengan tngdigital.com.my.
Unsur tekanan atau desakan dalam mesej: "masa terhad", "100 orang pertama", "tuntut sekarang".
Semak kod QR sebelum anda mengimbas
Untuk membantu pengguna mengurangkan risiko ini, PenipuMY telah menyediakan ciri bernama URL Analyzer terus di halaman utama. Dengannya, anda boleh mengesahkan kod QR atau sebarang pautan mencurigakan sebelum mengambil sebarang tindakan — tanpa perlu halaman berasingan atau log masuk.
Pergi ke halaman utama PenipuMY di penipu.my.
Pada bar carian di bahagian hero, tukar penapis daripada "All" kepada URL Analyzer.
Hantar. Sistem kemudian akan menganalisis kod QR secara automatik dan memaparkan keputusan sebelum anda mengimbas dengan TNG.
Cara menurunkan laman phishing
Jika anda menemui laman phishing yang menyamar sebagai Money Packet — atau mana-mana perkhidmatan terkenal lain — melaporkannya kepada pendaftar domain (domain registrar) biasanya jalan paling cepat. Cari pendaftar melalui carian WHOIS, kemudian hantar laporan penyalahgunaan bersama tangkapan skrin dan URL. Kebanyakan pendaftar akan menggantung domain phishing yang disahkan dalam masa beberapa jam.
Sudah menjadi mangsa penipuan?
Bagi pengguna yang sudah menjadi mangsa penipuan, PenipuMY turut menyediakan panduan lengkap di penipu.my/i-have-been-scammed. Panduan ini menyenaraikan langkah segera yang perlu diambil, berserta agensi berkaitan yang boleh dihubungi untuk membuat laporan.
Inisiatif seperti URL Analyzer memberi pengguna satu lapisan perlindungan tambahan — semakan pantas sebelum bertindak, yang banyak membantu mengurangkan risiko menjadi mangsa penipuan dalam talian, sama ada ketika musim perayaan mahupun pada bila-bila masa.
Share this article 6
We use cookies to keep you logged in and improve your experience. See our Privacy Policy.