
Filipino e-wallet giant GCash has shut down more than 6,700 fraudulent merchant accounts tied to “quishing”—an emerging cyber scam where bad actors exploit QRPh payment infrastructure to misdirect funds and steal sensitive personal data.
The enforcement action comes as fraud monitoring teams at GCash detected a sharp increase in schemes designed to mimic official payment gateways. By embedding compromised QRPh codes into digital and physical media—including emails, receipts, posters, and direct messages—scammers redirect unsuspecting buyers to fake login portals or malicious payment pages designed to look like legitimate GCash domains. In certain instances, scanning these fraudulent codes installs harmful software directly onto consumer devices.
To dismantle these illicit networks, GCash immediately blocks flagged wallets to freeze incoming stolen transactions. The company also initiates takedown requests for impersonation websites and escalates incident intelligence to regulatory bodies and enforcement agencies, including PH Payments Management Inc. (PPMI), the Cybercrime Investigation and Coordinating Center (CICC), and the Bangko Sentral ng Pilipinas (BSP).
“Scammers are constantly evolving their tactics alongside digital payments, and we are equally committed to staying ahead of these threats,” said Miguel Geronilla, Chief Information Security Officer at GCash. “By proactively blocking suspicious accounts, flagging fraudulent payment pages, and reporting these activities to regulators and law enforcement, we help stop these schemes before they can affect more Filipinos.”
Geronilla emphasized the company’s zero-tolerance stance regarding ecosystem security.
“Protecting users is at the core of our platform. We have zero tolerance for those who exploit digital financial services, and we will continue to strengthen our safeguards while working hand in hand with government and industry partners to keep the country’s digital payments ecosystem safe and secure,” Geronilla added.
To prevent financial loss from QRPh-based phishing schemes, cybersecurity experts recommend incorporating specific verification habits before completing any digital transaction:
- Inspect web addresses: Verify that payment URLs match official GCash web domains prior to authorizing funds.
- Confirm recipient details: Check the displayed merchant name on screen before approving any transfer.
- Exercise caution with unknown sources: Refrain from scanning QR codes provided in unsolicited messages, emails, or unverified physical placements.
- Halt suspicious activity: Stop any transaction immediately if page prompts or domain names appear unfamiliar or altered.
Users who encounter fraudulent links or suspicious payment requests can submit reports via the official GCash Help Center (help.gcash.com) through the conversational assistant Gigi or by dialing the hotline at 2882.
Incidents can also be reported directly to public authorities:
- PNP Anti-Cybercrime Group: (02) 8414-1560 / 0998-598-8116 or acg@pnp.gov.ph
- Cybercrime Investigation and Coordinating Center (CICC): Hotline 1326, mobile 0991-481-4225, or report@cicc.gov.ph




Leave a Reply