Monday, November 18, 2024

Fake QRIS code, new threats to digital banking ecosystem

Reading Time: 2 minutes
Novi Nurmalasari

Journalist

Mahinda Arkyasa

Editor

Interview

The recent case of fake QRIS codes installed in charity boxes presents a major hurdle amid Bank Indonesia’s efforts to develop a digital, tech-based payment system.

Moreover, the fact that the suspect, Mohammad Iman Mahlil, is a former bank employee means that “insiders” pose a great risk to the implementation of tampered QRIS codes.

In relation to the finding, cybersecurity expert Kaspersky has pointed out that there are quite a few vulnerabilities in QRIS that can be exploited by cybercriminals or hackers to do harmful actions. This is largely due to the fact that users cannot easily read the QRIS or verify the scanning process, making it easier for attackers to exploit these weaknesses.

The QRIS code created by criminals may lead to phishing sites that look like legitimate login pages for online banking or social networks. That’s why Kaspersky advises users to always check the link before tapping or clicking on it. 

Kaspersky also noted that hackers often use shortened links, making it more difficult for users to identify fake QRIS code when prompted for confirmation on their smartphones. This type of scheme can also trick users into downloading malicious software, instead of the intended game or tool, leading to potential security breaches.

In addition, QRIS code can also contain instructions to certain actions, such as adding contacts, making phone calls, drafting email and collecting recipient and subject lines, sending texts, sharing locations, and many more. 

It turns out that, despite all safety claims, QRIS can still be manipulated and breached. Therefore, to prevent this case from happening again, Bank Indonesia can only take precautions by pressing the payment service provider (PJP) to protect the system they are using. 

Bank Indonesia is also tightening the registration process of merchants who will use QRIS as their payment option. The central bank is coordinating with the Payment System Association (ASPI), payment system infrastructure providers, and PT Penyelesaian Transaksi Elektronik (PTEN) to investigate the risk of QRIS leaks.

Regarding PJP, ASPI has issued guidelines for merchants and users to improve the security of QRIS transactions. 

To ensure safe transactions, Bank Indonesia also encourages users to carefully check the information displayed within the payment application when scanning the code. This includes verifying the name of the merchant listed in the application and ensuring that it matches the correct merchant, and following the payment instructions provided by the merchant.

Merchants are also expected to regularly check their QRIS codes to ensure that they are indeed their own and have not been changed by unauthorized parties. 

Novi Nurmalasari

Journalist

Mahinda Arkyasa

Editor

 

Interview

SUBSCRIBE NOW
We will provide you with an invoice for your reimbursable expenses.

Free

New to Indonesian market? Read our free articles before subscribing to the premium plan. If you already run your business in Indonesia, make sure to subscribe to the premium subscription so you won’t miss any intelligence & business opportunities.

Premium

$550 USD/Year

or

$45 USD/Month

Cancelation: you can cancel your subscription at any time, by sending us an email inquiry@ibp-media.com

Add keywords to your market watch and receive notification:
Schedule a free consultation with us:

We’ll contact you for confirmation.

FURTHER READING

The Attorney General’s Office is investigating palm oil producer PT Darmex Plantations over corruption and money laundering allegations inflicted on giant oil palm plantation and palm oil producer PT Duta Palma Group’s business activities in Indragiri Hulu regency, Riau.
Indonesia’s power utility PT PLN is seeking global support and funding to achieve the government’s additional target of renewable energy installed capacity of 75 Gigawatt (GW) in the next 15 years.
The Directorate of General Crimes Investigation at the Jakarta Police Headquarters has named 22 suspects in a major online gambling case, which implicates officials from the Ministry of Communication and Digital (Komdigi).
The indigenous communities of Poco Leok in Manggarai Regency, East Nusa Tenggara, which include Gendang Mucu, Mocok, Mori, Nderu, Cako, Ncamar, Rebak, Jong, Tere, and Lungar, continue to resist the geothermal mining project led by PT PLN. This project, aimed at expanding the Ulumbu Geothermal Power Plant (PLTP) to Units 5 and 6, threatens to disrupt their ancestral lands and displace their traditional ways of life. Backed by Germany’s Kreditanstalt für Wiederaufbau (KfW), the project has been the subject of growing opposition from local residents, who demand that KfW withdraw its financial support and acknowledge the harm done to the community.
Deputy President Director of PT Bank Central Asia (BCA), Armand Hartono, emphasizes the importance of investment and business diversification as the main strategy to maintain business continuity, a principle he inherited from his father Robert Budi Hartono, who is also known as the boss of the Djarum Group.
The statement by Chairman of The Federal Reserve (The Feds), Jerome Powell, that the U.S. central bank will cut interest rates gradually and carefully in the next few months sends a positive signal for the Indonesian banking sector.