The Challenge
In Q3 2025, Mimecast's systems flagged over 716,000 unique malicious QR codes embedded in emails, a 13% increase from the previous quarter. These weren't simple phishing attempts. They were payment-enabled QR codes created through legitimate merchant accounts, delivered via trusted channels, and designed to bypass text-based filters.
The issue wasn't the QR code format itself. Payment platforms had onboarding systems that treated sub-accounts as low-risk extensions of verified merchants. Once a top-level merchant passed Know Your Business checks, sub-accounts could generate payment QR codes with minimal scrutiny. Fraudsters exploited this trust.
The TikTok sub-account case highlighted this pattern: attackers used legitimate advertising sub-accounts to generate payment QR codes, sent them as product deals or investment opportunities, and routed funds through advertising credits before withdrawal. The platform was real, the brand was trusted, and the payment rails worked as designed. The fraud occurred in the governance layer that wasn't monitored.
The Environment and Constraints
Payment platforms in APAC faced three constraints that made traditional fraud detection ineffective:
Detection tools couldn't see the threat. Security systems were built to parse URLs and text strings. A QR code is an image and bypassed link scanners and content filters. By the time the code was scanned and payment initiated, it was too late for intervention.
Settlement happened in real time. Unlike card networks with chargeback infrastructure, QR-based payments cleared instantly. Once a victim authorized payment, funds moved immediately to the merchant account. There was no dispute window or reversal mechanism.
The ecosystem shared almost no fraud intelligence. Card networks built collaborative fraud-signal sharing over decades. Most QR and alternative payment networks operated in isolation. A merchant flagged for suspicious behavior on one platform could onboard cleanly on another the same day.
Regulatory pressure was mounting. Forrester reported a 15% rise in fraud involving QR codes, SIM swaps, and fake payment apps across APAC in the past year. Singapore's Shared Responsibility Framework, active since December 2024, shifted liability from consumers to institutions. Banks, telcos, and platforms were now jointly responsible for fraud that occurred on their watch.
The Approach Taken
APAC regulators realized consumer verification of QR codes was ineffective. Instead, they assigned liability up the chain and required institutions to build monitoring infrastructure.
Singapore's waterfall model made the bank liable first if it failed fraud-surveillance duties, then the telco, and finally the consumer. This was a regulatory obligation.
Malaysia's Interoperable Fund Transfer Framework, enforced by June 2028, eliminated closed QR networks. All payment QR codes had to route through DuitNow QR, removing cross-wallet blind spots. Merchant Acquirers became responsible for onboarding checks and monitoring.
Australia's Scam Prevention Framework, active since February 2025, placed obligations on banks, telcos, and digital platforms jointly. The focus was on institutional failure, not consumer verification.
The technical response shifted from transaction monitoring to merchant behavior monitoring:
- Flag merchants issuing high volumes of QR codes with low completion rates before fraud reports arrive.
- Track the gap between QR code generation and payment. Legitimate use is fast and predictable; fraud shows long, erratic gaps.
- Score the payee in real time, not just the payer, because once payment clears there's no undo.
Results and Metrics
The regulatory frameworks created immediate accountability. Platforms could no longer treat sub-account governance as secondary. Banks couldn't rely on consumer education as their primary defense.
The shift from consumer liability to institutional liability forced payment platforms to apply rigorous monitoring to merchant onboarding, similar to card networks. Sub-accounts that could previously generate payment QR codes with minimal oversight now required behavioral monitoring and payee risk scoring.
Mimecast's Q3 2025 detection numbers, 716,000 malicious QR codes, up 13% quarter-over-quarter, showed the scale of the problem. More importantly, they showed detection was possible when platforms treated QR code generation as a privileged action requiring real-time monitoring.
What They Would Do Differently
The industry waited too long to recognize QR code fraud wasn't a scanning problem. Early responses focused on consumer warnings, "verify before you scan" messaging that placed the burden on victims while systemic vulnerabilities remained.
If platforms had applied merchant behavior monitoring from the start, tracking QR code generation patterns and payee concentration, many sub-account attacks would have been flagged early. The TikTok case proved legitimate parent merchants could host fraudulent sub-accounts. That risk was knowable and measurable with the right tools.
Another missed opportunity was cross-platform fraud intelligence sharing. Card networks built this decades ago. QR and alternative payment platforms still operate in silos. Until the industry builds collaborative fraud-signal sharing, fraudsters will exploit the gaps.
Takeaways for Your Team
Stop treating QR codes as a consumer education problem. The fraud happens in merchant onboarding and sub-account governance, layers your institution controls.
Instrument merchant behavior, not just transactions. Monitor QR code generation volume, completion rates, time gaps between generation and payment, and payee concentration patterns. These signals surface fraud before victims report it.
Score the payee in real time. Your transaction monitoring likely focuses on the payer. In QR code fraud, the recipient's risk profile matters more. Build payee risk scoring into your authorization flow.
Audit your sub-account governance. If your platform allows verified merchants to create sub-accounts with delegated payment privileges, those sub-accounts are your exposure. Apply the same monitoring to sub-accounts as you do to top-level merchants.
Prepare for liability shifts. Singapore, Australia, and Malaysia have already moved liability from consumers to institutions. If you operate in APAC or have customers there, you're subject to these frameworks. If you operate elsewhere, study them, they're the model for what's coming.
The regulatory logic is settled: institutions that control merchant onboarding and payment authorization are responsible for fraud on their platforms. Ensure your detection infrastructure matches that accountability.



