Sylpi Nopiya
Universitas Kebangsaan Republik Indonesia, Bandung, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Analysis of QRIS Misuse Mode as a Means of Personal Data Theft and Account Takeover in Bandung City, Indonesia Nur Muhamad Hamka; Sylpi Nopiya; Tantri Pebyani; Suci Fitriani; Viny Limbong; Yulianah Yulianah
Advances in Community Services Research Vol. 4 No. 2 (2026): March - August
Publisher : Yayasan Pendidikan Bukhari Dwi Muslim

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.60079/acsr.v4i2.878

Abstract

Purpose: This study analyzes the mechanisms of quishing attacks within QRIS transactions, examines users' vulnerability to QR-code-based fraud, and evaluates mitigation efforts and legal protection in Indonesia's digital payment ecosystem. Research Method: A sequential explanatory mixed-methods design was employed. Quantitative data were collected through online questionnaires distributed to QRIS users in Bandung using purposive sampling. Of the 100 questionnaires distributed, 89 valid responses met the inclusion criteria. Qualitative data from documented fraud cases and relevant literature were used to explain the quantitative findings. Results and Discussion: Although 89.9% of respondents were aware of QR code fraud risks, 38.2% had experienced financial losses, and 31.5% had nearly become victims. Routine payment activities (44.6%) and promotional offers (24.1%) emerged as the dominant triggers for scanning fraudulent QR codes. Furthermore, 39.5% of respondents reported being redirected to phishing websites, indicating that quishing frequently facilitates credential theft and account takeover through social engineering techniques. Implications: The findings highlight the need for stronger cybersecurity governance through dynamic QRIS implementation, enhanced security features, and continuous consumer education. Originality: This study integrates behavioral evidence from QRIS users with legal and cybersecurity perspectives to provide a comprehensive understanding of quishing in Indonesia's digital payment ecosystem.