A QR code can make a Philippine game top-up fast, but it can also hide a payment recipient or web address until it is scanned. The Bangko Sentral ng Pilipinas calls malicious QR-code phishing quishing: a code may lead to a fraudulent site, request personal information or trigger a harmful download. Treat the payment preview as a decision point, not a formality.
Start with an official purchase path
Use the game itself, Google Play, the Philippine App Store or a top-up site clearly listed by the publisher. A QR code posted in a comment, group chat, livestream or private message is not made official by a game logo or a low price.
When a publisher names an authorized partner, reach that partner through the publisher’s current page. Do not rely on a screenshot of an old partner list. Our official top-up checklist explains the source check.
Know what the QR code is asking the phone to do
A payment QR may open a bank or e-money app with a recipient and amount. Another code may open a website. Stop if it starts an app download, asks to install an APK, requests device-management access or leads to a login page unrelated to the verified seller.
QR Ph is the Philippine national standard for interoperable QR payments, but seeing a QR-style label does not prove that a particular seller or transaction is legitimate. The BSP Verifier itself says registration information is a guide, not a guarantee of financial soundness or safety.
Check four details before confirming
- Seller: confirm the offer is on an official publisher or authorized-partner page.
- Destination: read the full website domain or the recipient name shown by the payment app.
- Amount: verify the Philippine-peso total and any fee instead of trusting the image beside the code.
- Game account: confirm the player ID, server and character without sharing a password or OTP.
If any detail differs, cancel. A real promotion can survive a manual verification; a scammer often pressures the buyer to act before checking.
Never send credentials or approval codes
A normal payment confirmation may use the bank or wallet’s own security step. A seller should not ask you to read back an OTP, approve a new device, share a recovery code or screen-share the wallet. Those actions can authorize access beyond one purchase.
The BSP’s consumer guidance says to check sources, protect personal and financial information and report suspicious transactions quickly. Keep the game password separate from email and payment accounts, and use strong verification where available.
Printed codes and replaced stickers
At a kiosk, tournament or café, inspect whether a second QR sticker covers the original. Ask staff to confirm the displayed recipient name and amount. Do not scan a code left loose on a counter or attached to an unofficial event poster.
For person-to-person payment, understand that the wallet may show an individual’s registered name rather than a store brand. That mismatch needs an explanation before payment, not after. If staff cannot verify it, use another official channel.
Keep a useful but private receipt
Save the transaction reference, date, amount, seller page and game order number. Do not post the full receipt publicly; it may expose a name, phone number, email or reference that a fake support agent can misuse. Send evidence only through the payment provider’s and publisher’s official support routes.
A screenshot showing “successful” is not proof that currency reached the right game account. Check the in-game balance and official order history before repeating the payment.
If the QR payment looks suspicious
Do not scan it again. If no payment was made, report the listing to the platform and alert the impersonated publisher. If money moved, contact the bank or e-money issuer immediately, preserve the transaction reference and ask for the official dispute path.
The BSP directs consumers to report first to the concerned financial institution, then use its consumer-assistance channels with the complaint reference when appropriate. Cybercrime reports may also be made through the official agencies listed by BSP. Do not pay a second “recovery fee” to someone in chat.
Editorial review: 14 September 2026. Partner lists, payment screens and reporting routes can change; verify them on the live publisher, financial-provider and BSP pages.