Mid-Autumn Festival QR code scam uses “appreciation gifts” to steal data and money
On September 21, 2026, Vietnam’s Ministry of Public Security warned about a scam involving Mid-Autumn Festival gifts, tea, vouchers and “customer appreciation” packages containing QR codes. After scanning, victims may be redirected to fake websites, asked to provide login credentials or OTPs, install suspicious applications, or pay upfront fees, potentially leading to data theft and financial loss.
A physical gift delivered to someone’s home can appear more trustworthy than an unexpected email or suspicious text message. That trust is exactly what makes this type of social engineering effective.
According to the Ministry of Public Security, fraudsters may use leaked personal information to send packages to the correct recipient and make them look legitimate with familiar branding or e-commerce logos. The real risk is not the QR code technology itself, but the destination and actions hidden behind the code.

How does the Mid-Autumn Festival QR code scam work?
The scam typically begins with a package that appears legitimate. Fraudsters may send mooncakes, tea, greeting cards or vouchers together with messages such as “customer appreciation gift,” “confirm your gift,” or “claim your lucky money.”
Once the QR code is scanned, the victim may be pushed into one of several scenarios:
What happens after scanning | Likely objective |
Redirect to a fake banking or e-commerce website | Steal login credentials, personal data or OTPs |
Prompt to download an unknown file or application | Install software capable of collecting data or gaining control over the device |
Request a “shipping fee” or “activation fee” | Steal money directly and potentially demand further payments |
Authorities also warned that fake packages may use familiar brand logos or images to build trust. Shopee has separately warned users about fraudulent “appreciation gifts” and free prize schemes that use QR codes or instructions to move victims into the next stage of the scam.
Why are Mid-Autumn gifts effective for social engineering?
These campaigns combine three elements: seasonal demand for gifts, trusted brand imagery and enough personal information to make the package appear authentic.
What makes the physical-gift scenario notable is that it brings an offline element into the attack chain. A correct name, address, real package and recognizable logo can lower a victim’s suspicion before the malicious digital interaction even begins.
For businesses, this reinforces a broader cybersecurity lesson: social engineering attacks increasingly combine personal data, trusted identities and legitimate-looking customer experiences rather than relying on one technical exploit alone.
Who could be affected?
For individuals, the immediate risks include stolen credentials, OTPs, identity data or money.
For businesses, the impact can extend to brand impersonation, customer complaints, compromised employee accounts and exposure of corporate data. If an employee scans a malicious QR code on a personal device that also has access to Microsoft 365, business email or internal applications, the potential attack surface becomes wider.
This does not mean every QR scan automatically compromises a company. The actual impact depends on where the code leads, what information the victim enters, whether software is installed and what permissions are granted.
Another concern is the source of the personal information used to make these packages convincing. The Ministry of Public Security noted that leaked personal data may be used to deliver gifts directly to victims. Names, phone numbers and delivery addresses can therefore become part of the fraud infrastructure.
What should users do before and after scanning a QR code?
The safest approach is to separate the physical gift from the digital request. Receiving a real package does not prove that the QR code, website or campaign inside it is legitimate.
Immediate action checklist
Do not scan QR codes printed on packages or leaflets from unknown senders.
Do not trust a package solely because it carries a familiar company logo.
Open the company’s official website or app independently instead of using the provided QR code.
Never provide Internet Banking passwords, PINs, OTPs or verification codes to claim a gift.
Do not install .apk files or applications from unknown links.
Do not pay “shipping,” “activation,” or “verification” fees to receive a supposedly free gift.
If banking information has already been entered, contact the bank immediately through an official channel.
Preserve the package, message, QR code, suspicious URL and transaction history as evidence if a report is required.
What does IPSIP Vietnam’s expert perspective suggest?
The attack chain may involve social media, physical packages, QR phishing, fake websites and untrusted mobile applications. The goal is to persuade the victim to voluntarily provide information, install software or transfer money.

Organizations may face brand impersonation, customer trust issues, compromised employee accounts, data exposure and incident response costs. If customer data is used to personalize scam packages, the issue can also become a data governance and privacy concern.
The Mid-Autumn Festival QR code scam shows how social engineering is moving beyond email and messaging into blended physical-digital scenarios involving real packages, personal data and familiar brand imagery.
For Vietnamese businesses, the main lesson is not simply to tell employees to “avoid unknown QR codes.” A stronger approach is to build independent verification procedures, protect customer data, train users to recognize phishing patterns and maintain the ability to detect and respond when an account or device is compromised.
References
Vietnam Ministry of Public Security - Warning about Mid-Autumn Festival gift scams using QR codes to steal assets
Dân trí - Fraudsters impersonate agencies and organizations with fake Mid-Autumn Festival gift offers
Shopee Help Centre - Warning about fake customer appreciation gifts, free prizes and low-price offers











Comments