top of page

Online scams during Vietnam National Day 2026: Deepfakes and malicious QR codes increase digital transaction risks

In late August 2026, Vietnamese authorities and cybersecurity sources warned of scams targeting the September 2 National Day holiday, including deepfake family impersonation, malicious QR codes, fake hotel bookings and fraudulent airline tickets. Vietnam’s A05 reported 959 online fraud cases causing approximately VND 1.5 trillion in losses during the first half of 2026. The issue is not associated with a specific CVE.

When images, voices and QR codes can all be generated, manipulated or weaponized for fraud, the familiar rule of “recognize it, therefore trust it” is no longer sufficient. On August 30, 2026, Vietnam Cybersecurity Magazine warned that online scams were becoming increasingly personalized, with artificial intelligence helping attackers produce more convincing identity impersonation and fraudulent content.

For businesses, the risks extend well beyond employees losing personal funds. A fake fund-transfer request impersonating an executive, a QR code leading to a counterfeit Microsoft 365 login page, or a compromised travel account can become the starting point for credential theft, payment fraud and unauthorized access to corporate systems.

online-scams-vietnam-national-day-2026
Warning online scams during Vietnam National Day 2026

What is happening during the September 2 National Day holiday period?

Attackers are combining established social engineering techniques with artificial intelligence, fake websites and digital payment workflows to create more convincing fraud scenarios. Their objectives remain familiar: persuading victims to transfer money, disclose login credentials or one-time passwords, or install untrusted software.

On August 22, 2026, the Civil Aviation Authority of Vietnam warned that fake websites, social media pages and accounts impersonating aviation brands could promote discounted tickets, special offers or other programs to steal payments and collect personal information.

The authority cited statistics from the Department of Cybersecurity and High-Tech Crime Prevention, known as A05, showing that 959 online fraud cases were detected nationwide during the first six months of 2026, causing approximately VND 1.5 trillion in losses.

On August 26, Gia Lai Provincial Police also highlighted several common holiday scam scenarios, including fake hotel bookings and discounted tickets, fraudulent promotions and giveaways, impersonation of government agencies, counterfeit event tickets and criminals posing as relatives to request money.

👉 For broader context, IPSIP’s Vietnam Cybersecurity Landscape Q2 2026 also noted that AI and deepfake technologies are enabling attackers to produce fraudulent content faster, personalize it more effectively and make impersonation increasingly difficult to identify.

Why are deepfakes and QR codes becoming more effective attack tools?

Deepfakes weaken one of the most natural human verification mechanisms: recognizing a familiar face or voice. Quishing, or phishing through QR codes, hides the destination URL from immediate view and often moves the victim’s interaction from a desktop environment to a mobile device.

The U.S. Federal Trade Commission has warned that scammers can take a short audio sample available online and combine it with voice-cloning technology to imitate a family member. The FTC recommends that people should not verify a financial request based only on a voice and should instead call a known phone number or confirm the request through another trusted person.

The FBI has similarly documented malicious actors using AI-generated messages and voices to impersonate trusted or high-profile individuals. Attackers may then attempt to move conversations to another platform or send links designed to compromise accounts.

QR phishing is also growing significantly. Microsoft reported that QR-code phishing volume increased from 7.6 million incidents in January to 18.7 million in March 2026, representing a 146% increase during the first quarter. PDF files were the dominant delivery method, accounting for approximately 70% of QR-code attacks observed in March.

Scam scenario

How attackers build trust

Primary objective

Warning signs

Deepfake family member or executive

Familiar face or cloned voice

Money transfer, sensitive data

Urgency, secrecy, unusual requests

Malicious QR code

QR embedded in PDFs, emails, posters or messages

Credential theft, malware delivery

Login request immediately after scanning

Fake travel booking or ticket

Brand logos, realistic imagery, fake pages

Deposit or payment theft

Unusually low prices, pressure to pay

Fake promotion or giveaway

Impersonated brand or organization

OTP, banking data

Suspicious links, requests for personal data

Government or institutional impersonation

Legal or financial pressure

App installation, money transfer

Demands for immediate action

Which scenarios should businesses and employees be particularly concerned about?

The business risk increases when consumer-oriented scam techniques are adapted to corporate environments. Attackers may impersonate senior executives and request payments, send malicious QR codes that imitate authentication processes, or pose as suppliers asking employees to change payment details.

Microsoft has previously observed email campaigns using PDF attachments and QR codes that redirected victims to RaccoonO365 phishing infrastructure designed to steal Microsoft 365 credentials. During an approximately two-week period in February 2025, related activity targeted more than 2,300 organizations.

In Vietnam, Can Tho City Police warned on August 21, 2026, that images, voices and videos should not be treated as standalone proof of identity. Additional caution is particularly important when a familiar person or authority figure asks someone to transfer money, provide an OTP, open a link, scan a QR code or install an application.

Businesses seeking broader phishing guidance can also reference IPSIP’s article on phishing email warning signs, risks and prevention tools, which provides a useful foundation for employee awareness and internal reporting procedures.

What should businesses do immediately to reduce the risk?

The most important control is to eliminate single-channel verification for sensitive transactions. Video, voice, email and messaging accounts can all be manipulated, impersonated or compromised.

Priority action checklist:

  • Establish a call-back verification procedure for unusual payment requests using a previously known telephone number or approved communication channel.

  • Require at least two authorized individuals to approve financial transactions above a defined threshold.

  • Prohibit employees from providing passwords, OTPs or other authentication information through phone calls, email or messaging platforms.

  • Train employees to review the destination URL after scanning a QR code and stop if an unexpected login page appears.

  • Enable MFA for email, VPN, cloud platforms and other critical systems; use phishing-resistant MFA where practical for privileged accounts.

  • Create a rapid reporting channel for suspicious emails, QR codes, calls or payment requests.

  • Monitor abnormal logins, MFA changes, newly created sessions and unusual data-download behavior.

  • Conduct targeted deepfake and executive-impersonation exercises for finance teams, procurement teams and senior management.

If an account may already have been compromised, changing the password alone may not be sufficient. Organizations should consider revoking sessions and tokens, reviewing authenticated devices, checking newly registered MFA methods and examining recently granted application permissions.

What does the IPSIP Vietnam's expert perspective highlight?

Businesses should move away from the assumption that recognizing a face, voice or account is sufficient proof of identity. Sensitive transactions should instead require verification through an independent and previously established channel.

The September 2, 2026 National Day period demonstrates how online fraud is evolving from easily recognizable scam messages toward more personalized and convincing forms of impersonation. Deepfakes, malicious QR codes, fake travel websites and impersonated social media accounts may differ in presentation, but they exploit the same weakness: persuading victims to skip independent verification.

👉 For Vietnamese businesses, the priority should not be attempting to identify every fake image, voice or message by visual inspection alone. Security processes should ensure that no single video, voice call, email or QR code can independently authorize a sensitive transaction.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page