This article includes:
Common phishing tactics
Scammers usually begin with an email, SMS, or instant message that appears to be from Codashop and contains a link to a fake website. Codashop never reaches out first to request sensitive information, such as a one-time password (OTP), bank password, or e-wallet PIN.
Note: Codashop will never ask for an OTP, password, or PIN, even during a support conversation.
A common tactic is a phishing site that offers prizes in exchange for a phone number, using the name of a telco to appear legitimate. Top-ups made on a fake website are redirected to the scammer's account rather than the customer's.
Common scam formats to watch for:
- Accounts advertising phishing websites in Facebook groups
- Fake pages promoting "free diamonds" appearing in search results
- Fake social media accounts claiming to offer free diamonds and linking to phishing pages
- Videos encouraging viewers to check phishing links in the description
- Fake mobile applications impersonating the Codashop app
What to do if compromised
If payment details have been compromised, contact the relevant bank, telco company, or Codashop immediately to block the number. Confirm that any Codashop website is the official domain before entering payment details; some attackers use URL shortener techniques or lookalike domains to appear legitimate.
Note: Never reply to phishing emails or submit personal details to forms on fake websites. This can lead to identity theft and unauthorized withdrawals from bank accounts.
Official Codashop Malaysia platforms
- Codashop Malaysia website
- Facebook Codashop Malaysia
- Instagram Codashop Malaysia
- Blog Codashop Malaysia
Note: Be cautious of any information claiming to be from Codashop that comes from sources other than those listed above. Purchases can only be made through Codashop's official platforms and must be completed directly by the customer.
To report a scammer, contact Customer Support.