All Tools & QuizzesInteractive Quiz · 11 Questions

Can You Spot a Scam in the Philippines?

Test your scam-spotting skills against real GCash, courier, and job-scam texts hitting the Philippines.

Why scam texts work — and how to spot them

Phishing in the Philippines rarely looks technical. It looks like a courier saying your parcel is on hold, a bank saying your card was used in another city, a recruiter offering ₱1,500 a day for liking videos, or a GCash message saying your account will be frozen unless you confirm your details today. The message is designed to trigger urgency, because urgency is what stops people from checking.

The tell is almost always the destination, not the wording. Legitimate banks, e-wallets, and government agencies do not ask you to enter your PIN, OTP, MPIN, or full card number on a page you reached from a text message, and they never ask you to send an OTP to a person. If a message pushes you toward a link or a phone number to 'verify', treat the link itself as the scam even when the sender name looks right.

Sender IDs can be faked. Under the SIM Registration Act many commercial senders use branded names, and scammers copy those names so their message lands in the same thread as real ones. A message appearing inside an existing bank or wallet thread is not proof it came from the bank. Open the official app yourself and check for the same notice there.

The 11 questions in this quiz are modelled on message patterns actually circulating in the Philippines: courier redelivery fees, fake GCash verification pages, salary-too-good job offers on Telegram, cloned bank domains with an extra hyphen, and 'wrong send' refund requests. Score 9 or higher and you can reliably spot the common ones; anything lower is worth a second run after you read the answers.

  • Never share an OTP. There is no legitimate reason for anyone — including a bank agent, a courier, or a buyer — to ask for it.
  • Type the domain yourself instead of tapping links. Scam sites use lookalikes such as gcash-verify, bpi-secure, or a .com that should be .com.ph.
  • Enable in-app notifications and biometrics on your e-wallet and banking apps so unauthorised logins surface immediately.
  • If you already tapped and entered details, change the password, revoke sessions in the app, and report it to your bank or wallet provider straight away.
  • Report scam numbers to your telco (free) and, for financial losses, to the bank's official hotline and the PNP Anti-Cybercrime Group.

Frequently asked questions about phishing in the Philippines

How can I tell if a GCash or Maya message is real?

Ignore the sender name and check the app. Real account notices always appear inside the official app's notification centre. GCash and Maya never ask for your MPIN, OTP, or password by text, call, chat, or web form — any message that does is a scam regardless of how official it looks.

What should I do right after clicking a phishing link?

If you only opened the page, close it and clear the tab. If you entered credentials, immediately change that password, log out of all sessions in the official app, remove any linked cards, and call your bank or wallet's official hotline to flag the account. Speed matters more than certainty here.

Can scammers really take money using only an OTP?

Yes. An OTP is the final approval step, so a scammer who already has your number and password only needs that code to move funds or link your account to a new device. That is why sharing an OTP is the single most damaging mistake in almost every reported case.

Are 'work from home, ₱1,500 per task' job offers ever legitimate?

Almost never when they arrive unsolicited by text or Telegram and pay for liking videos, rating hotels, or making small 'deposits' to unlock tasks. The pattern pays out small amounts first to build trust, then requires a larger top-up that is never returned.

Where do I report a scam text in the Philippines?

Forward it to your telco's free reporting channel, report the number in-app if it impersonates a wallet or bank, and file a report with the PNP Anti-Cybercrime Group or the NBI Cybercrime Division if you lost money. Keep screenshots and reference numbers.

Keep going