As digital finance becomes an everyday convenience, GCash is urging Filipinos to stay alert against increasingly sophisticated online scams designed to exploit human trust.
Phishing and smishing now account for more than 80% of reported digital fraud cases nationwide. A report by Gogolook underscores this escalating threat, revealing that malicious link attacks nearly quadrupled in 2025 alone as bad actors frequently impersonated reputable institutions to deceive account holders.
In response to these escalating risks, GCash operator G-Xchange Inc. is fortifying its multi-layered security ecosystem. Alongside technical barriers like biometric logins, multi-factor authentication, and in-app one-time passwords (OTPs), the platform is championing collaborative defense under Republic Act No. 12010, also known as the Anti-Financial Account Scamming Act (AFASA). However, as Chief Information Security Officer Joel Geronimo points out, technical solutions are only half the battle; real safety requires active user vigilance.
Recognizing the Red Flags
Fraudsters rely heavily on social engineering to prompt quick, emotional decisions. Staying secure begins with knowing how to spot their most frequent tactics:
Suspicious External Links
Scammers often craft messages claiming an account is suspended or under threat, directing users to click an external link. These malicious pages mimic official login screens to harvest passwords, MPINs, and OTPs. GCash strictly maintains that it will never send external links via text message, nor will it direct customers outside the app to resolve account alerts.
Urgent Rewards and Expiring Points
Deceptive texts frequently tease free prizes, unclaimed refunds, or points that will expire within the hour. Phrasing such as “claim now,” “last chance,” or “verify immediately” is meant to induce panic. Legitimate promotions should always be reviewed directly through official in-app notifications rather than unsolicited SMS links.
Credential Harvesting via Phone and Text
Whether through robocalls or spoofed phone numbers, scammers frequently pose as customer support representatives needing to reactivate or update an account. Platform representatives will never request sensitive security credentials, making any prompt for an OTP or MPIN an immediate red flag.
Imposter and Emergency Scams
In these emotionally driven scenarios, bad actors impersonate friends or family members facing urgent financial emergencies, such as sudden medical bills or legal troubles. Before using Send Money or initiating a bank transfer, users should pause and independently verify the request through a secondary channel.
An Extra Layer: GInsure Scam Protection

Even with disciplined digital habits, sophisticated schemes can occasionally slip past a user’s radar. To give account holders a dedicated financial buffer, GCash has rolled out GInsure Scam Protection, an in-app insurance solution underwritten by Chubb Philippines.
Available directly within the application, users can activate up to ₱15,000 in coverage for 30 days for a one-time fee of ₱30. The policy covers unauthorized transactions resulting from phishing, hacking, and identity spoofing. This includes fraudulent transfers made through Send Money, illicit bank transfers, and compromised transactions across partner e-commerce platforms like Lazada, Shopee, and the Google Play Store.
While GInsure Scam Protection provides valuable financial backup, platform leaders stress that insurance is designed to complement—not replace—careful digital hygiene.
If you encounter suspicious communication or suspect unauthorized account activity, reports can be filed through the in-app Help Center, via the Gigi chat support feature, or by phoning the 2882 hotline. Incidents may also be escalated to the Philippine National Police Anti-Cybercrime Group at acg@pnp.gov.ph.
