Police Warn Against VNeID Scams as Cybercriminals Target Vietnam's Digital ID Users

- Au Co Ward Police in Phu Tho province successfully intervened to protect a resident targeted by a fraudulent VNeID activation phone scam.
- Impersonators pose as police officers to trick users into downloading malicious software or providing confidential banking and personal credentials.
- Law enforcement reiterates that Level 2 VNeID identity registration cannot be conducted over the phone and strictly requires in-person biometric capture at official stations.
- Citizens are warned never to click unverified external links, download unknown APK files, or share one-time authentication codes (OTPs).
A timely intervention by local law enforcement officers in northern Vietnam has exposed the evolving tactics of cybercrime syndicates targeting the country's flagship electronic identification infrastructure, prompting authorities to reiterate strict security protocols for millions of digital citizens.
Quick summary
- Officers at Au Co Ward Police in Phu Tho province prevented a resident from losing sensitive data to fraudsters posing as police officers offering Level 2 VNeID activation support.
- Scammers increasingly leverage social engineering, malicious application links, and fake official identities to trick citizens into compromising administrative credentials and banking data.
- Authorities reiterate that Level 2 electronic identity registration requires in-person biometric verification at designated police stations and can never be completed remotely over the phone.
- Citizens are advised never to install software from unverified links, disclose one-time passwords (OTPs), or transfer money at the request of unsolicited callers.
Why it matters
As Vietnam accelerates its national digital transformation under Project 06, the VNeID application has become a central gateway for public administration, digital citizenship, healthcare records, and civil registry management. Because Level 2 electronic identification integrates verified personal identification records, criminal record checks, and driver licenses, a compromised VNeID account poses severe risks beyond simple identity theft.
Threat actors who gain remote access through deceptive links or manipulated credentials can exploit administrative privileges, initiate illicit financial transfers, or manipulate bank accounts tied to digital verification. The persistent weaponization of administrative milestones threatens public confidence in national digital platforms, making vigilance and rapid community-level policing essential shields against widespread fraud.
Background
Over the past two years, Vietnam's Ministry of Public Security has progressively rolled out the VNeID ecosystem to streamline public administrative services and reduce physical paperwork. While Level 1 accounts can be activated independently on mobile devices through citizen identification card data, Level 2 accounts mandate strict facial recognition and fingerprint cross-referencing conducted directly by police personnel.
Despite clear institutional policies, cybercriminals frequently exploit public confusion surrounding administrative deadlines and technical requirements. Previously, syndicates relied on impersonating tax officials, judicial officers, or couriers delivering suspicious packages. In recent months, fraud syndicates have pivoted toward exploiting technical support scenarios, capitalizing on citizens' eagerness to comply with administrative digitalization mandates.
The Phu Tho Incident: How Local Police Intercepted the Threat
The latest operational alert stemmed from an incident on August 12 in Au Co Ward, Phu Tho province. A local temporary resident, identified as Vu Tien Hoang Vi (born 2003), received an unsolicited phone call from an individual claiming to be an officer attached to the ward police station. The caller asserted that Vi needed immediate assistance to complete and activate his Level 2 VNeID electronic identification profile.
Recognizing inconsistencies in the caller's instructions and tone, Vi promptly visited the Au Co Ward police station to confirm the legitimacy of the request. Officers immediately identified the approach as a textbook social engineering attempt aimed at securing unauthorized access to the resident's mobile device and financial credentials.
Police personnel advised Vi to terminate all contact with the caller immediately and guided him through safe social media and digital hygiene practices. Authorities emphasized key preventative steps, explicitly instructing the resident to refuse any requests for one-time passwords (OTPs), bank account numbers, or personal credentials, and to never download applications via unofficial links.

Tactics and Attack Vectors Exploited by Impersonators
Cybersecurity specialists and police investigators highlight that phone scams centered on digital identity generally follow a coordinated, multi-stage attack vector designed to bypass standard mobile operating system protections:
1. Establishing Authority and Urgency
Scammers masquerade as local administrative or police officials, often citing fabricated system errors, non-compliance penalties, or imminent data lockouts to induce panic and force rapid compliance without independent verification.
2. Distributing Malicious Installation Packages
Fraudsters direct targets away from official application marketplaces such as Google Play or Apple App Store, instructing them to access third-party links or download sideloaded Android Package Kits (APKs) disguised as official government utilities.
3. Hijacking Device Permissions
Once installed, these malicious tools request elevated Accessibility Service permissions. This enables threat actors to mirror smartphone screens, capture keystrokes, intercept SMS authentication codes, and remotely execute transactions without the victim's immediate knowledge.
Crucial Verification Rules for Digital Citizens
To safeguard personal data and prevent financial losses, law enforcement agencies urge the public to observe fundamental security guidelines when managing their digital accounts:
- In-Person Requirement for Level 2: State authorities do not process Level 2 VNeID registrations or updates via telephone calls, messaging platforms, or external video chats. All Level 2 activations require direct physical presence at local police stations.
- Never Sideload Unknown Applications: Legitimate public administrative software is distributed exclusively through official channels and verified application stores. Citizens should never tap unverified links sent via SMS, Zalo, or social media.
- Protect Sensitive Credentials: Law enforcement personnel will never solicit OTP verification codes, banking passwords, or personal financial details under any pretext.
- Direct Verification: When in doubt, residents should hang up immediately and verify administrative notices directly at their nearest commune or ward police headquarters.
Qnews24h insight
The Au Co Ward case highlights both the vulnerability of individual users during nationwide digital transitions and the critical value of ground-level police responsiveness. While technological guardrails like biometric authentication and anti-malware safeguards continue to strengthen, human psychology remains the primary exploit targeted by organized cybercrime syndicates.
Protecting national digital infrastructure requires an ongoing balance between administrative convenience and aggressive public cybersecurity literacy campaigns. As long as citizens maintain the habit of verifying official requests in person rather than yielding to phone-based urgency, the return on investment for remote social engineering syndicates will drastically diminish.
Sources
- Soha.vn: Reporting on the official fraud prevention advisory issued by Au Co Ward Police, Phu Tho Province (August 2026).
- Phu Tho Provincial Police Department incident documentation.
Why it matters
The security of national digital identity platforms is foundational to modern governance, public administration, and consumer banking. Impersonation scams targeting VNeID do not merely inflict direct financial losses on individuals through device hijacking; they also threaten broader public trust in essential digital public services.
Background
As Vietnam accelerates its national administrative modernization through the VNeID platform, millions of citizens are required to register electronic identity accounts. Scammers have continually adapted their methods, shifting from fake tax collection and legal summons scams to exploiting the procedural steps of Level 2 VNeID registration.
The persistent threat of administrative impersonation highlights the need for continuous public cybersecurity education. While software safeguards evolve, frontline police accessibility and citizen skepticism toward unsolicited calls remain the most effective deterrents against remote social engineering.
References
Editorial information
The editorial team reviews sources, adds context, and structures stories so readers can understand the news more clearly.
Article from QNEWS24H
Comments
(0)No comments yet. Be the first to share your thoughts.