facebook-pixel

Phishing Attacks in Singapore: How to Recognise and Avoid Them in 2026

L
Lunyb Security Team
··9 min read

Singapore consistently ranks as one of the most digitally connected nations in the world, but that same connectivity has made it a prime target for phishing attackers. According to the Singapore Police Force and the Cyber Security Agency (CSA), scam and cybercrime losses in Singapore continue to climb year after year, with phishing among the top attack vectors. This guide explains how phishing attacks in Singapore work, the red flags to look for, and how individuals and businesses can defend themselves.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a trusted entity — a bank, government agency, delivery firm, or colleague — to trick victims into revealing sensitive information or transferring money. In Singapore, phishing commonly targets DBS, OCBC, UOB customers, SingPass users, and recipients of SingPost or courier notifications.

Unlike random malware attacks, phishing exploits human trust. A single click on a spoofed link or a moment of panic reading a fake "account suspended" SMS can compromise banking credentials, MyInfo data, or corporate systems.

The Phishing Landscape in Singapore

Singapore's phishing threat has evolved rapidly. In the early 2020s, most attacks were crude English-language emails. Today, phishing campaigns targeting Singaporean users are highly localised, referencing GST vouchers, IRAS tax refunds, LTA traffic fines, and even MOM work pass notifications.

The Cyber Security Agency of Singapore (CSA) reported tens of thousands of phishing attempts each year, with fake banking sites and government impersonation making up the largest share. The 2021 OCBC phishing incident, which cost victims over S$13.7 million, remains a defining moment that pushed banks to remove clickable links from SMS messages entirely.

Why Singapore Is a High-Value Target

  • High digital adoption: Nearly universal smartphone penetration and PayNow usage.
  • Wealth concentration: High per-capita income makes successful scams lucrative.
  • Trust in institutions: Singaporeans generally trust government and bank communications, which attackers exploit.
  • Multilingual population: Attackers can craft messages in English, Mandarin, Malay, or Tamil.

Common Types of Phishing Attacks in Singapore

1. SMS Phishing (Smishing)

Smishing is the most prevalent form of phishing in Singapore. Victims receive an SMS that appears to come from a bank, SingPost, or a government agency, urging immediate action. Since 2022, the SMS Sender ID Registry (SSIR) has made it harder for scammers to spoof official IDs, but attackers now use fake short codes or numeric senders instead.

2. Email Phishing

Fake emails impersonating IRAS tax refunds, DHL parcel deliveries, or Microsoft 365 login prompts remain extremely common. These often lead to convincing replica websites hosted on lookalike domains such as dbs-secure-login.com or singpass-verify.net.

3. WhatsApp and Telegram Scams

Attackers pose as friends, employers, or delivery drivers on messaging apps. A common variant: someone claims to be from your bank's fraud team and asks you to "verify" a transaction by sharing an OTP.

4. Voice Phishing (Vishing)

Callers impersonate police officers, SingPost, or the Ministry of Health. The infamous "China officials" scam variant tells victims they are involved in money laundering and must transfer funds to a "safe account."

5. QR Code Phishing (Quishing)

Fake QR codes stuck over legitimate ones at hawker centres, bubble tea shops, and even survey flyers redirect users to credential-harvesting pages. A 2023 case in Singapore saw a woman lose S$20,000 after scanning a QR code offering a free drink.

6. Business Email Compromise (BEC)

Targeted at SMEs and finance teams, BEC involves attackers impersonating suppliers or executives to redirect invoice payments. Singapore MAS and the Police have flagged BEC as one of the fastest-growing threats to local businesses.

Red Flags: How to Recognise a Phishing Attempt

Most phishing attempts share tell-tale signs. Train yourself to pause and check for the following before clicking, replying, or paying.

Red FlagExampleWhat to Do
Urgency or threats"Your account will be suspended in 24 hours"Ignore and verify via official app
Suspicious sender domainsupport@dbs-sg-alert.comCheck the exact domain, not the display name
Requests for OTP or password"Please share the SMS code to verify"Never share OTPs with anyone
Unusual payment methodsRequests for gift cards, crypto, or PayNow to unknown numbersRefuse and report
Grammatical errorsAwkward phrasing, missing articlesTreat as suspicious
Mismatched URLsLink text says dbs.com.sg but points elsewhereHover to preview before clicking

Verifying Links Safely

Shortened links are a common phishing tool because they hide the true destination. Before clicking, expand any shortened URL using a link preview service. Reputable shorteners such as Lunyb provide transparent, scannable links and click analytics that legitimate businesses can share confidently — but that also means users should always preview unknown short links first. For a broader look at reputable shorteners, see our 2026 URL shortener buyer's guide.

How to Avoid Phishing Attacks: A Step-by-Step Framework

  1. Pause before acting. Scammers rely on panic. Take 30 seconds before responding to any urgent message.
  2. Verify through official channels. Log in to your bank's app directly rather than clicking any link. Call the number printed on your bank card, not the one in the message.
  3. Enable Money Lock and transaction alerts. All major Singapore banks now offer "Money Lock" features to ring-fence funds from digital access.
  4. Use two-factor authentication (2FA). Prefer app-based authenticators or hardware tokens over SMS OTPs where possible.
  5. Keep devices patched. Enable automatic updates for iOS, Android, and browsers.
  6. Install anti-scam apps. The ScamShield app, developed by the Singapore Police Force and Open Government Products, blocks known scam calls and SMS.
  7. Never share OTPs, SingPass, or MyInfo credentials. No legitimate agency will ever ask for them.
  8. Use unique passwords. A password manager helps you avoid reusing credentials that could be exposed in breaches.

Protecting Businesses in Singapore from Phishing

Phishing is not just a consumer problem. Under Singapore's Personal Data Protection Act (PDPA) and MAS Technology Risk Management Guidelines, organisations have legal and regulatory obligations to protect customer data — and phishing is a leading cause of breaches.

Technical Controls

  • Email authentication: Implement SPF, DKIM, and DMARC with a reject policy for your domain.
  • Advanced email filtering: Use tools like Microsoft Defender for Office 365, Google Workspace Advanced Protection, or Proofpoint.
  • Endpoint protection: Deploy EDR solutions to catch malware delivered through phishing.
  • Encrypted DNS and web filtering: Block known phishing domains at the network layer.
  • Phishing-resistant MFA: Move toward FIDO2/passkeys for privileged accounts.

Human Controls

  • Quarterly phishing simulation exercises tailored to Singapore-specific lures (IRAS, CPF, SingPost).
  • Clear internal reporting channels — a one-click "Report Phish" button in email clients works well.
  • Segregation of duties for payments, with dual approval for any change in supplier bank details.

Vendor and Link Hygiene

Businesses that send marketing links to customers should use consistent, branded domains so recipients learn to trust them. Trusted shortening providers help maintain that consistency; you can compare options in our Rebrandly review and Lunyb honest review to see how link branding reduces the risk of customers mistaking your emails for phishing.

What to Do If You Fall Victim

If you suspect you've clicked a phishing link or shared information, act immediately. Speed is critical because Singapore banks can sometimes freeze fraudulent transfers within minutes.

  1. Contact your bank's 24/7 fraud hotline and activate a "kill switch" if available (DBS, OCBC, UOB, Standard Chartered, Citibank all offer this).
  2. Change compromised passwords from a clean, trusted device.
  3. Enable Money Lock on remaining funds to prevent further access.
  4. Lodge a police report via the Singapore Police Force at eservices.police.gov.sg or in person at any Neighbourhood Police Centre.
  5. Report the scam to ScamShield (ScamShield app or scamshield.gov.sg).
  6. Notify your employer if work devices or accounts were involved.
  7. Monitor your credit with the Credit Bureau Singapore (CBS) for any unauthorised applications.

Official Singapore Resources

  • ScamShield Helpline: 1799
  • Singapore Police Force: Anti-Scam Centre, 1800-722-6688
  • Cyber Security Agency (CSA): csa.gov.sg — SingCERT reports phishing trends and provides advisories.
  • GoSafeOnline: Public awareness portal run by CSA with regularly updated phishing case studies.
  • Monetary Authority of Singapore (MAS): Financial industry advisories and Shared Responsibility Framework details.

The Future of Phishing in Singapore

Phishing is becoming harder to spot. Generative AI now produces grammatically perfect, culturally accurate lures in Singlish, Mandarin, or Malay. Deepfake voice scams have already been documented locally, with a 2024 case involving a fake video call from a supposed CEO. Attackers are also increasingly abusing legitimate services — Google Forms, Notion pages, and Dropbox share links — to host phishing content that bypasses traditional filters.

Defence must evolve accordingly. Expect wider adoption of passkeys, mandatory device binding for banking apps, and stronger implementation of Singapore's Shared Responsibility Framework, which shifts liability between banks, telcos, and consumers based on how each party handled the scam.

Frequently Asked Questions

What is the most common phishing scam in Singapore?

SMS phishing impersonating banks (particularly DBS, OCBC, and UOB) and government agencies like IRAS or SingPost is the most common. Since 2022, Singapore banks have removed clickable links from SMS, so any SMS with a link claiming to be from your bank is almost certainly a scam.

Will my bank in Singapore reimburse me if I fall for phishing?

It depends. Under MAS's Shared Responsibility Framework, banks and telcos may bear losses if they failed their duties (e.g., not detecting suspicious transfers, delivering scam SMS). However, if you shared your OTP or credentials, you may be considered partly liable. Report the scam within hours to maximise chances of recovery.

How do I check if a link in an SMS or email is safe?

Do not click. Instead, log in to the service directly through its official app or by typing the website into your browser. For shortened links, use a link-preview tool to see the true destination first. Reputable link platforms like Lunyb publish their domain openly so users can verify branded short links.

Is ScamShield effective against phishing in Singapore?

Yes, ScamShield is one of the most effective consumer tools available locally. It blocks known scam calls and filters suspicious SMS on iOS and Android. It won't stop every threat — especially newer WhatsApp or Telegram scams — but combined with 2FA and cautious behaviour, it significantly reduces risk.

What should businesses do first to defend against phishing?

Start with three foundations: enforce DMARC (reject) on your email domain, roll out phishing-resistant MFA (passkeys or hardware tokens) for all staff, and run regular phishing simulations tailored to Singapore-specific lures. Combined, these measures block the majority of common attacks and dramatically reduce blast radius when one does succeed.

Final Thoughts

Phishing attacks in Singapore have grown more sophisticated, more localised, and more damaging. But the defences are equally strong: awareness, verification habits, technical controls like DMARC and passkeys, and national resources like ScamShield and the Anti-Scam Centre. The single most powerful protection remains a simple mindset — pause, verify, then act. If a message creates panic or demands secrecy, that is almost always the phishing red flag itself.

Stay updated with CSA advisories, use trusted platforms for your links and communications, and share this knowledge with older family members and colleagues who are often the most vulnerable. In cybersecurity, community awareness is one of the strongest firewalls we have.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles