Phishing Attacks in Singapore: How to Recognise and Avoid Them in 2026
Singapore consistently ranks as one of the most digitally connected nations in the world, but that same connectivity has made it a prime target for phishing attackers. According to the Singapore Police Force and the Cyber Security Agency (CSA), scam and cybercrime losses in Singapore continue to climb year after year, with phishing among the top attack vectors. This guide explains how phishing attacks in Singapore work, the red flags to look for, and how individuals and businesses can defend themselves.
What Are Phishing Attacks?
Phishing is a form of social engineering where attackers impersonate a trusted entity — a bank, government agency, delivery firm, or colleague — to trick victims into revealing sensitive information or transferring money. In Singapore, phishing commonly targets DBS, OCBC, UOB customers, SingPass users, and recipients of SingPost or courier notifications.
Unlike random malware attacks, phishing exploits human trust. A single click on a spoofed link or a moment of panic reading a fake "account suspended" SMS can compromise banking credentials, MyInfo data, or corporate systems.
The Phishing Landscape in Singapore
Singapore's phishing threat has evolved rapidly. In the early 2020s, most attacks were crude English-language emails. Today, phishing campaigns targeting Singaporean users are highly localised, referencing GST vouchers, IRAS tax refunds, LTA traffic fines, and even MOM work pass notifications.
The Cyber Security Agency of Singapore (CSA) reported tens of thousands of phishing attempts each year, with fake banking sites and government impersonation making up the largest share. The 2021 OCBC phishing incident, which cost victims over S$13.7 million, remains a defining moment that pushed banks to remove clickable links from SMS messages entirely.
Why Singapore Is a High-Value Target
- High digital adoption: Nearly universal smartphone penetration and PayNow usage.
- Wealth concentration: High per-capita income makes successful scams lucrative.
- Trust in institutions: Singaporeans generally trust government and bank communications, which attackers exploit.
- Multilingual population: Attackers can craft messages in English, Mandarin, Malay, or Tamil.
Common Types of Phishing Attacks in Singapore
1. SMS Phishing (Smishing)
Smishing is the most prevalent form of phishing in Singapore. Victims receive an SMS that appears to come from a bank, SingPost, or a government agency, urging immediate action. Since 2022, the SMS Sender ID Registry (SSIR) has made it harder for scammers to spoof official IDs, but attackers now use fake short codes or numeric senders instead.
2. Email Phishing
Fake emails impersonating IRAS tax refunds, DHL parcel deliveries, or Microsoft 365 login prompts remain extremely common. These often lead to convincing replica websites hosted on lookalike domains such as dbs-secure-login.com or singpass-verify.net.
3. WhatsApp and Telegram Scams
Attackers pose as friends, employers, or delivery drivers on messaging apps. A common variant: someone claims to be from your bank's fraud team and asks you to "verify" a transaction by sharing an OTP.
4. Voice Phishing (Vishing)
Callers impersonate police officers, SingPost, or the Ministry of Health. The infamous "China officials" scam variant tells victims they are involved in money laundering and must transfer funds to a "safe account."
5. QR Code Phishing (Quishing)
Fake QR codes stuck over legitimate ones at hawker centres, bubble tea shops, and even survey flyers redirect users to credential-harvesting pages. A 2023 case in Singapore saw a woman lose S$20,000 after scanning a QR code offering a free drink.
6. Business Email Compromise (BEC)
Targeted at SMEs and finance teams, BEC involves attackers impersonating suppliers or executives to redirect invoice payments. Singapore MAS and the Police have flagged BEC as one of the fastest-growing threats to local businesses.
Red Flags: How to Recognise a Phishing Attempt
Most phishing attempts share tell-tale signs. Train yourself to pause and check for the following before clicking, replying, or paying.
| Red Flag | Example | What to Do |
|---|---|---|
| Urgency or threats | "Your account will be suspended in 24 hours" | Ignore and verify via official app |
| Suspicious sender domain | support@dbs-sg-alert.com | Check the exact domain, not the display name |
| Requests for OTP or password | "Please share the SMS code to verify" | Never share OTPs with anyone |
| Unusual payment methods | Requests for gift cards, crypto, or PayNow to unknown numbers | Refuse and report |
| Grammatical errors | Awkward phrasing, missing articles | Treat as suspicious |
| Mismatched URLs | Link text says dbs.com.sg but points elsewhere | Hover to preview before clicking |
Verifying Links Safely
Shortened links are a common phishing tool because they hide the true destination. Before clicking, expand any shortened URL using a link preview service. Reputable shorteners such as Lunyb provide transparent, scannable links and click analytics that legitimate businesses can share confidently — but that also means users should always preview unknown short links first. For a broader look at reputable shorteners, see our 2026 URL shortener buyer's guide.
How to Avoid Phishing Attacks: A Step-by-Step Framework
- Pause before acting. Scammers rely on panic. Take 30 seconds before responding to any urgent message.
- Verify through official channels. Log in to your bank's app directly rather than clicking any link. Call the number printed on your bank card, not the one in the message.
- Enable Money Lock and transaction alerts. All major Singapore banks now offer "Money Lock" features to ring-fence funds from digital access.
- Use two-factor authentication (2FA). Prefer app-based authenticators or hardware tokens over SMS OTPs where possible.
- Keep devices patched. Enable automatic updates for iOS, Android, and browsers.
- Install anti-scam apps. The ScamShield app, developed by the Singapore Police Force and Open Government Products, blocks known scam calls and SMS.
- Never share OTPs, SingPass, or MyInfo credentials. No legitimate agency will ever ask for them.
- Use unique passwords. A password manager helps you avoid reusing credentials that could be exposed in breaches.
Protecting Businesses in Singapore from Phishing
Phishing is not just a consumer problem. Under Singapore's Personal Data Protection Act (PDPA) and MAS Technology Risk Management Guidelines, organisations have legal and regulatory obligations to protect customer data — and phishing is a leading cause of breaches.
Technical Controls
- Email authentication: Implement SPF, DKIM, and DMARC with a reject policy for your domain.
- Advanced email filtering: Use tools like Microsoft Defender for Office 365, Google Workspace Advanced Protection, or Proofpoint.
- Endpoint protection: Deploy EDR solutions to catch malware delivered through phishing.
- Encrypted DNS and web filtering: Block known phishing domains at the network layer.
- Phishing-resistant MFA: Move toward FIDO2/passkeys for privileged accounts.
Human Controls
- Quarterly phishing simulation exercises tailored to Singapore-specific lures (IRAS, CPF, SingPost).
- Clear internal reporting channels — a one-click "Report Phish" button in email clients works well.
- Segregation of duties for payments, with dual approval for any change in supplier bank details.
Vendor and Link Hygiene
Businesses that send marketing links to customers should use consistent, branded domains so recipients learn to trust them. Trusted shortening providers help maintain that consistency; you can compare options in our Rebrandly review and Lunyb honest review to see how link branding reduces the risk of customers mistaking your emails for phishing.
What to Do If You Fall Victim
If you suspect you've clicked a phishing link or shared information, act immediately. Speed is critical because Singapore banks can sometimes freeze fraudulent transfers within minutes.
- Contact your bank's 24/7 fraud hotline and activate a "kill switch" if available (DBS, OCBC, UOB, Standard Chartered, Citibank all offer this).
- Change compromised passwords from a clean, trusted device.
- Enable Money Lock on remaining funds to prevent further access.
- Lodge a police report via the Singapore Police Force at eservices.police.gov.sg or in person at any Neighbourhood Police Centre.
- Report the scam to ScamShield (ScamShield app or scamshield.gov.sg).
- Notify your employer if work devices or accounts were involved.
- Monitor your credit with the Credit Bureau Singapore (CBS) for any unauthorised applications.
Official Singapore Resources
- ScamShield Helpline: 1799
- Singapore Police Force: Anti-Scam Centre, 1800-722-6688
- Cyber Security Agency (CSA): csa.gov.sg — SingCERT reports phishing trends and provides advisories.
- GoSafeOnline: Public awareness portal run by CSA with regularly updated phishing case studies.
- Monetary Authority of Singapore (MAS): Financial industry advisories and Shared Responsibility Framework details.
The Future of Phishing in Singapore
Phishing is becoming harder to spot. Generative AI now produces grammatically perfect, culturally accurate lures in Singlish, Mandarin, or Malay. Deepfake voice scams have already been documented locally, with a 2024 case involving a fake video call from a supposed CEO. Attackers are also increasingly abusing legitimate services — Google Forms, Notion pages, and Dropbox share links — to host phishing content that bypasses traditional filters.
Defence must evolve accordingly. Expect wider adoption of passkeys, mandatory device binding for banking apps, and stronger implementation of Singapore's Shared Responsibility Framework, which shifts liability between banks, telcos, and consumers based on how each party handled the scam.
Frequently Asked Questions
What is the most common phishing scam in Singapore?
SMS phishing impersonating banks (particularly DBS, OCBC, and UOB) and government agencies like IRAS or SingPost is the most common. Since 2022, Singapore banks have removed clickable links from SMS, so any SMS with a link claiming to be from your bank is almost certainly a scam.
Will my bank in Singapore reimburse me if I fall for phishing?
It depends. Under MAS's Shared Responsibility Framework, banks and telcos may bear losses if they failed their duties (e.g., not detecting suspicious transfers, delivering scam SMS). However, if you shared your OTP or credentials, you may be considered partly liable. Report the scam within hours to maximise chances of recovery.
How do I check if a link in an SMS or email is safe?
Do not click. Instead, log in to the service directly through its official app or by typing the website into your browser. For shortened links, use a link-preview tool to see the true destination first. Reputable link platforms like Lunyb publish their domain openly so users can verify branded short links.
Is ScamShield effective against phishing in Singapore?
Yes, ScamShield is one of the most effective consumer tools available locally. It blocks known scam calls and filters suspicious SMS on iOS and Android. It won't stop every threat — especially newer WhatsApp or Telegram scams — but combined with 2FA and cautious behaviour, it significantly reduces risk.
What should businesses do first to defend against phishing?
Start with three foundations: enforce DMARC (reject) on your email domain, roll out phishing-resistant MFA (passkeys or hardware tokens) for all staff, and run regular phishing simulations tailored to Singapore-specific lures. Combined, these measures block the majority of common attacks and dramatically reduce blast radius when one does succeed.
Final Thoughts
Phishing attacks in Singapore have grown more sophisticated, more localised, and more damaging. But the defences are equally strong: awareness, verification habits, technical controls like DMARC and passkeys, and national resources like ScamShield and the Anti-Scam Centre. The single most powerful protection remains a simple mindset — pause, verify, then act. If a message creates panic or demands secrecy, that is almost always the phishing red flag itself.
Stay updated with CSA advisories, use trusted platforms for your links and communications, and share this knowledge with older family members and colleagues who are often the most vulnerable. In cybersecurity, community awareness is one of the strongest firewalls we have.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication blocks over 99.9% of automated account attacks, yet most people still rely on passwords alone. Learn what 2FA is, which methods are strongest, and how to enable it on your most important accounts in 2026.
Social Engineering Attacks: A Complete Guide to Recognizing and Preventing Human-Based Cyber Threats
Social engineering attacks exploit human psychology rather than technical vulnerabilities, making them one of the most successful cyber threats today. This complete guide covers the most common attack types, real-world examples, and proven strategies to defend yourself and your organization.
Zero Trust Security Model Explained Simply: A 2026 Guide
Zero Trust is a modern cybersecurity framework built on one simple rule: never trust, always verify. This plain-English guide explains the core principles, how Zero Trust works in practice, and how organizations of any size can start implementing it today.
What Is Identity Theft Protection and Do You Need It? A Complete Guide
Identity theft protection services monitor your personal data and help you recover from fraud, but they can't actually prevent theft. This complete guide explains how these services work, compares top options, and helps you decide whether you really need one.