facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks have become one of the most persistent cyber threats in Singapore, costing victims tens of millions of dollars each year. From fake SMS messages impersonating DBS and OCBC to sophisticated scams mimicking SingPass and IRAS, cybercriminals are constantly refining their tactics to trick Singaporeans into giving away credentials, OTPs, and money.

This guide explains what phishing looks like in the Singapore context, how to recognize the warning signs, and what practical steps you can take to protect yourself, your family, and your business.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a trusted person, brand, or institution to trick victims into revealing sensitive information or performing actions that compromise their security. In Singapore, phishing typically arrives via SMS (smishing), email, WhatsApp, Telegram, phone calls (vishing), or fake websites.

According to the Singapore Police Force and the Cyber Security Agency (CSA), phishing-related scams remain among the top cybercrime categories, with losses regularly exceeding S$60 million annually. Victims range from elderly citizens targeted through fake bank alerts to business owners tricked by invoice fraud.

Common Phishing Goals in Singapore

  • Stealing bank login credentials and OTPs
  • Hijacking SingPass or Corppass accounts
  • Harvesting credit card details
  • Installing malware or remote-access apps (especially on Android)
  • Redirecting business payments to attacker-controlled accounts

The Most Common Phishing Attacks in Singapore

Understanding the local threat landscape is the first step to defending against it. Here are the phishing scams currently dominating in Singapore.

1. Fake Bank SMS and Emails

Scammers send SMS or emails pretending to be from DBS, POSB, OCBC, UOB, or Standard Chartered, warning of "unauthorized transactions" or "account suspension." The message includes a link to a fake login page that captures your username, password, and SMS OTP in real time.

2. SingPass and Government Impersonation

Phishing pages that mimic SingPass, IRAS, ICA, and MOM are widespread. Common lures include fake tax refunds, ICA immigration issues, or MOH health notifications. Once attackers gain SingPass access, they can open credit lines, apply for loans, or commit identity fraud.

3. Parcel Delivery Scams

Messages claiming to be from SingPost, Ninja Van, or customs authorities ask you to "pay a small fee" or "update delivery details." The linked page harvests card information and often triggers recurring unauthorized charges.

4. Job Scams on WhatsApp and Telegram

Attackers pose as recruiters from real companies, offering easy part-time work. Victims are eventually directed to phishing sites or asked to install malicious apps to "complete tasks."

5. Malicious Android APK Scams

A uniquely dangerous trend in Singapore involves scammers convincing victims to sideload Android apps outside the Play Store. These apps request accessibility permissions and can silently drain bank accounts. Google and local banks have since restricted sideloaded apps from accessing banking apps as a countermeasure.

6. Business Email Compromise (BEC)

SMEs in Singapore are frequent targets. Attackers spoof supplier or CEO email addresses to redirect invoice payments. A single BEC incident can cost a company hundreds of thousands of dollars.

How to Recognize a Phishing Attempt

Phishing messages usually share a common set of red flags. Learning to spot them takes only a few minutes but can save you from significant losses.

Warning Signs in Messages

  1. Urgency and fear: "Your account will be suspended in 24 hours."
  2. Unexpected links: Any link you didn't request, especially shortened or unfamiliar domains.
  3. Requests for OTP or password: No legitimate bank or government agency in Singapore will ever ask for these.
  4. Generic greetings: "Dear Customer" instead of your name.
  5. Slight misspellings: "dbs-secure.com" or "singpass-login.sg" instead of official domains.
  6. Grammatical errors or awkward Singlish that doesn't match official tone.

Warning Signs on Websites

  • The URL doesn't match the official domain (real DBS is dbs.com.sg, not dbs-sg-secure.com).
  • No padlock or an unusual certificate authority.
  • Pop-ups asking for OTP immediately after login.
  • Requests to install an app, enable accessibility, or disable Play Protect.

Legitimate vs. Phishing: A Quick Comparison

FeatureLegitimate MessagePhishing Message
SenderOfficial shortcode or verified domainRandom mobile number or lookalike domain
GreetingUses your registered name"Dear Customer" or "User"
LinksOfficial .com.sg or .gov.sg domainShortened, misspelled, or foreign TLD
RequestsNever asks for OTP or full passwordRequests OTP, PIN, or full card number
ToneNeutral, informativeUrgent, threatening, or too good to be true
AttachmentsRare, and only expected filesUnexpected .apk, .zip, or .exe files

How to Avoid Falling Victim to Phishing

Prevention is far cheaper than recovery. Here are the most effective habits and tools for Singapore users.

1. Verify Before You Click

If you receive a message claiming to be from your bank, don't tap the link. Open the official mobile app or type the URL manually. For SingPass matters, always go directly to singpass.gov.sg.

2. Use the ScamShield App

The ScamShield app, developed by the National Crime Prevention Council and the Singapore Police Force, blocks known scam calls and SMS. It's free and highly recommended for all Singapore residents.

3. Enable the Money Lock Feature

DBS, OCBC, and UOB now offer a "Money Lock" or "Security Lock" feature that ring-fences a portion of your savings from digital transactions. Even if attackers steal your credentials, they cannot move locked funds.

4. Turn On Multi-Factor Authentication Everywhere

Enable MFA on your email, SingPass, banking apps, and social media. Prefer authenticator apps (Google Authenticator, Microsoft Authenticator) or hardware keys over SMS-based codes when possible.

5. Inspect Shortened Links Before Opening

Shortened URLs are convenient but can hide malicious destinations. Reputable link management platforms such as Lunyb allow both creators and recipients to preview the underlying destination and use safety checks before redirecting. If you're evaluating link tools for your own business, our 2026 buyer's guide to URL shorteners compares the safest options.

6. Keep Devices and Browsers Updated

Most phishing kits exploit outdated browsers. Enable automatic updates on iOS, Android, Windows, and macOS. Use browsers with built-in phishing protection such as Chrome, Edge, or Safari with Google Safe Browsing enabled.

7. Never Sideload Android Apps

Only install apps from the Google Play Store or Apple App Store. If someone insists you install an APK to "receive a refund" or "complete a job task," it is almost certainly malware.

8. Educate Family Members

Elderly parents and young children are frequent phishing targets. Walk them through common scams, show them what real bank apps look like, and set up joint account alerts so suspicious transactions are noticed immediately.

What to Do If You've Been Phished

Speed matters. If you suspect you've clicked a phishing link or entered credentials on a fake site, act within minutes.

  1. Call your bank immediately using the anti-scam hotline printed on the back of your card. Every major Singapore bank has a 24/7 fraud line.
  2. Freeze your accounts through the bank app if the feature is available.
  3. Change passwords for the affected account and any account sharing the same password.
  4. Reset your SingPass at singpass.gov.sg if you suspect government credentials were exposed.
  5. Report the scam to the Singapore Police Force at 1800-255-0000 or via police.gov.sg/iwitness.
  6. File a report with ScamShield so the sender number or URL can be added to national blocklists.
  7. Check for malware: If you installed any app, run a mobile security scan and consider a factory reset.

Phishing Protection for Singapore Businesses

SMEs and enterprises face the additional risk of BEC, credential stuffing, and supply-chain phishing. A layered defense is essential.

Technical Controls

  • Deploy DMARC, SPF, and DKIM on all corporate email domains.
  • Use an email security gateway with sandboxing for attachments and links.
  • Enforce phishing-resistant MFA (FIDO2 keys) for admin and finance staff.
  • Segment access so no single account can approve outgoing payments alone.
  • Use branded, trackable short links through platforms like Lunyb so recipients can trust your outbound URLs — see our honest review of Lunyb for a deeper look.

Human Controls

  • Run quarterly phishing simulations and record click rates.
  • Establish a clear "verify by phone" policy for any payment changes.
  • Encourage a no-blame reporting culture so staff flag mistakes early.

Pros and Cons of Common Anti-Phishing Measures

Pros

  • Most tools (ScamShield, Money Lock, MFA) are free.
  • Layered defenses drastically reduce successful attacks.
  • Improved awareness helps the whole family and workplace.
  • Fast reporting can sometimes recover stolen funds.

Cons

  • No solution is 100% effective — social engineering evolves quickly.
  • Some features (like Money Lock) reduce convenience.
  • SMS-based MFA is still vulnerable to SIM swap attacks.
  • Recovering funds sent overseas is often difficult.

Frequently Asked Questions

How do I report a phishing SMS or email in Singapore?

Forward suspicious SMS to 9-SPF-SPF (9773-7773) or report through the ScamShield app. Phishing emails can be reported to the Singapore Cyber Security Agency at csa.gov.sg and to your email provider using the built-in "Report Phishing" option.

Will my bank refund me if I fall for a phishing scam?

Under the Shared Responsibility Framework introduced by MAS and IMDA, banks and telcos may be liable if they fail to meet certain anti-scam duties. However, if you willingly disclosed your OTP or password, recovery is not guaranteed. Report the incident within minutes for the best chance of reversal.

Are shortened links always dangerous?

No. Shortened URLs are widely used by legitimate businesses for tracking, branding, and mobile-friendly sharing. The risk depends on the platform and the sender. Reputable shorteners include malware scanning, click analytics, and preview options. For a comparison of trustworthy providers, see our Rebrandly review for 2026.

Can antivirus software stop phishing?

Modern security suites help by blocking known malicious URLs and scanning downloads, but they cannot stop a user from voluntarily typing credentials into a convincing fake page. Combine antivirus with MFA, ScamShield, and healthy skepticism for the best results.

What should I do if I already gave away my SingPass credentials?

Immediately reset your SingPass password at singpass.gov.sg, enable SingPass Face Verification, and check your CBS credit report and CPF statements for unauthorized activity. Report the incident to the Singapore Police Force and monitor for suspicious loan applications or account openings.

Final Thoughts

Phishing attacks in Singapore are growing more targeted and technically sophisticated, but the fundamentals of defense remain the same: pause before you click, verify through official channels, enable multi-factor authentication, and never share OTPs or passwords. Combine these habits with local tools like ScamShield and bank-provided Money Lock features, and you'll be well ahead of the vast majority of attempted scams.

Stay skeptical, stay updated, and share this knowledge with the people around you — a well-informed community is the strongest firewall Singapore has.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles