Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore have grown into one of the most damaging cybercrime categories, costing victims hundreds of millions of dollars each year. From fake SingPost delivery messages to spoofed DBS and OCBC banking alerts, scammers are targeting Singaporeans across SMS, WhatsApp, email, and social media with increasingly convincing lures. This guide explains how these attacks work, how to recognise them quickly, and what practical steps you can take to stay safe.
What Are Phishing Attacks?
Phishing is a form of social engineering where attackers impersonate a trusted organisation — a bank, government agency, courier, or employer — to trick you into revealing sensitive information or installing malware. In Singapore, phishing typically arrives as an SMS, email, WhatsApp message, or a paid ad linking to a fake login page that harvests your credentials, SingPass details, OTPs, or credit card numbers.
According to the Singapore Police Force and the Cyber Security Agency of Singapore (CSA), phishing-related scams — including job scams, e-commerce scams, and government official impersonation scams — consistently rank among the top cybercrimes reported each year, with losses exceeding S$650 million in recent annual figures.
Why Singapore Is a Prime Target
Singapore's high smartphone penetration, digital banking adoption, and reliance on services like SingPass, PayNow, and e-commerce platforms make it an attractive target for phishing syndicates. Several factors amplify the risk:
- High-value targets: Singaporeans have significant disposable income and widespread access to instant digital payments.
- Trusted institutions: Scammers exploit household-name brands like DBS, POSB, UOB, OCBC, SingPost, IRAS, and MOH.
- Multilingual population: Attackers craft lures in English, Mandarin, Malay, and Tamil to widen their reach.
- Cross-border operations: Many syndicates operate from overseas, making prosecution difficult.
Common Types of Phishing Attacks in Singapore
1. SMS Phishing (Smishing)
Fake SMS messages claim your parcel is stuck at customs, your bank account is suspended, or you have unpaid IRAS taxes. They include a shortened link leading to a spoofed login page. Since the SMS Sender ID Registry was rolled out, unregistered sender IDs now show as "Likely-SCAM", but scammers have shifted to using random mobile numbers or overseas gateways.
2. Email Phishing
Emails impersonating DBS, Singtel, StarHub, Shopee, or Lazada request that you "verify your account" or "claim a refund." These often include convincing logos, footers, and even MAS or SingCERT references to appear legitimate.
3. WhatsApp and Telegram Scams
Job scams and investment scams frequently begin on WhatsApp or Telegram. A friendly "HR recruiter" offers part-time work reviewing hotels or products, then directs you to a phishing site or a fake trading platform that steals deposits.
4. Voice Phishing (Vishing)
Callers pretending to be from the Singapore Police Force, ICA, or MOH claim you're involved in money laundering or a health violation. They pressure victims into transferring funds or handing over SingPass credentials.
5. Malicious Android APK Scams
A newer and highly damaging tactic: victims are convinced to install an APK file outside the Google Play Store — often disguised as a food delivery, cleaning service, or pet grooming app. The malware then intercepts SMS OTPs and drains bank accounts.
6. QR Code Phishing (Quishing)
Fake QR codes are pasted over legitimate ones at bubble tea shops, hawker centres, or on "survey" flyers. Scanning them leads to phishing sites requesting payment or SingPass logins.
Warning Signs of a Phishing Attempt
Most phishing messages share telltale red flags. Look for these before you click:
- Urgency or fear: "Your account will be suspended in 24 hours."
- Unfamiliar sender: Overseas numbers (+63, +60, +84) impersonating local businesses.
- Suspicious URLs: Domains like
dbs-verify-sg.comorsingpost-parcel.topinstead of official.com.sgor.gov.sgaddresses. - Requests for OTPs, passwords, or SingPass: Legitimate agencies never ask for these.
- Poor grammar or odd phrasing — although AI-generated scams are increasingly polished.
- Unexpected attachments — especially .apk, .exe, .zip, or .html files.
- Too-good-to-be-true offers: Guaranteed returns, free iPhones, or high-paying part-time work with no experience needed.
Real Examples of Phishing in Singapore
Bank Impersonation SMS
"DBS-Alert: A new payee has been added to your account. If this wasn't you, verify at hxxps://dbs-sg-secure.com/login." The link opens a pixel-perfect clone of the DBS iBanking page — but any credentials entered go straight to the attacker.
SingPost Parcel Scam
"Your parcel SP8827192SG cannot be delivered due to incomplete address. Update here: hxxps://singpost-redelivery.top." Victims enter card details to pay a small "redelivery fee" of S$1.20 — but the card is later charged thousands.
Government Official Impersonation
A caller claims to be from MOM or ICA and says your work pass has been flagged. They transfer you to a "police officer" who instructs you to install screen-sharing software and log in to your bank to "prove your funds are clean."
How to Protect Yourself: A Step-by-Step Checklist
- Never click links in unsolicited messages. Instead, open the official app or type the URL manually.
- Verify sender IDs. Legitimate SMS from banks and government agencies come from registered sender IDs, not random mobile numbers.
- Enable Money Lock on your DBS, OCBC, UOB, or Standard Chartered accounts to ring-fence savings from digital transfers.
- Turn on Google Play Protect and refuse to sideload APK files from any source outside the Play Store.
- Use strong, unique passwords with a reputable password manager like 1Password or Bitwarden.
- Enable two-factor authentication using an authenticator app (Google Authenticator, Authy) rather than SMS where possible.
- Keep devices updated. Install iOS, Android, and browser security patches promptly.
- Use ScamShield. Install the ScamShield app from the National Crime Prevention Council to block known scam calls and messages.
- Preview shortened links. Use a reputable shortener with link preview and malware scanning — see our 2026 URL shortener comparison for safer options.
- Report suspicious messages to the ScamShield bot on WhatsApp (+65 9151 1119) or forward SMS to 9OR-SCAM (96795226).
How Phishing Techniques Compare
| Attack Type | Primary Channel | Common Lure | Risk Level |
|---|---|---|---|
| Smishing | SMS | Parcel delivery, bank alert | High |
| Email Phishing | Account verification, refund | Medium | |
| Malicious APK | WhatsApp / Web | Fake service app | Very High |
| Vishing | Phone call | Government official | High |
| Quishing | QR code | Fake payment / survey | Medium |
| Job Scam | WhatsApp / Telegram | Part-time review work | High |
Safer Link Sharing and Verification
Because so many phishing attempts hide behind shortened or lookalike URLs, being able to inspect where a link truly goes before clicking is critical. Modern link management platforms such as Lunyb offer link previews, click analytics, and abuse detection, which help both businesses and everyday users avoid dispatching or clicking malicious URLs. If you want a deeper look at how Lunyb handles trust and safety, see our honest review of Lunyb.
For businesses, using a link platform with branded custom domains also reduces phishing risk — customers learn to trust links.yourbrand.sg rather than random shorteners. Compare the leading options in our Rebrandly review to see which suits your team.
What to Do If You've Been Phished
Speed matters. If you suspect you've fallen for a phishing attack:
- Call your bank immediately using the official hotline (DBS: 1800 339 6963, OCBC: 1800 363 3333, UOB: 1800 222 2121). Ask them to freeze your accounts and cards.
- Change all passwords from a clean device, starting with email and banking.
- Revoke SingPass access at singpass.gov.sg if credentials were compromised.
- Uninstall any suspicious apps and consider a factory reset for Android devices infected with malicious APKs.
- File a police report at eservices.police.gov.sg or the nearest Neighbourhood Police Centre.
- Report to ScamShield so the syndicate's numbers and URLs can be blocked for others.
Advice for Businesses in Singapore
Small and medium enterprises are increasingly targeted by business email compromise (BEC) and invoice fraud. Steps to reduce risk:
- Deploy DMARC, SPF, and DKIM on your email domain to prevent spoofing.
- Train staff quarterly with simulated phishing exercises.
- Require dual authorisation for any bank transfer above a defined threshold.
- Verify payment change requests by calling the vendor on a previously known number.
- Use endpoint protection with anti-phishing browser extensions.
- Adopt encrypted DNS resolvers (such as Cloudflare 1.1.1.1 for Families or Quad9) to block known malicious domains at the network level.
The Role of Regulation and Industry Response
Singapore has rolled out several measures to reduce phishing harm:
- Shared Responsibility Framework (SRF) — effective from December 2024, apportioning phishing losses between banks, telcos, and consumers when duties aren't met.
- SMS Sender ID Registry — non-registered organisations are flagged as "Likely-SCAM".
- Anti-Scam Command — a specialised police unit consolidating investigation, intervention, and enforcement.
- Money Lock feature across major local banks.
- Singpass Face Verification to reduce credential-based account takeovers.
FAQ
How common are phishing attacks in Singapore?
Very common. Phishing-related scams consistently account for the majority of reported cybercrime in Singapore, with tens of thousands of cases reported annually and total losses exceeding S$650 million in recent years according to Singapore Police Force statistics.
Will my bank refund me if I'm phished?
Under the Shared Responsibility Framework, banks and telcos may bear part of the loss if they failed to meet defined anti-scam duties. However, if you willingly disclosed OTPs, passwords, or installed malware, you may still bear most of the loss. Report immediately to maximise recovery chances.
How do I check if a link is safe before clicking?
Hover over the link on desktop to reveal the true URL, or long-press on mobile. Use link preview tools, VirusTotal, or Google Safe Browsing. Reputable shorteners like Lunyb include preview and safety-scan features so recipients can inspect destinations before visiting.
Is SingPass ever legitimately requested via SMS or email?
No. The Singapore Government will never ask you to log in to SingPass via a link in an SMS, email, or WhatsApp message. Always access SingPass through the official app or by typing singpass.gov.sg directly into your browser.
What should I do if my elderly parent falls for a phishing scam?
Act quickly: call their bank's 24-hour hotline to freeze accounts, help them change all passwords, install ScamShield on their phone, enable Money Lock, and file a police report. Consider setting up transaction alerts and a lower daily transfer limit for added protection.
Final Thoughts
Phishing attacks in Singapore will continue to evolve as scammers adopt AI-generated voices, deepfake video calls, and more convincing spoofed domains. The best defence is a healthy scepticism toward any unsolicited message asking you to click, log in, or transfer money — combined with strong technical safeguards like two-factor authentication, Money Lock, and safer link verification tools. Stay informed, share this knowledge with vulnerable family members, and always verify before you trust.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
What Data Does Google Have on You? The Complete 2026 Breakdown
Google collects an enormous amount of data about every user — from search queries and location history to voice recordings and ad interest profiles. This complete 2026 guide breaks down exactly what Google knows, where to see it, and how to take back control.
Password Manager vs Browser Passwords: Which Is Safer in 2026?
Browser password stores are convenient but vulnerable to malware and device access. Dedicated password managers offer zero-knowledge encryption, cross-platform sync, and stronger protection. Here's how the two compare — and which one you should actually be using in 2026.
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication blocks over 99% of account takeover attacks, yet millions of users still rely on passwords alone. This comprehensive guide explains how 2FA works, compares every major method from SMS to hardware keys, and shows you exactly how to enable it on the accounts that matter most.
How to Know if Your Phone Is Hacked: 10 Warning Signs
Is your phone acting strange? Learn the 10 clearest warning signs your device has been hacked — from battery drain to SIM-swap attacks — plus a step-by-step recovery plan. Works for both iPhone and Android users worldwide.