facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have grown into one of the most damaging forms of cybercrime, costing victims hundreds of millions of dollars each year. From fake DBS SMSes to counterfeit SingPost delivery notifications, scammers are constantly refining their tactics to exploit trust in familiar brands and government agencies. This guide explains how phishing works in the Singapore context, how to recognize it, and the practical steps you can take to stay safe.

What Are Phishing Attacks?

Phishing is a type of social engineering attack where criminals impersonate a trusted entity — a bank, government agency, delivery service, or employer — to trick you into revealing sensitive information such as passwords, OTPs, credit card numbers, or SingPass credentials. In Singapore, phishing is the leading gateway to more serious scams including unauthorized bank transfers, malware installation, and identity theft.

According to the Singapore Police Force's annual scam statistics, phishing-related scams consistently rank among the top five scam types, with losses regularly exceeding S$100 million per year. The Cyber Security Agency of Singapore (CSA) has also flagged phishing as a persistent threat targeting both individuals and small businesses.

Why Singapore Is a Prime Target

Singapore's high digital adoption, widespread use of PayNow, SingPass, and digital banking, and a population comfortable transacting online make it a lucrative environment for phishing operators. Several factors amplify the risk:

  • High smartphone penetration — nearly every adult uses mobile banking and messaging apps.
  • Trusted government digital services — SingPass and IRAS are frequently impersonated because citizens are conditioned to respond quickly to official-looking messages.
  • Cross-border communication — many Singaporeans receive legitimate international SMSes, making it harder to filter spoofed foreign numbers.
  • Fast-moving e-commerce — parcel delivery scams thrive because online shopping is routine.

Common Types of Phishing Attacks in Singapore

1. SMS Phishing (Smishing)

The most prevalent form. Victims receive an SMS pretending to be from DBS, OCBC, UOB, POSB, SingPost, or ICA. The message usually contains urgent language ("Your account will be suspended") and a shortened link leading to a fake login page.

2. Email Phishing

Fake emails claiming to be from IRAS (tax refunds), CPF Board, or e-commerce platforms like Shopee and Lazada. These often contain attachments with malware or links to credential-harvesting sites.

3. WhatsApp and Telegram Phishing

Scammers hijack contact lists or pose as recruiters offering "part-time jobs" that eventually funnel victims into fake investment platforms or job scams that require them to hand over banking details.

4. Voice Phishing (Vishing)

Callers impersonate SPF officers, MOH staff, or bank fraud teams, claiming your identity has been used in a crime. They pressure victims into transferring money or sharing SingPass OTPs.

5. QR Code Phishing (Quishing)

A rising threat in Singapore. Scammers place fake QR stickers over legitimate ones at hawker centres, bubble tea shops, or on survey flyers. Scanning leads to a malicious app download or fake payment page.

Warning Signs of a Phishing Attempt

Learning to spot the red flags is the single most effective defense. Here are the most reliable indicators:

  1. Urgency or fear tactics — "Your account will be locked in 24 hours."
  2. Suspicious sender details — a bank SMS coming from a regular +65 mobile number instead of the official alphanumeric sender ID.
  3. Mismatched or shortened URLs — links that don't match the official domain (e.g., dbs-secure-sg.com instead of dbs.com.sg).
  4. Requests for OTPs, passwords, or SingPass credentials — no legitimate organization will ever ask for these.
  5. Poor grammar or unusual phrasing — although AI-generated phishing has narrowed this gap.
  6. Unexpected attachments — especially .apk, .zip, or .exe files.
  7. Too-good-to-be-true offers — tax refunds, lottery wins, or high-yield investments.

Real Phishing Scenarios Seen in Singapore

Scenario A: The Fake DBS SMS

A victim receives an SMS: "DBS Alert: Unusual login detected. Verify now: hxxps://dbs-verify-sg[.]com." The link leads to a pixel-perfect clone of the DBS login page. After entering credentials and the OTP, the scammer immediately transfers funds via PayNow.

Scenario B: SingPost Parcel Redelivery

An SMS says a parcel cannot be delivered and asks for a S$0.50 redelivery fee. The payment page captures card details, which are later used for unauthorized transactions overseas.

Scenario C: The Malicious Android App

A WhatsApp message advertises discounted seafood or cleaning services. The victim is directed to download an APK outside the Play Store. Once installed, the app captures banking credentials and intercepts SMS OTPs, enabling full account takeover.

How Phishing Uses Shortened URLs

Attackers often disguise malicious destinations behind shortened links because they hide the true domain. This is why link inspection matters more than ever. Reputable link shorteners implement anti-abuse scanning, blocklists, and preview features so that malicious links can be flagged or reviewed before a click. If you use short links in your own business communications — for marketing, receipts, or customer support — pick a provider that takes safety seriously. Platforms like Lunyb offer link previews and abuse monitoring, and our 2026 buyer's guide to URL shorteners compares the safety features of the top options.

Comparison: Legitimate vs. Phishing Messages

FeatureLegitimate MessagePhishing Message
Sender IDAlphanumeric (e.g., "DBS", "SingPost")Random mobile number or spoofed ID
LinksOfficial domain (dbs.com.sg, singpost.com)Lookalike domain, shortened URL, or IP address
ToneInformational, no pressureUrgent, threatening, time-limited
RequestsNever asks for OTP or passwordAsks for credentials, OTP, or card details
GrammarProfessional and consistentOdd phrasing, inconsistent formatting
AttachmentsRarely sent unsolicitedAPK, ZIP, or executable files

How to Protect Yourself: A Step-by-Step Guide

  1. Enable the Singapore SMS Sender ID Registry protections. Since 2023, non-registered SMS sender IDs are labeled "Likely-SCAM" — treat these with maximum suspicion.
  2. Use the bank's official app, not links. If you receive a message about your account, close it and open the app directly.
  3. Turn on the Money Lock feature offered by DBS, OCBC, and UOB to ring-fence savings from digital transfers.
  4. Enable two-factor authentication everywhere, preferably using an authenticator app rather than SMS.
  5. Install ScamShield, the free app by the National Crime Prevention Council and Open Government Products, which blocks known scam calls and SMSes.
  6. Never install APKs from links. Only download apps from the Google Play Store or Apple App Store.
  7. Verify QR codes physically before scanning — check for stickers placed over originals.
  8. Use encrypted DNS or a privacy-focused browser (Brave, Firefox with strict tracking protection) to reduce exposure to malicious domains.
  9. Keep your devices updated. Both iOS and Android release monthly security patches that close phishing-related vulnerabilities.
  10. Educate family members, especially older relatives, who are disproportionately targeted.

What to Do If You've Been Phished

Act within minutes — the window between credential theft and fund transfer is often less than an hour.

  1. Call your bank's 24/7 fraud hotline immediately to freeze accounts and reverse transactions if possible.
  2. Change all affected passwords, starting with email, banking, and SingPass.
  3. Revoke device access from your banking and SingPass apps.
  4. Lodge a police report via the SPF e-Services portal or in person at any Neighbourhood Police Centre.
  5. Report the scam to ScamShield at report.scamshield.gov.sg so the number or URL can be blocklisted for others.
  6. Contact CSA's SingCERT if the incident involves a business or work device.
  7. Monitor your credit via the Credit Bureau Singapore for signs of identity misuse.

Advice for Small Businesses in Singapore

SMEs are increasingly targeted through business email compromise (BEC) — a sophisticated form of phishing where attackers impersonate suppliers or executives to reroute payments.

  • Enforce DMARC, SPF, and DKIM on your email domain to prevent spoofing.
  • Adopt a dual-approval process for any payment above a set threshold.
  • Train staff quarterly using simulated phishing tests.
  • Use hardware security keys (YubiKey, Google Titan) for admin and finance accounts.
  • When sharing links with customers, use a reputable link shortener with abuse detection. Compare options such as Rebrandly and Lunyb to find one with the security posture you need.

The Regulatory Landscape

Singapore has introduced strong measures to combat phishing:

  • Shared Responsibility Framework (SRF) — effective 2024, this outlines when banks and telcos must compensate phishing victims.
  • SMS Sender ID Registry — mandatory registration for organizations sending SMSes.
  • Protection from Scams Bill — allows authorities to restrict transactions for victims under active manipulation.
  • Anti-Scam Command (ASCom) — a centralized SPF unit dedicated to scam response and asset recovery.

These frameworks improve protection but do not replace individual vigilance. Legal recourse is slow, and recovering transferred funds is rare once they leave Singapore's banking system.

Frequently Asked Questions

How common are phishing attacks in Singapore?

Extremely common. Phishing consistently ranks among the top scam types reported to the Singapore Police Force, with tens of thousands of cases annually and hundreds of millions of dollars in losses. Nearly every Singaporean adult has received at least one phishing SMS or email.

Will my bank refund me if I fall for a phishing scam?

Under the Shared Responsibility Framework, banks may bear part of the loss if they failed to meet certain duties (like sending real-time transaction alerts). However, if you willingly entered your OTP or credentials, refunds are not guaranteed. Each case is assessed individually.

Is it safe to click on shortened URLs?

Shortened URLs are not inherently dangerous — many legitimate businesses use them. The risk comes from not knowing the destination. Use link preview features, hover to inspect the expanded URL, and rely on shorteners with active abuse detection. Our 2026 URL shortener comparison reviews safety features across major providers.

What is the fastest way to report a phishing SMS in Singapore?

Forward the SMS to 9-SPF-SPF-1 (97957971) or use the ScamShield app, which reports directly to authorities and helps blocklist the number for others. You can also submit the URL at report.scamshield.gov.sg.

Can antivirus software prevent phishing?

Modern security suites and browser protections (Chrome Safe Browsing, Microsoft Defender SmartScreen) block many known phishing sites, but they cannot catch every new attack. Human vigilance — checking sender IDs, verifying URLs, and refusing to share OTPs — remains the most reliable defense.

Final Thoughts

Phishing attacks in Singapore are not going away — if anything, they are becoming more sophisticated with AI-generated messages, deepfake voice calls, and highly localized lures. The good news is that the fundamentals of defense remain unchanged: slow down, verify independently, and never share credentials or OTPs. Combine personal vigilance with practical tools like ScamShield, Money Lock, two-factor authentication, and safer link-handling practices, and you dramatically reduce your risk. Share this guide with family and colleagues — awareness is the most effective anti-phishing tool Singapore has.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles