facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··10 min read

Phishing attacks in Singapore have surged dramatically over the past few years, with the Singapore Police Force reporting over S$650 million lost to scams in 2023 alone, a significant portion attributed to phishing. From fake DBS SMS messages to counterfeit SingPass login pages, cybercriminals are constantly refining their tactics to target Singaporean consumers and businesses. This guide will help you recognize the most common phishing techniques used locally, understand the warning signs, and adopt practical strategies to keep your personal data and finances safe.

What Are Phishing Attacks?

Phishing is a form of cybercrime where attackers impersonate trusted organizations, such as banks, government agencies, or delivery services, to trick victims into revealing sensitive information like passwords, credit card numbers, or one-time passwords (OTPs). In Singapore, phishing typically arrives through SMS (smishing), email, WhatsApp messages, phone calls (vishing), or fraudulent websites that mimic legitimate local brands.

The goal is always the same: manipulate the victim into taking action, whether that is clicking a malicious link, downloading a fake app, or transferring money. What makes phishing particularly dangerous in Singapore is how convincingly localized these attacks have become, using proper Singlish phrasing, local logos, and references to real Singaporean institutions like CPF, IRAS, and MOM.

The Current Phishing Landscape in Singapore

Singapore's high digital adoption rate makes it an attractive target for phishing operations. With near-universal smartphone penetration, widespread use of digital banking apps, and everyday reliance on services like SingPass, PayNow, and GrabPay, attackers have many entry points to exploit.

Common Types of Phishing Seen in Singapore

  1. Banking phishing: Fake SMS or emails claiming to be from DBS, OCBC, UOB, or Standard Chartered, urging users to "verify" their accounts.
  2. Government impersonation: Messages pretending to be from IRAS about tax refunds, MOM about work pass issues, or ICA about immigration matters.
  3. Parcel delivery scams: Fake SingPost, Ninja Van, or J&T Express notifications asking for redelivery fees or customs charges.
  4. E-commerce phishing: Counterfeit Shopee, Lazada, or Carousell login pages designed to steal credentials.
  5. Job scams: WhatsApp or Telegram messages offering high-paying part-time roles that require upfront "training fees" or bank details.
  6. Investment scams: Fake trading platforms promising guaranteed returns, often promoted through social media or dating apps.

Why Singapore Is a Prime Target

Several factors contribute to Singapore's vulnerability to phishing. The country's affluence makes potential payouts higher for attackers. Its multicultural, multilingual population means scammers can craft messages in English, Mandarin, Malay, or Tamil to reach specific demographics. Additionally, the trust Singaporeans place in official-looking communications from government bodies and banks can be exploited when scammers replicate these formats convincingly.

How to Recognize a Phishing Attempt

Recognizing phishing requires a healthy dose of skepticism and knowledge of the red flags that most fraudulent messages share. Below are the key signs to watch for.

1. Suspicious Sender Details

Legitimate banks and government agencies in Singapore use official domains and registered SMS sender IDs. Emails from "dbs-security@gmail.com" or "iras.refund@outlook.com" are immediate red flags. Since the introduction of the SMS Sender ID Registry (SSIR) in early 2023, unregistered senders now appear as "Likely-SCAM," but attackers still find ways around this using overseas numbers or spoofed IDs.

2. Urgency and Fear Tactics

Phishing messages almost always create a sense of urgency. Common phrases include:

  • "Your account will be suspended in 24 hours"
  • "Unusual login detected, verify immediately"
  • "Your parcel is being held, pay S$2.30 to release"
  • "Tax refund of S$847 pending, click to claim"

Real institutions rarely demand instant action through a clickable link.

3. Suspicious Links and URLs

Always inspect URLs carefully before clicking. Phishing links often use:

  • Misspelled domains (e.g., "dbs-sg.com" instead of "dbs.com.sg")
  • Extra subdomains (e.g., "singpass.gov.sg.verify-login.xyz")
  • Uncommon top-level domains like .xyz, .top, .click, or .info
  • Shortened URLs from unfamiliar services designed to hide the true destination

When you receive a shortened link, use a reputable service that shows link previews or uses transparent redirect pages. Trustworthy shorteners like Lunyb focus on privacy and safe redirects, but you should still verify unknown links before clicking. For a broader comparison of trustworthy shortening tools, see our 2026 buyer's guide to URL shorteners.

4. Poor Grammar or Odd Phrasing

While phishing quality has improved, many scam messages still contain grammatical errors, awkward capitalization, or inconsistent formatting. A legitimate DBS message will not say "Dear Valued Customer, kindly to update your accounts details immediately."

5. Requests for Sensitive Information

No legitimate Singaporean bank, government agency, or reputable business will ever ask you to share:

  • Your full password
  • Your OTP or SMS verification code
  • Your SingPass credentials
  • Your full NRIC combined with other identifiers
  • Your CVV or full card number via SMS/email

Real Examples of Phishing in Singapore

Case 1: The OCBC Phishing Scam of 2021-2022

One of the most infamous cases involved nearly 800 OCBC customers losing approximately S$13.7 million to a coordinated SMS phishing campaign. Victims received messages appearing to come from OCBC's real SMS thread, claiming account issues. Clicking the link led to a fake login page that captured credentials and OTPs in real time. This case prompted the introduction of stricter banking security measures across Singapore.

Case 2: SingPost Parcel Scams

Fake SingPost SMS messages request small fees (typically S$1-S$3) to "release" a parcel. Victims think the amount is trivial and enter card details, only to have their full card compromised for larger fraudulent transactions later.

Case 3: Fake Job Offers on WhatsApp

Scammers pose as recruiters offering easy remote work reviewing hotels or e-commerce products. After initial small payouts to build trust, victims are asked to deposit larger sums for "premium tasks" and lose everything.

How to Protect Yourself from Phishing Attacks

Comparison: Safe vs. Risky Habits

SituationSafe HabitRisky Habit
Receiving a bank SMS with a linkOpen the bank's official app directlyTap the SMS link
Verifying a suspicious messageCall the bank via the number on your cardCall the number in the message
Logging into SingPassType singpass.gov.sg manuallyClick a link from an email
Sharing OTPsNever share, even with "support staff"Read out OTP over phone
Suspicious linkCheck URL preview or expand shortenerClick blindly

Practical Steps to Stay Safe

  1. Enable two-factor authentication (2FA) on all banking, email, and government accounts, ideally using an authenticator app rather than SMS.
  2. Use the money lock feature offered by DBS, OCBC, and UOB to protect a portion of your funds from digital transactions.
  3. Install the ScamShield app developed by the National Crime Prevention Council to filter known scam calls and SMS.
  4. Keep your devices updated, including operating systems, browsers, and banking apps.
  5. Use encrypted DNS services like Cloudflare 1.1.1.1 or Quad9 to block known phishing domains at the network level.
  6. Bookmark official websites for your bank, SingPass, IRAS, and CPF, and access them only via bookmarks.
  7. Verify unknown links using online scanners like VirusTotal or URLVoid before clicking.
  8. Never sideload apps from links in messages; only install from the official App Store or Google Play.

Business-Level Protection

Companies in Singapore should implement additional safeguards to protect employees and customers:

  • Deploy DMARC, SPF, and DKIM email authentication to prevent domain spoofing.
  • Conduct regular phishing simulation training for staff.
  • Use branded, trusted link shorteners with custom domains to make legitimate marketing links easier for customers to verify. For more on choosing branded shorteners, read our Rebrandly review.
  • Establish a clear incident response plan and reporting channels.
  • Enable endpoint detection and response (EDR) tools on all workstations.

What to Do If You Fall Victim

If you suspect you have been phished, act quickly. Time is critical in limiting damage.

  1. Contact your bank immediately using the hotline printed on your physical card. Request a freeze on your accounts and cards.
  2. Change all passwords, starting with your email (since email is the recovery channel for most other accounts).
  3. Report the incident to the Singapore Police Force via 999 for urgent cases or through the ScamShield helpline at 1799.
  4. File a police report at any Neighbourhood Police Centre or online at police.gov.sg.
  5. Notify SingCERT at csa.gov.sg/singcert if the incident involves a business or significant data compromise.
  6. Monitor your credit report through the Credit Bureau Singapore for any unauthorized activity.
  7. Warn your contacts if scammers may have accessed your address book, as they might target them next.

Singapore's Regulatory Response to Phishing

Singapore has taken several strong steps to combat phishing:

  • SMS Sender ID Registry (SSIR): Mandatory registration for organizations using SMS sender IDs, making it harder for scammers to spoof legitimate brands.
  • Shared Responsibility Framework: Introduced by MAS and IMDA in 2024, this framework distributes liability for phishing losses between banks, telcos, and consumers based on their duties of care.
  • Money lock features: Required across all major retail banks, allowing customers to ring-fence savings from online transactions.
  • Anti-Scam Command: A dedicated police unit that works with banks and payment providers to freeze fraudulent transfers in real time.
  • Cybersecurity Act updates: Strengthened protections for critical information infrastructure and reporting obligations.

Frequently Asked Questions

How do I report a phishing SMS in Singapore?

Forward the suspicious SMS to 9-SPF-SPF-SPF (9773 7773) to report it to the Singapore Police Force. You can also report it through the ScamShield app or call the anti-scam helpline at 1799. If it impersonates a specific bank or agency, notify that organization directly through their official channels.

Are shortened links always dangerous?

No, shortened links are not inherently malicious. Many legitimate businesses use them for tracking and cleaner sharing. However, because they hide the destination URL, they can be misused. Stick to reputable shortening services, use link preview tools, or expand the URL using services like unshorten.it before clicking. Trustworthy providers like Lunyb prioritize transparency and privacy in how links are handled.

Will my bank refund me if I fall victim to phishing?

Under Singapore's Shared Responsibility Framework, banks and telcos may be liable for a portion of losses if they failed in their duties of care (e.g., allowing spoofed SMS to reach customers). However, if you shared your OTP or credentials, you may bear some or all of the loss. Report the incident immediately, as fast action increases the chance of recovering funds before they are transferred out.

How can I tell if a website is a phishing site?

Check the URL carefully for misspellings, unusual domains, or extra characters. Look for HTTPS and a valid certificate, though these alone do not guarantee legitimacy. Real Singapore government sites end in .gov.sg, and major banks use .com.sg. When in doubt, close the page and navigate to the official site directly through a bookmark or by typing the address manually.

What is the most common phishing tactic in Singapore right now?

Currently, SMS phishing impersonating banks and parcel delivery services remains the most prevalent. Job scams on Telegram and WhatsApp, as well as fake investment platforms promoted via social media, are also rising rapidly. Attackers increasingly use AI-generated content to make messages more convincing, so vigilance is more important than ever.

Final Thoughts

Phishing attacks in Singapore will continue to evolve, but so can your defenses. The single most effective protection is skepticism: pause before you click, verify before you act, and never share OTPs or passwords, no matter how legitimate the request appears. Combine this mindset with strong technical safeguards, familiarity with Singapore's official reporting channels, and awareness of current scam trends, and you significantly reduce your risk of becoming a victim.

Stay informed, keep your family and colleagues educated, and report every suspicious message you encounter. Every report helps authorities disrupt scam networks and protect fellow Singaporeans.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles