facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··10 min read

Phishing attacks in Singapore have become increasingly sophisticated, targeting everyone from retirees using PayNow to executives at multinational corporations in the CBD. According to the Singapore Police Force and the Cyber Security Agency of Singapore (CSA), scam-related losses continue to break records year after year, with phishing consistently ranking among the top attack vectors. This guide explains how these scams work locally, how to recognize them, and what to do if you have already clicked.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate trusted organizations — banks, government agencies, delivery companies, or employers — to trick you into revealing sensitive information such as passwords, One-Time Passwords (OTPs), Singpass credentials, or credit card details. In Singapore, phishing typically arrives via SMS, WhatsApp, email, or fake websites that closely mimic DBS, OCBC, UOB, IRAS, SingPost, or Singpass login pages.

The end goal is almost always financial: unauthorized PayNow transfers, credit card fraud, or takeover of your Singpass account to commit identity theft. Because Singapore is highly digital — with near-universal smartphone use and cashless payments — the attack surface is unusually large.

The Phishing Landscape in Singapore: 2024–2026

Singapore's phishing threat has evolved significantly. What used to be poorly-worded emails from "Nigerian princes" has been replaced by pixel-perfect replicas of MyInfo login pages and AI-generated voice calls that sound like your bank's relationship manager.

Key Trends

  • Malicious Android APK scams: Victims are lured into installing fake apps (often disguised as food delivery, cleaning services, or e-commerce apps advertised on Facebook) that then steal banking credentials.
  • Job scams on WhatsApp and Telegram: Fake "part-time job" offers referencing well-known brands like Shopee, Lazada, or Grab.
  • Government impersonation: Fake SMSes claiming to be from IRAS (tax refunds), ICA (passport expiry), MOM (work pass issues), or Singapore Police Force.
  • Bank SMS spoofing: Despite the SMS Sender ID Registry (SSIR), scammers still bypass protections using unregistered IDs or overseas numbers.
  • AI-powered voice phishing (vishing): Cloned voices of family members claiming to be in trouble abroad.

Common Types of Phishing Attacks in Singapore

1. SMS Phishing (Smishing)

You receive a text claiming your DBS account has been locked, your PayNow limit needs verification, or your parcel from SingPost is stuck at customs. A shortened link redirects to a fake login page that captures your credentials and OTP in real time.

2. Email Phishing

Emails supposedly from IRAS about a tax rebate, from your "IT department" asking you to reset your Microsoft 365 password, or from CPF Board about contribution issues. These often include convincing logos, Singapore-specific language, and even correct addressing.

3. WhatsApp and Telegram Phishing

Attackers hijack WhatsApp accounts by tricking users into sharing their WhatsApp verification code, then message the victim's contacts pretending to be them and asking for urgent PayNow transfers.

4. Singpass Phishing

Fake Singpass login pages harvest credentials, giving attackers access to MyInfo, HDB records, CPF, and IRAS. This is arguably the most dangerous form of phishing in Singapore because Singpass is the master key to your digital identity.

5. QR Code Phishing (Quishing)

Malicious QR codes stuck over legitimate ones at hawker centres, on parking meters, or on fake bubble tea shop feedback flyers redirect to phishing sites.

6. Voice Phishing (Vishing)

Callers claim to be from a bank's fraud department, the Singapore Police Force, or Interpol, warning you that your identity is being used for money laundering. They pressure you to transfer funds to a "safe account."

How to Recognize a Phishing Attempt

Phishing messages share common patterns. If you learn to spot them, you dramatically reduce your risk.

Red Flags Checklist

  1. Urgency and fear: "Your account will be suspended in 24 hours." Legitimate Singaporean institutions rarely threaten immediate suspension via SMS.
  2. Unfamiliar links: Hover over or long-press the link. Real DBS links end with dbs.com.sg, not dbs-secure-login.xyz or dbs.com.sg.verify-account.co.
  3. Requests for OTP, password, or Singpass details: No bank, government agency, or legitimate company will ever ask for these.
  4. Unexpected attachments or APK files: Never install Android apps from links sent via SMS or WhatsApp.
  5. Generic greetings: "Dear Customer" instead of your name — although modern attacks often personalize.
  6. Grammar and formatting issues: Odd spacing, missing Singaporean context, or unusual currency symbols.
  7. Sender inconsistency: The SMS Sender ID says "DBS" but the message asks you to call an unfamiliar number.
  8. Too-good-to-be-true offers: "You've won a \$500 NTUC voucher — claim now."

Comparing Legitimate vs. Phishing Messages

FeatureLegitimate MessagePhishing Message
Sender IDRegistered under SSIR (e.g., "DBS", "IRAS")Random number or spoofed ID with "Likely-SCAM" label
Link domainOfficial domain (dbs.com.sg, singpass.gov.sg)Look-alike domain or URL shortener to unknown site
ToneInformational, no pressureUrgent, threatening, or overly rewarding
RequestsDirects you to log in via the official appAsks for OTP, password, or Singpass credentials
AttachmentsRare; usually PDFs from known contactsAPK files, ZIP files, suspicious documents

Real Examples of Phishing Scams in Singapore

Example 1: The Fake IRAS Tax Refund

An email or SMS claims you are eligible for a tax refund of a specific amount and directs you to a Singpass-branded login page. Once you enter your credentials and 2FA code, attackers immediately log in to the real Singpass and change your details.

Example 2: The SingPost Parcel Scam

"Your parcel could not be delivered. Please pay a small redelivery fee." The link leads to a payment page that captures your credit card details. Because the fee is small (often under \$2), victims lower their guard.

Example 3: The Malicious Cleaning App

A Facebook ad promotes cheap home cleaning services. Users are asked to install an APK to book. The app requests accessibility permissions and then silently authorizes bank transfers when the user next logs in to their banking app.

Example 4: The WhatsApp Family Emergency

"Hi Mum, I lost my phone, this is my new number. Can you PayNow \$3,000 urgently, I'll explain later." AI voice cloning is increasingly used to reinforce these scams with follow-up calls.

How to Avoid Phishing Attacks: A Practical Guide

1. Verify Before You Click

When you receive a suspicious message, do not click the link. Instead, open the official app directly (DBS digibank, Singpass, SingPost) and check for notifications there. If nothing appears, the message is almost certainly fake.

2. Use Strong, Unique Passwords with 2FA

Use a password manager (Bitwarden, 1Password) to generate unique passwords for every account. Enable two-factor authentication wherever possible — ideally with an authenticator app or hardware key rather than SMS.

3. Enable the Money Lock Feature

Most major Singapore banks (DBS, OCBC, UOB) now offer a "Money Lock" or similar feature that ring-fences a portion of your savings and makes them inaccessible via digital banking. This is a strong defense against account takeover.

4. Turn On Anti-Malware Protections

The Singapore government's ScamShield app blocks known scam calls and SMSes. Bank apps also include enhanced anti-malware modes that detect sideloaded APKs and block banking access if suspicious apps are found.

5. Be Careful With Shortened Links

Not all shortened links are malicious — reputable services are used every day for legitimate marketing and sharing. The key is knowing who sent it and whether the destination is trustworthy. If you use link shortening for your own business or personal sharing, use a reputable service like Lunyb that provides click analytics and safe redirects, so your recipients can trust your links. You can read our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners.

6. Never Share OTPs or Singpass Credentials

This is the single most important rule. No legitimate bank, telco, government agency, or delivery company will ever ask you for your OTP or Singpass password. Ever.

7. Keep Devices Updated

Install iOS and Android updates promptly. Many phishing-related exploits rely on outdated operating systems or browsers.

8. Use Encrypted DNS and Safer Browsing

Enable secure DNS (such as Cloudflare's 1.1.1.1 for Families or Quad9) on your home router and phone. These services automatically block known malicious domains at the network level, adding a strong layer of protection before you even see a phishing page.

What to Do If You Have Been Phished

If you clicked a link and entered credentials, act within minutes — not hours.

  1. Freeze your bank cards immediately using your banking app's card lock feature.
  2. Call your bank's 24-hour hotline. DBS: 1800-339-6963. OCBC: 1800-363-3333. UOB: 1800-222-2121.
  3. Change your passwords — starting with your email, Singpass, and any banking apps. Do this from a different, trusted device if possible.
  4. Report to the Singapore Police Force via the ScamShield helpline at 1799 or file a report at spf.police.gov.sg.
  5. Reset your Singpass at singpass.gov.sg or a Singpass counter if your credentials may be compromised.
  6. Check MyInfo for any changes to your registered mobile number or email.
  7. Run a malware scan and, if you sideloaded an APK, factory reset your Android phone.
  8. Enable transaction notifications for every bank account so you spot fraudulent activity instantly.

How Singapore Is Fighting Back

The Singapore government has rolled out several initiatives worth understanding:

  • SMS Sender ID Registry (SSIR): Blocks unregistered senders from using organization names.
  • Shared Responsibility Framework (SRF): Banks and telcos share liability for phishing losses under certain conditions.
  • Anti-Scam Command: A dedicated Singapore Police Force unit coordinating with banks to freeze fraudulent accounts within hours.
  • ScamShield app: Free from the App Store and Google Play — filters known scam SMSes and calls.
  • Money Lock: Bank feature to secure a portion of your savings from digital access.

Phishing Protection for Businesses in Singapore

SMEs are increasingly targeted with Business Email Compromise (BEC), where attackers impersonate the CEO or a supplier to authorize fake invoice payments.

Business Best Practices

  1. Deploy DMARC, SPF, and DKIM email authentication for your domain.
  2. Provide phishing awareness training every 6 months.
  3. Simulate phishing campaigns to measure employee readiness.
  4. Enforce multi-person approval for outbound payments above a threshold.
  5. Use branded, trackable links from services like Lunyb so recipients can verify your communications, and see our Rebrandly review for alternatives.
  6. Enable conditional access and MFA on all Microsoft 365 and Google Workspace accounts.

FAQs

How do I report a phishing SMS in Singapore?

Forward the SMS to 9-SPF-SCAM (97723726) or report it through the ScamShield app. You can also report to the Singapore Police Force via the i-Witness portal or by calling the anti-scam hotline at 1799.

Will my bank refund me if I fall for a phishing scam?

Under Singapore's Shared Responsibility Framework, banks and telcos may bear part of the loss if they failed in their duties (such as not blocking a known scam SMS). However, if you willingly shared your OTP or Singpass credentials, refunds are unlikely. Always act within minutes — the faster you report, the higher the chance of recovering funds.

Are shortened links dangerous?

Shortened links themselves are not dangerous — many businesses use them legitimately for marketing and tracking. The danger comes from unsolicited links from unknown senders. Use link preview tools or expand shortened URLs before clicking any that you did not expect, regardless of the shortening service used.

What is the most common phishing scam in Singapore right now?

In recent months, malicious Android APK scams disguised as e-commerce, food, or lifestyle apps advertised on social media have been among the most damaging, with individual victims losing tens or hundreds of thousands of dollars. Bank SMS spoofing and Singpass phishing pages remain persistent threats.

Can iPhone users be phished too?

Yes. While iPhones cannot easily sideload malicious APKs, iOS users are still vulnerable to phishing websites, SMS scams, WhatsApp hijacking, and vishing. Enable Lockdown Mode if you are a high-risk user, and never install unknown configuration profiles.

Final Thoughts

Phishing attacks in Singapore are relentless, but they are also predictable. Nearly every successful scam relies on three ingredients: urgency, trust, and a click. Slow down, verify through official channels, and remember that no legitimate organization will ever ask you for your OTP or Singpass password. Combine that discipline with practical tools — ScamShield, Money Lock, 2FA, and secure DNS — and you will neutralize the vast majority of phishing threats before they reach your wallet.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles