Phishing Attacks in Singapore: How to Recognize and Avoid Them in 2026
Phishing attacks in Singapore have surged to record levels, with the Singapore Police Force reporting billions of dollars lost to scams in recent years. From fake DBS SMS alerts to impersonation calls claiming to be from SingPost or IRAS, phishing has become the most common cyber threat facing everyday Singaporeans and local businesses. This guide explains exactly how to recognize phishing attempts, what to do when you spot one, and how to protect yourself and your family.
What Are Phishing Attacks?
Phishing is a type of social engineering attack where criminals impersonate a trusted organization — such as a bank, government agency, or delivery service — to trick you into revealing sensitive information like passwords, OTPs, credit card numbers, or SingPass credentials. In Singapore, phishing often arrives via SMS, WhatsApp, email, or phone calls, and increasingly through fake websites that closely mimic legitimate ones.
The goal is almost always financial: draining your bank account, taking out loans in your name, or gaining access to corporate systems for ransomware attacks. Because Singapore has high digital adoption and a trusting culture around official-looking communications, phishing succeeds here at alarming rates.
The State of Phishing in Singapore
According to the Singapore Cyber Security Agency (CSA) and Singapore Police Force annual scam reports, phishing-related scams consistently rank in the top three cybercrime categories. Key trends include:
- Impersonation of local banks — DBS, OCBC, UOB, and Standard Chartered are the most spoofed brands.
- Government agency scams — Fake messages from IRAS, ICA, MOM, Singapore Police, and CPF Board.
- Parcel delivery phishing — SingPost, Ninja Van, and DHL SMS scams with fake tracking links.
- Job scams — Fake work-from-home offers via WhatsApp and Telegram targeting young Singaporeans.
- SingPass phishing — Fake login pages harvesting SingPass credentials to open bank accounts fraudulently.
The Monetary Authority of Singapore (MAS) has implemented Shared Responsibility Framework rules requiring banks to compensate victims in certain scenarios, but prevention remains the strongest defense.
Common Types of Phishing Attacks in Singapore
1. SMS Phishing (Smishing)
SMS is still the most common phishing channel in Singapore. Typical messages claim your bank account is locked, a parcel needs redelivery, or your SingPass is about to expire. The message contains a shortened or lookalike link that leads to a fake login page.
2. Email Phishing
Emails impersonating IRAS during tax season, LinkedIn recruiters, or Microsoft 365 admins are widespread. Corporate accounts are particularly targeted through business email compromise (BEC), where attackers impersonate the CEO or a supplier to authorize fraudulent invoices.
3. WhatsApp and Telegram Scams
Messaging apps have become a phishing goldmine. Common scripts include fake job offers promising SGD 200–500 daily, romance scams evolving into investment fraud, and impersonation of family members asking for urgent PayNow transfers.
4. Voice Phishing (Vishing)
Automated calls or live callers impersonate the Singapore Police, ICA, or DHL customs officers. Victims are told they are implicated in a crime and must transfer money or share OTPs to "clear their name."
5. QR Code Phishing (Quishing)
Physical QR code stickers placed on top of legitimate ones at hawker centres, on parking meters, or on promotional flyers redirect victims to phishing sites. This has grown rapidly since QR-based payments became standard in Singapore.
How to Recognize a Phishing Attack: 8 Red Flags
- Urgency and threats — "Your account will be suspended in 24 hours" or "Immediate action required."
- Unfamiliar sender numbers — Local banks in Singapore no longer send SMS with clickable links. If you see one, it is a scam.
- Suspicious URLs — Check the domain carefully. "dbs-sg-secure.com" or "singpost-redelivery.net" are not legitimate.
- Requests for OTPs or passwords — No bank, government agency, or legitimate company will ever ask for these.
- Poor grammar or odd phrasing — Although AI has improved scam quality, many phishing messages still contain awkward English or unusual Singlish attempts.
- Unexpected attachments — Especially .zip, .html, or .exe files claiming to be invoices or delivery notices.
- Too-good-to-be-true offers — Free vouchers, tax refunds, or high-paying part-time jobs.
- Requests to install apps outside official stores — Sideloading APKs is a major infection vector for banking trojans in Singapore.
Phishing Examples Common in Singapore
| Scam Type | Typical Message | What They Want |
|---|---|---|
| DBS/POSB SMS | "Unusual activity detected. Verify at dbs-verify.sg-login.com" | iBanking credentials + OTP |
| SingPost Parcel | "Your parcel is held. Pay SGD 1.50 redelivery fee" | Credit card details |
| IRAS Tax Refund | "You are eligible for a SGD 385 refund. Click to claim" | SingPass login + bank info |
| ICA Immigration | "Your passport has an issue. Call this number immediately" | Money transfer via PayNow |
| Job Scam (Telegram) | "Earn SGD 300/day doing simple online tasks" | Deposit to unlock earnings |
| Fake Police Call | "You are involved in money laundering. Prove innocence" | Full bank transfer to "safe account" |
How to Protect Yourself from Phishing in Singapore
Enable ScamShield and SMS Filters
The ScamShield app, developed by the National Crime Prevention Council and Open Government Products, blocks known scam calls and SMS. Every Singapore resident with a smartphone should have it installed. On iPhone, also enable SMS filtering under Settings → Messages → Unknown & Spam.
Use the Money Lock Feature
All major Singapore banks now offer a "Money Lock" feature that segregates funds so they cannot be transferred digitally. Lock any amount you don't need for daily use — this alone has prevented millions in losses since 2023.
Verify Links Before Clicking
Never click SMS or email links directly. Instead, open your banking app manually, or type the official URL. If you receive a shortened link, you can preview it using safe URL expanders before opening. When creating or receiving short links for legitimate business use, choose a trusted provider like Lunyb, which offers link previews and safe redirection features to reduce phishing risk.
Enable Multi-Factor Authentication (MFA)
Use SingPass face verification, Google Authenticator, or hardware keys like YubiKey rather than SMS-based OTPs where possible. SMS OTPs can be intercepted through SIM-swapping attacks.
Keep Devices and Apps Updated
Many phishing campaigns pair credential theft with malware that exploits outdated Android and iOS versions. Enable automatic updates on all devices and never sideload APK files from links sent via WhatsApp or Telegram.
Use Encrypted DNS and Safe Browsing
Enable Google Safe Browsing or Microsoft Defender SmartScreen in your browser. Consider using encrypted DNS services like Cloudflare's 1.1.1.1 for Families or Quad9, which block known phishing domains at the network level — a simple change that protects every device on your home Wi-Fi.
Educate Family Members
Elderly parents and young children are particularly vulnerable. Have regular conversations about scam trends, and set up a family "safe word" for emergency money requests to prevent impersonation scams.
What to Do If You've Been Phished
If you suspect you've fallen victim to a phishing attack in Singapore, act quickly:
- Call your bank immediately — Use the 24/7 anti-scam hotlines: DBS 1800-339-6963, OCBC 1800-363-3333, UOB 1800-222-2121.
- Report to the Police — Call 1800-255-0000 or file a report online at police.gov.sg. For active scams in progress, dial the Anti-Scam Hotline at 1799.
- Reset SingPass — If SingPass credentials were shared, immediately reset your password at singpass.gov.sg and check for any unauthorized transactions.
- Freeze credit reports — Contact Credit Bureau Singapore to place a fraud alert on your file.
- Preserve evidence — Take screenshots of the phishing messages, note phone numbers, and record transaction references.
- Report to ScamShield — Submit the scam details in-app to help protect other users.
- Scan your devices — Run a full malware scan and consider factory-resetting any device that may have installed malicious apps.
Phishing Protection for Businesses in Singapore
SMEs in Singapore are prime targets because they often lack dedicated security teams. Key defenses include:
- Email security gateways — Deploy solutions like Microsoft Defender for Office 365, Proofpoint, or Mimecast with DMARC, SPF, and DKIM properly configured.
- Employee training — Run quarterly phishing simulations. CSA's SG Cyber Safe programme offers free resources for local SMEs.
- Verify financial requests out-of-band — Always confirm invoice changes or wire transfer requests by phone using a previously known number.
- Use branded, trusted short links — When sending marketing links or internal communications, use a reputable shortener with custom domains. Compare options in our 2026 URL shortener buyer's guide and consider dedicated business plans reviewed in our Rebrandly review.
- Report to SingCERT — Businesses affected by phishing should report incidents to the Singapore Computer Emergency Response Team.
The Future of Phishing in Singapore
AI-generated phishing content, deepfake voice calls impersonating family members, and increasingly sophisticated fake apps mimicking Singapore banks are all on the rise. Attackers are also exploiting legitimate services — such as Google Forms, Notion pages, and cloud storage links — to bypass URL filters.
The good news: Singapore's regulatory response is among the strongest in Asia. MAS's Shared Responsibility Framework, the introduction of SMS Sender ID Registry (SSIR), and mandatory kill-switch features on bank apps are all reducing the success rate of common attacks. But criminals adapt fast, and personal vigilance remains the most reliable defense.
Frequently Asked Questions
How do I report a phishing SMS in Singapore?
Forward the phishing SMS to 9-SPAM-9 (97267) or report it through the ScamShield app. You can also file a police report at 1800-255-0000 or online at police.gov.sg. For urgent cases where money has already been transferred, call the Anti-Scam Hotline at 1799 immediately.
Will my bank refund me if I fall for a phishing scam?
Under MAS's Shared Responsibility Framework effective from 2024, banks and telcos must compensate victims if they failed in specific duties (such as not sending real-time transaction alerts). However, if you shared your OTP or SingPass credentials voluntarily, you may bear part or all of the loss. Contact your bank immediately — the sooner you act, the better the chance of recovery.
How can I tell if a URL is safe to click?
Check the exact domain (not just what appears before the first slash), look for HTTPS with a valid certificate, and be wary of lookalike characters (like "rn" instead of "m"). For shortened links, use a link preview service before clicking. Legitimate Singapore banks and government agencies never send SMS with clickable links to log in.
Is ScamShield enough to protect me from phishing?
ScamShield is highly effective at blocking known scam numbers and SMS, but no tool catches everything. Combine it with strong passwords, multi-factor authentication, bank Money Lock features, and awareness training for the best protection. New scam variants appear daily, so healthy skepticism remains essential.
What should elderly family members do to avoid phishing?
Install ScamShield on their phones, enable large-print SMS filtering, set up a family safe word for money-related requests, activate Money Lock on their bank accounts, and encourage them to always call you before responding to any urgent message about money, parcels, or government agencies. Many community centres in Singapore also offer free anti-scam workshops for seniors.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Zero Trust Security Model Explained Simply: A 2026 Guide
Zero Trust flips traditional cybersecurity on its head with one rule: never trust, always verify. This guide breaks down how it works, why it matters, and how to start implementing it—whether you run an enterprise or just want to secure your own digital life.
Phishing Attacks: How to Recognize and Avoid Them in 2026
Phishing attacks are the #1 cause of data breaches in 2026. Learn how to spot the red flags, avoid the most common scams, and respond quickly if you've been targeted.
What Data Does Google Have on You? The Complete 2026 Breakdown
Google quietly collects thousands of data points about your searches, location, voice, purchases, and even your offline movements. This guide breaks down exactly what Google knows about you, where that data lives, and how to reclaim your digital privacy.
How to Know if Your Phone Is Hacked: 10 Warning Signs
Suspect your phone has been compromised? Learn the 10 clearest warning signs your phone is hacked, from battery drain and data spikes to unknown apps and mystery 2FA codes — plus a step-by-step recovery plan for Android and iPhone.