facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have grown into one of the most damaging forms of cybercrime, costing residents and businesses hundreds of millions of dollars each year. From fake SingPost delivery notices to counterfeit DBS login pages, scammers are getting smarter, faster, and more localised. This guide explains what phishing is, how to recognise the most common Singapore-specific scams, and the practical steps you can take to protect yourself, your family, and your organisation.

What Is Phishing?

Phishing is a form of social engineering where attackers impersonate a trusted person, brand, or authority to trick you into revealing sensitive information, clicking a malicious link, or authorising a fraudulent transaction. In Singapore, phishing typically arrives via SMS (smishing), email, WhatsApp, Telegram, or fake mobile apps that mimic banks and government services.

According to the Singapore Police Force's annual scam statistics, phishing scams consistently rank in the top three scam categories, with victims losing more than S$100 million annually. The Cyber Security Agency of Singapore (CSA) has repeatedly warned that phishing is now the entry point for larger fraud schemes, including malware-enabled banking scams that can drain accounts within minutes.

Why Singapore Is a Prime Target for Phishing

Singapore's high smartphone penetration, digital banking adoption, and reliance on services like Singpass, PayNow, and government e-services make it a lucrative target. Attackers know that a single successful click can unlock access to bank accounts, CPF savings, or corporate systems.

Key factors that make Singapore attractive to phishers include:

  • Digital-first population: Almost every adult uses online banking and mobile payments.
  • Trust in institutions: Singaporeans generally trust official-looking messages from banks and government agencies.
  • Cross-border syndicates: Many operations run from overseas, making prosecution difficult.
  • Multilingual environment: Scammers craft messages in English, Mandarin, Malay, and Tamil to widen their reach.

The Most Common Phishing Attacks in Singapore

Understanding the local threat landscape is the first line of defence. Below are the phishing categories that dominate the Singapore market in 2026.

1. Bank Impersonation Scams

Fake messages claiming to be from DBS, OCBC, UOB, Standard Chartered, or Citibank alert you to "suspicious activity" and ask you to verify your account through a link. The link leads to a near-perfect clone of the bank's login page that captures your credentials and one-time password (OTP).

2. Government and Singpass Phishing

Scammers impersonate IRAS, MOM, ICA, MOH, or Singpass, often warning about unpaid taxes, work pass issues, or account suspension. Some fake sites even mimic the Singpass login screen to steal digital identity credentials, which can then be used to apply for loans in the victim's name.

3. Delivery and Logistics Scams

Fake SingPost, Ninja Van, J&T, or DHL notifications claim your parcel is stuck at customs or needs a small delivery fee. The payment page harvests card details and OTPs.

4. E-commerce and Marketplace Scams

Buyers on Carousell, Shopee, or Lazada receive links to "verify payment" or "release funds" that lead to phishing pages harvesting PayNow or bank credentials.

5. Job Offer and Investment Scams

Unsolicited WhatsApp or Telegram messages offer high-paying part-time work or crypto investment opportunities. Victims are directed to fake platforms where they "deposit" funds that vanish.

6. Malicious APK Scams

Increasingly common in Singapore, victims are tricked into installing Android APK files (often disguised as delivery, food, or utility apps). Once installed, the malware reads SMS messages, captures OTPs, and allows attackers to take over banking apps remotely.

Phishing Red Flags: How to Recognise an Attack

Most phishing attempts share tell-tale signs. Train yourself and your team to pause whenever you notice any of the following:

  1. Urgency and threats: "Your account will be suspended in 24 hours."
  2. Unusual sender addresses: Look for misspellings like "dbs-sg-secure.com" or "singpass-verify.net".
  3. Shortened or mismatched links: Hover over links to check the real destination before clicking.
  4. Requests for OTPs, PINs, or Singpass credentials: No legitimate bank or agency will ever ask for these.
  5. Poor grammar or awkward phrasing in what should be an official message.
  6. Attachments or APK files you did not expect.
  7. Generic greetings such as "Dear Customer" instead of your name.
  8. Payment requests via PayNow to personal numbers claiming to be a business or agency.

Phishing Channels Compared

Different channels carry different levels of risk. Here is a quick comparison of how phishing typically arrives in Singapore:

ChannelCommon DisguiseRisk LevelKey Defence
SMS (Smishing)Bank alerts, delivery noticesVery HighCheck for SMS Sender ID Registry compliance; never click links
EmailInvoices, tax notices, HR memosHighVerify sender domain; use email filters
WhatsApp / TelegramJob offers, investment tipsHighIgnore unsolicited messages; block and report
Phone callsPolice, MOH, bank officersHighHang up and call the official hotline directly
Fake websites / adsCloned bank or shopping sitesMediumType URLs manually; check for HTTPS and correct domain
Malicious APKsDelivery, food, utility appsCriticalOnly install apps from Google Play or Apple App Store

How to Verify Suspicious Links Safely

Shortened links are a favourite tool of scammers because they hide the real destination. Before you click anything, use these steps to check where a link truly leads:

  1. Hover, don't click: On desktop, hover over the link to preview the destination in the status bar.
  2. Use a link expander: Paste the shortened URL into a link-expansion tool to reveal the final URL.
  3. Check the domain carefully: Confirm it exactly matches the official brand (e.g., dbs.com.sg, not dbs-com-sg.net).
  4. Look for HTTPS and a valid certificate: Though not a guarantee, absence is a strong warning.
  5. Scan with reputable tools: Services like VirusTotal or Google Safe Browsing can flag known malicious URLs.

Legitimate short links from trusted providers can also help you and your organisation build safer sharing habits. Platforms such as Lunyb offer transparent link previews and analytics so recipients can verify destinations before clicking. If you want to compare shortening tools for business use, see our 2026 buyer's guide to the best URL shorteners and our Rebrandly review.

What to Do If You Clicked a Phishing Link

Quick action can dramatically limit the damage. Follow this checklist immediately if you suspect you've been phished:

  1. Disconnect from the internet to stop further data transmission or remote control.
  2. Contact your bank using the official hotline printed on your card. Freeze accounts and cards.
  3. Change passwords for banking, Singpass, email, and any linked accounts, using a different device if possible.
  4. Enable or reset multi-factor authentication on all critical accounts.
  5. Uninstall suspicious apps, especially any APK you sideloaded, and run a full antivirus scan.
  6. Perform a factory reset on your phone if you installed a malicious APK — this is often the only reliable fix.
  7. Report the incident to the Singapore Police Force via the ScamShield app, 1800-722-6688 (Anti-Scam Helpline), or www.police.gov.sg/iwitness.
  8. Alert family and colleagues in case the scammer uses your account to attack them next.

How to Prevent Phishing Attacks: A Practical Checklist

Prevention is far cheaper than recovery. Adopt these habits at home and in the workplace:

  • Enable the Money Lock feature offered by DBS, OCBC, UOB, and other Singapore banks to ring-fence funds that cannot be transferred digitally.
  • Turn on ScamShield on your iPhone or Android device to filter known scam calls and SMS.
  • Use multi-factor authentication (preferably app-based or hardware tokens) on every critical account.
  • Never install APK files from links in SMS, email, or chat apps. Stick to official app stores.
  • Keep devices updated — iOS, Android, browsers, and antivirus software patch known exploits.
  • Use encrypted DNS (such as Cloudflare 1.1.1.1 or Quad9) to block many phishing domains at the network level.
  • Bookmark official portals for banks, Singpass, IRAS, and CPF instead of clicking search results or links.
  • Educate the vulnerable — elderly parents and young family members are frequent targets. Practise spotting fakes together.
  • For businesses: conduct regular phishing simulations, deploy DMARC/SPF/DKIM on your email domains, and train staff quarterly.

Singapore Resources for Reporting and Learning

Singapore has one of the world's most coordinated anti-scam ecosystems. Bookmark these resources:

  • ScamShield app — free from Apple App Store and Google Play.
  • Anti-Scam Helpline: 1800-722-6688.
  • ScamAlert.sg — official portal by the National Crime Prevention Council with the latest scam alerts.
  • SingCERT — CSA's incident response team for cybersecurity issues at www.csa.gov.sg/singcert.
  • Police iWitness portal for online reporting of scams and cybercrime.

The Future of Phishing in Singapore

Phishing tactics are evolving fast. In 2026 and beyond, expect to see:

  • AI-generated messages with perfect grammar in all four official languages, making red flags harder to spot.
  • Deepfake voice calls impersonating bank officers, family members, or executives (CEO fraud).
  • QR code phishing (quishing) placed on hawker centre tables, parking meters, and posters.
  • Browser-in-the-browser attacks that render a fake Singpass or bank login popup indistinguishable from the real one.
  • More targeted attacks on SMEs that lack dedicated IT security teams.

Staying safe means combining technology (encrypted DNS, MFA, up-to-date devices), habits (verify, don't trust), and awareness (know the current scam trends). The moment you feel rushed or emotional about a message, that's your cue to slow down and verify through an official channel.

Frequently Asked Questions

How do I report a phishing SMS or email in Singapore?

Forward suspicious SMS to 7726 (SPAM) via your telco, report the incident through the ScamShield app, or file a report on www.police.gov.sg/iwitness. For work-related phishing, notify SingCERT at singcert@csa.gov.sg.

Will my bank refund money lost to phishing in Singapore?

Under the Shared Responsibility Framework that took effect in December 2024, banks and telcos may bear part of the loss if they failed in their duties (e.g., not blocking a scam SMS). However, customers who share OTPs or install malicious apps often remain partly liable. Report the incident immediately — the faster you act, the higher the chance of recovering funds through the Anti-Scam Centre.

Is it safe to click short links I receive in Singapore?

Short links are not inherently dangerous, but they hide the destination. Only click short links from senders you trust, and use link-expansion tools or a shortener that provides preview pages to see the real URL first. Business owners should use reputable shortening platforms that offer analytics, custom domains, and safety scanning.

What is the difference between phishing and smishing?

Phishing is the umbrella term for social engineering attacks that trick you into revealing information. Smishing specifically refers to phishing carried out via SMS. In Singapore, smishing is currently the most common variant because SMS still feels trustworthy to many users, especially older residents.

Can antivirus software alone protect me from phishing?

No. Antivirus is one layer, but phishing exploits human trust rather than software flaws. You need a combination of technical controls (MFA, encrypted DNS, updated devices, reputable browsers), behavioural habits (verify senders, never share OTPs), and awareness of current scam trends in Singapore. Treat every unexpected message asking for action as suspicious until proven otherwise.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles