Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore have reached record levels, with the Singapore Police Force reporting more than S$1.1 billion lost to scams in 2024 alone — a significant portion driven by phishing. From fake DBS SMS alerts to spoofed SingPass login pages, attackers are exploiting trust in local institutions to steal money, credentials, and identities. This guide explains how phishing works in the Singapore context, how to recognize the latest tactics, and how to protect yourself, your family, and your business.
What Is a Phishing Attack?
A phishing attack is a form of social engineering where criminals impersonate a trusted entity — such as a bank, government agency, or courier — to trick victims into revealing sensitive information or transferring money. In Singapore, phishing typically arrives via SMS, WhatsApp, email, or fraudulent websites that closely mimic legitimate services like DBS, OCBC, UOB, IRAS, SingPass, or SP Group.
Unlike random spam, phishing is targeted psychologically. It relies on urgency ("Your account will be suspended"), authority ("This is IRAS"), or fear ("Unauthorized transaction detected") to bypass rational thinking and force a quick reaction.
The State of Phishing in Singapore
Singapore is a highly digital society with widespread PayNow, e-government services, and mobile banking adoption. That same digital maturity makes it a lucrative target. According to the Singapore Police Force and the Cyber Security Agency of Singapore (CSA), phishing-related scams — including job scams, e-commerce scams, and government official impersonation scams — consistently rank among the top scam categories.
Common trends observed in 2024–2026 include:
- SMS spoofing pretending to be from banks or MOM, ICA, and IRAS
- Malicious Android APK files disguised as food delivery, cleaning, or pet-grooming apps
- Fake MyInfo and SingPass login portals
- WhatsApp takeovers via fake "verification codes"
- QR code phishing ("quishing") on parking meters, bubble tea stalls, and stickers
Common Types of Phishing Attacks Targeting Singaporeans
1. Smishing (SMS Phishing)
Fraudsters send texts pretending to be from DBS, POSB, OCBC, UOB, or Singpass. Messages often warn of a locked account, unusual login, or unpaid bill and include a shortened link. Since the SMS Sender ID Registry was rolled out, unregistered sender IDs now display as "Likely-SCAM" — a strong warning sign to never ignore.
2. Email Phishing
Emails may impersonate SingPost delivery notifications, IRAS tax refunds, Netflix billing issues, or Microsoft 365 password resets. Look for slight misspellings in the domain (e.g., singp0st.com instead of singpost.com).
3. Voice Phishing (Vishing)
Callers claim to be from the police, MOH, ICA, or a bank fraud team, often using spoofed +65 numbers. They pressure victims into transferring money to a "safe account" or installing remote-access apps like AnyDesk.
4. WhatsApp and Telegram Scams
Attackers hijack accounts by requesting a "6-digit code" they say was sent by mistake. Once inside, they message contacts asking for PayNow transfers or OTPs.
5. QR Code Phishing (Quishing)
Malicious QR stickers are placed over legitimate ones at F&B outlets, EV chargers, or parking machines. Scanning leads to a fake payment gateway.
6. Malicious App Downloads
Victims are directed to sideload an APK outside the Google Play Store. The app requests accessibility permissions, silently reads OTPs, and drains bank accounts. Google Play Protect's Enhanced Protection in Singapore now blocks many of these — but not all.
How to Recognize a Phishing Attempt
Most phishing attempts share a set of tell-tale signals. Learning to spot even one or two is often enough to prevent an incident.
Red Flags Checklist
- Urgency or threats — "Act within 24 hours or your account will be frozen."
- Sender ID marked "Likely-SCAM" or an unknown number claiming to be an official body.
- Suspicious links — hover to preview. Legitimate banks in Singapore never send clickable transactional links via SMS.
- Requests for OTPs, PINs, or SingPass credentials — no legitimate institution will ever ask for these.
- Unusual payment methods — gift cards, crypto, or overseas remittance.
- Grammar and formatting errors, or overly generic greetings like "Dear Customer."
- Domain mismatches — always check the URL carefully before entering credentials.
Real-World Phishing Examples in Singapore
The DBS SMS Scam
Victims receive an SMS claiming their DBS account has been locked. The link leads to a pixel-perfect clone of the DBS ib.dbs.com.sg login page. Once credentials and OTPs are entered, funds are transferred within minutes.
The IRAS Tax Refund Email
An email announces a S$389 tax refund and asks the user to "verify their bank details" via a MyInfo-style login. In reality, IRAS never issues refunds through unsolicited email links — refunds are credited automatically or via GIRO.
The Job Scam via Telegram
A recruiter offers easy work-from-home jobs "reviewing hotels" or "boosting merchant sales." Small commissions build trust, then victims are asked to top up increasingly large amounts to "unlock" earnings.
How to Verify Suspicious Links Safely
Before clicking any link, especially a shortened one, take a moment to inspect it. Trusted URL shorteners provide preview and safety features that help expose the destination. If you use a shortener like Lunyb for your own links, you benefit from click analytics and link management that make it easier for recipients to trust and verify your URLs — the opposite of what phishers rely on.
Steps to Check a Link Before Clicking
- Long-press (mobile) or hover (desktop) to preview the full URL.
- Use a link expander tool to reveal the final destination of shortened URLs.
- Check the domain letter-by-letter — attackers use lookalike characters (rn vs m, 0 vs O).
- Scan the URL with Google Safe Browsing or VirusTotal.
- Type the official website URL directly into your browser instead of clicking.
If you're evaluating link platforms for business use, our 2026 buyer's guide to URL shorteners compares safety features across the top providers.
Comparison: Legitimate vs Phishing Communications
| Signal | Legitimate Message | Phishing Message |
|---|---|---|
| Sender ID | Registered (e.g., "DBS", "SPF", "IRAS") | "Likely-SCAM" or random +65 / overseas number |
| Links | No clickable transactional links in SMS | Shortened or lookalike domains |
| Tone | Neutral, informational | Urgent, threatening, or too good to be true |
| OTP requests | Never asked over the phone or chat | Requested "for verification" |
| Payment channel | Official app, GIRO, or PayNow to registered UEN | Personal PayNow, crypto, gift cards |
| Grammar | Polished, consistent branding | Odd phrasing, mixed fonts, blurred logos |
How to Protect Yourself from Phishing
Personal Security Habits
- Enable the Money Lock feature on DBS, OCBC, UOB, and Standard Chartered to ring-fence savings from digital transfers.
- Turn on ScamShield — the app developed by the National Crime Prevention Council and Open Government Products — to filter scam calls and messages.
- Activate Google Play Protect Enhanced to block sideloaded APKs.
- Use hardware security keys or passkeys for SingPass and email accounts wherever supported.
- Never share OTPs, even with someone claiming to be from your bank.
- Set daily transaction limits to the minimum you actually need.
Device and Network Protection
- Keep iOS and Android updated — most phishing kits exploit outdated systems.
- Use encrypted DNS (such as Cloudflare 1.1.1.1 or Quad9) to block known malicious domains at the network level.
- Install a reputable mobile security app that flags phishing URLs in real time.
- Avoid public Wi-Fi for banking; use your mobile data connection instead.
For Businesses and SMEs
- Implement DMARC, SPF, and DKIM to prevent email spoofing of your domain.
- Train employees quarterly using simulated phishing exercises.
- Enforce multi-factor authentication across Microsoft 365, Google Workspace, and financial platforms.
- Use branded, trackable short links for external communications so customers can distinguish legitimate messages from spoofed ones. Platforms compared in our Rebrandly review and Lunyb's own offering support custom domains that build trust.
- Follow the CSA's Cybersecurity Toolkit for SMEs for a structured baseline.
What to Do If You've Been Phished
Speed matters. Every minute counts once credentials or funds are compromised.
- Freeze your accounts — call your bank's 24/7 anti-scam hotline immediately (DBS: 1800 339 6963, OCBC: 1800 363 3333, UOB: 1800 222 2121).
- Report to the police at the ScamShield Helpline 1799 or file a report at police.gov.sg/iwitness.
- Notify SingPass at 6335 3533 if your SingPass credentials were exposed, and reset your password.
- Change all reused passwords — especially email, which is the recovery point for everything else.
- Scan your device for malicious apps. Factory reset if you installed any APK.
- Report the phishing message to ScamShield via the app or forward SMS to 9008.
Official Singapore Resources
- ScamShield app — filter and report scam messages
- 1799 Anti-Scam Helpline — 24/7 advice
- scamalert.sg — latest scam trends by NCPC
- csa.gov.sg — Cyber Security Agency advisories and SG Cyber Safe programme
- police.gov.sg — I-Witness portal for filing reports online
Frequently Asked Questions
How do I report a phishing SMS in Singapore?
Forward the suspicious SMS to 9008 (the ScamShield reporting number) or report it directly through the ScamShield app. For financial loss, call 1799 or your bank's anti-scam hotline immediately, then file a report at police.gov.sg/iwitness.
Are "Likely-SCAM" SMS always scams?
Not always, but they are extremely high risk. The label appears when the sender uses an alphanumeric Sender ID that isn't registered with the SMS Sender ID Registry (SSIR). Legitimate Singapore organizations register their IDs, so a "Likely-SCAM" tag almost always indicates a spoofing attempt.
Can I get my money back after being phished?
The Shared Responsibility Framework (SRF) that took effect in December 2024 outlines when banks and telcos may bear part of the loss for phishing scams involving registered SMS sender IDs. Recovery is not guaranteed, but reporting within minutes and freezing the account improves the chance of intercepting transfers.
Is it safe to click on shortened URLs?
Shortened URLs are safe when they come from trusted senders and reputable services. The risk lies in not knowing the destination. Preview the link, use link-expander tools, and prefer shorteners that offer safety scanning and analytics — like the ones covered in our 2026 URL shortener guide.
How can businesses in Singapore protect customers from being phished in their name?
Register your Sender ID with SSIR, enforce DMARC/SPF/DKIM on your domain, use consistent branded short links, publish official contact channels prominently, and educate customers that you will never request OTPs or passwords. Regular phishing simulations for staff further reduce internal risk.
Final Thoughts
Phishing in Singapore has evolved from clumsy emails to highly polished, multi-channel operations that exploit trust in local institutions. The good news: nearly every phishing attempt still contains a red flag if you slow down long enough to look. Combine awareness with practical safeguards — Money Lock, ScamShield, passkeys, encrypted DNS, and cautious link handling — and you dramatically lower your risk. Share this guide with family members, especially elderly relatives who are disproportionately targeted, and treat every urgent message as suspicious until proven otherwise.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Is Public WiFi Safe? The Truth in 2026
Public WiFi in 2026 is safer than ever thanks to universal HTTPS and encrypted DNS — but new threats like evil twin hotspots and captive portal scams still target users. Learn the real risks and 10 practical steps to browse airports, cafes, and hotels securely.
Phishing Attacks: How to Recognize and Avoid Them in 2026
Phishing attacks cause more than 80% of security breaches worldwide. This guide breaks down every major phishing type, the red flags to watch for, and a step-by-step checklist to protect your accounts, your team, and your data in 2026.
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication blocks over 99% of account takeover attempts, yet most people still rely only on passwords. Learn what 2FA is, which methods are safest, and how to set it up on your most important accounts in minutes.
End-to-End Encryption Explained: How It Works and Why It Matters
End-to-end encryption keeps your messages private from everyone except you and the person you're talking to — including the platform itself. Learn how E2EE works under the hood, where it protects you, and how to use it effectively in 2026.