facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them in 2026

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have surged in both volume and sophistication, costing victims over S$150 million annually according to Singapore Police Force data. From fake DBS SMS messages to counterfeit SingPass logins and cloned government websites, scammers are exploiting every digital touchpoint Singaporeans rely on daily. This guide breaks down how these attacks work, how to recognize them instantly, and how to protect yourself, your family, and your business.

What Is a Phishing Attack?

A phishing attack is a form of social engineering where cybercriminals impersonate trusted organizations—banks, government agencies, delivery companies, or employers—to trick victims into revealing sensitive information such as passwords, OTPs, credit card details, or SingPass credentials. The attack typically arrives through email, SMS (smishing), WhatsApp, phone calls (vishing), or fake websites.

In Singapore, phishing is the second most common scam type, and it often serves as the entry point for larger fraud schemes, including unauthorized bank transfers, identity theft, and business email compromise (BEC).

The State of Phishing in Singapore in 2026

Singapore's high digital adoption rate, near-universal smartphone penetration, and cashless economy make it a prime target for phishing operators, many of whom operate from overseas syndicates. According to the Singapore Cyber Security Agency (CSA) and the Anti-Scam Centre:

  • Phishing scams accounted for more than 22,000 reported cases in the last reporting year.
  • Losses exceeded S$150 million, with the average victim losing between S$3,000 and S$8,000.
  • Bank impersonation, delivery scams (SingPost, Ninja Van), and government impersonation (IRAS, ICA, MOM) are the top three categories.
  • Attackers now use AI-generated voices, deepfake videos on social media, and localized Singlish phrasing to appear more credible.

Common Types of Phishing Attacks Targeting Singaporeans

1. Bank Impersonation Scams

Fake SMS or emails claiming to be from DBS, POSB, OCBC, UOB, or Standard Chartered urge you to "verify" your account, dispute a suspicious transaction, or reactivate a frozen card. The links lead to pixel-perfect replicas of real banking login pages.

2. Government Agency Impersonation

Scammers pose as officers from ICA, IRAS, MOM, MOH, or the Singapore Police Force. Common hooks include unpaid taxes, expired work permits, contact tracing follow-ups, or parcels containing illegal items registered under your NRIC.

3. Delivery and Parcel Scams

Messages claiming a package from SingPost, Ninja Van, or Lazada is "held at customs" and requires a small payment. The payment page harvests card details and often triggers recurring unauthorized charges.

4. SingPass Phishing

One of the most dangerous forms. A compromised SingPass account can be used to open bank accounts, apply for loans, or file fraudulent CPF claims under the victim's identity.

5. Job Scams and Business Email Compromise

Job seekers receive offers requesting SingPass logins or upfront "training fees." Businesses receive spoofed emails from vendors or CEOs requesting urgent wire transfers—BEC losses in Singapore have exceeded S$70 million in a single year.

6. E-commerce and Payment Platform Phishing

Fake Carousell buyers/sellers, counterfeit PayNow QR codes, and cloned Shopee login pages designed to steal credentials or trick sellers into scanning QR codes that authorize withdrawals rather than receive payments.

How to Recognize a Phishing Attempt

Every phishing attack, no matter how sophisticated, contains at least one of these red flags. Learn them, and you'll spot 95% of scams before clicking anything.

Red Flag Checklist

  1. Urgency and threats: "Your account will be closed in 24 hours" or "Immediate legal action."
  2. Requests for OTP, password, or SingPass credentials: No legitimate bank or government agency will ever ask for these.
  3. Suspicious links: Hover over the URL. Real DBS links end in dbs.com.sg, not dbs-sg-secure.com or dbs.verify-login.xyz.
  4. Generic greetings: "Dear Customer" instead of your actual name.
  5. Grammar and spelling errors, or awkward phrasing that mixes formal English with Singlish oddly.
  6. Unexpected attachments (.zip, .exe, .html) or QR codes in emails.
  7. Sender mismatch: Email display name says "DBS Bank" but the actual address is randomstring@gmail.com.
  8. Payment requests via unusual channels: PayNow to a personal number, cryptocurrency, or gift cards.

Phishing Methods Compared

Attack TypeChannelTypical TargetKey Warning Sign
Email phishingEmailEveryone; corporate staffMismatched sender domain, urgent links
SmishingSMS / iMessageBank customers, shoppersShortened or lookalike URLs
VishingPhone callElderly, professionalsCaller claims to be police/ICA/IRAS
WhatsApp/Telegram phishingMessaging appsInvestors, job seekersUnsolicited investment offers, fake HR
QR code phishing (quishing)Physical & digitalF&B customers, payersSticker over original QR, unexpected payment prompt
Spear phishing / BECEmailFinance staff, executivesCEO urgency, changed bank details

Real Examples of Phishing in Singapore

The Fake DBS SMS

A common message reads: "DBS: We detected an unusual login from Johor Bahru. If this wasn't you, verify immediately: dbs-secure-sg.com/verify". The domain is not owned by DBS. Clicking leads to a login page that captures your user ID, PIN, and OTP in real time, allowing the scammer to drain the account within minutes.

The ICA Parcel Scam

A robocall claims a parcel under your NRIC contains contraband. The call is "transferred" to a fake police officer who requests SingPass login for "identity verification" or asks you to transfer funds to a "safety account" for investigation. The Singapore Police Force never operates this way.

The Fake Job Offer

A WhatsApp message from "Grace at Shopee HR" offers S$150–S$500/day for reviewing products. After a few small payouts to build trust, victims are asked to top up thousands to "unlock higher-tier tasks." The money never returns.

How to Avoid Phishing Attacks: 10 Practical Steps

  1. Never click links in unsolicited SMS or email. Instead, open the official app or type the URL manually.
  2. Enable the ScamShield app from the National Crime Prevention Council to auto-filter known scam numbers and SMS.
  3. Turn on Money Lock features offered by DBS, OCBC, and UOB to ring-fence savings from digital transfers.
  4. Use two-factor authentication (2FA) on every important account, preferably via an authenticator app rather than SMS.
  5. Verify unknown links before clicking. Paste them into a URL scanner like VirusTotal or Google Safe Browsing. When you shorten links for your own business, use a reputable shortener such as Lunyb that provides link analytics and protects against malicious redirects—see our honest Lunyb review for details.
  6. Check the sender domain carefully. Legitimate Singapore government emails end in .gov.sg. Banks use their official .com.sg domains.
  7. Never share OTPs, passwords, or SingPass details—no exceptions, ever.
  8. Enable app-based transaction alerts so any charge, no matter how small, triggers a push notification.
  9. Educate elderly family members using real examples. Set up joint alerts on their accounts.
  10. Report suspicious messages to ScamShield or call the Anti-Scam Helpline at 1800-722-6688.

Protecting Your Business from Phishing

Small and medium businesses in Singapore are increasingly targeted through business email compromise. A single successful phishing email can cost tens of thousands of dollars.

Business Protection Checklist

  • Implement SPF, DKIM, and DMARC records on your company domain to prevent email spoofing.
  • Conduct quarterly phishing simulations for staff, especially finance and HR teams.
  • Require dual authorization for any wire transfer above a set threshold.
  • Verify changes to vendor bank details by phone using a known number, never one supplied in the request email.
  • Use branded, trackable short links for customer communications so recipients learn to trust your specific domain. If you're evaluating link management platforms, our 2026 URL shortener buyer's guide and Rebrandly review can help you choose.
  • Keep endpoint protection, browsers, and OS patched. Many phishing kits deliver malware once the link is clicked.

What to Do If You've Been Phished

Speed matters. The first 30 minutes are critical for recovering funds and locking down accounts.

  1. Freeze your bank cards immediately through your banking app or by calling the bank's 24-hour hotline.
  2. Change compromised passwords—starting with the affected account, then any account sharing that password.
  3. Revoke SingPass access at singpass.gov.sg if you suspect credentials were entered on a fake site.
  4. File a police report at spf.gov.sg/e-services or in person; you'll need the report for insurance and dispute claims.
  5. Call the Anti-Scam Helpline (1800-722-6688) to trigger fund tracing across local banks.
  6. Notify your telco if your SIM may have been compromised or if you're receiving suspicious calls.
  7. Scan your device for malware, and consider a factory reset if a malicious APK was installed (a common Android attack vector in Singapore).

Government and Industry Resources

  • ScamShield app — Free anti-scam call and SMS filter for iOS and Android.
  • Anti-Scam Helpline: 1800-722-6688
  • ScamAlert.sg — Latest scam trends and advisory updates.
  • CSA SingCERT — Cybersecurity advisories and phishing reporting for individuals and businesses.
  • MAS Money Lock guidance — Bank-by-bank feature comparison.

FAQ: Phishing Attacks in Singapore

1. How do I report a phishing SMS or email in Singapore?

Forward suspicious SMS to 9-SPF-SCAM (97226726) or report through the ScamShield app. Phishing emails can be reported to CSA SingCERT via csa.gov.sg. If you've lost money, call the Anti-Scam Helpline at 1800-722-6688 and file a police report.

2. Will my bank refund me if I fall for a phishing scam?

Under Singapore's Shared Responsibility Framework (SRF), banks and telcos may bear part of the loss if they failed in their anti-scam duties (e.g., allowing a spoofed SMS through). However, if you willingly entered credentials or OTPs on a fake site, refunds are not guaranteed. Each case is assessed individually, so report immediately to maximize your chances.

3. Are shortened URLs safe to click?

Short links from reputable services are generally safe, but scammers do abuse free shorteners to hide malicious destinations. Best practice: preview the full URL before clicking by adding "+" to a bit.ly link or using an unshortening tool. When creating your own short links, choose a platform with malware scanning and analytics rather than any anonymous free service.

4. How can I protect elderly parents from phishing calls?

Install ScamShield on their phones, enable Money Lock on their savings account, set daily transfer limits to low amounts, and add a trusted contact for large transactions. Have regular conversations about real scam examples—awareness is the single strongest defense. Encourage them to always call you before acting on any "urgent" message.

5. What's the difference between phishing, smishing, and vishing?

All three are social engineering attacks. Phishing typically refers to email-based scams, smishing uses SMS or messaging apps, and vishing uses voice calls (including AI-generated voices). The psychological tactics—urgency, authority, fear—are identical across all three; only the delivery channel changes.

Final Thoughts

Phishing in Singapore isn't slowing down—it's evolving. Attackers now blend AI, deepfakes, localized language, and multi-channel pressure to catch even tech-savvy users off guard. The good news: nearly every attack still relies on the same handful of psychological triggers. If you slow down, verify through official channels, and never share OTPs or credentials, you'll defeat the vast majority of scams targeting Singaporeans today.

Stay skeptical, keep your software updated, use trusted tools for link management and account security, and share what you've learned with the people around you. Every informed user is one less potential victim.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles