facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have surged into one of the most damaging categories of cybercrime, costing victims hundreds of millions of dollars every year. From fake DBS SMS alerts to counterfeit SingPass login pages, scammers are increasingly sophisticated, well-funded, and locally targeted. This guide explains what phishing looks like in the Singapore context, how to recognize the warning signs, and the practical steps you can take today to protect yourself, your family, and your business.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a trusted party — a bank, government agency, courier, or employer — to trick you into revealing sensitive information or transferring money. In Singapore, phishing typically arrives through SMS, WhatsApp, email, phone calls, or fraudulent websites that closely mimic legitimate local brands.

According to the Singapore Police Force and the Cyber Security Agency of Singapore (CSA), phishing-related scams consistently rank among the top scam types reported each year, with losses climbing into the hundreds of millions of Singapore dollars annually. The targets are broad: retirees, students, working professionals, SMEs, and even large enterprises have all fallen victim.

The Phishing Landscape in Singapore

Singapore's high smartphone penetration, cashless payment adoption, and reliance on digital government services make it a lucrative environment for phishing operators. Attackers localise their lures using Singlish phrasing, Singapore-specific brands, and timely hooks such as GST vouchers, CDC vouchers, or MOM work pass renewals.

Common Local Impersonation Targets

  • Banks: DBS, POSB, OCBC, UOB, Standard Chartered, Maybank, and Trust Bank.
  • Government agencies: SingPass, IRAS, MOM, ICA, MOH, and the Singapore Police Force.
  • Logistics and delivery: SingPost, Ninja Van, J&T, Lazada, Shopee, and Qoo10.
  • Telcos and utilities: Singtel, StarHub, M1, and SP Group.
  • Transport and lifestyle: LTA, ERP 2.0, Grab, and ComfortDelGro.

Types of Phishing Attacks Targeting Singaporeans

Phishing is not a single technique — it is a family of attacks that share the same goal: trick you into acting against your own interests. Here are the variants most commonly seen in Singapore.

1. SMS Phishing (Smishing)

Fake SMS messages claiming your bank card is blocked, your parcel is undeliverable, or your SingPass is suspended. These messages often contain a shortened or lookalike link leading to a cloned login page.

2. Email Phishing

Emails impersonating IRAS tax refunds, Microsoft 365 password expirations, or vendor invoices. Business Email Compromise (BEC) is especially damaging for SMEs, where attackers hijack email threads and reroute payments.

3. Voice Phishing (Vishing)

Callers pretending to be police officers, bank staff, or China officials accusing you of money laundering. Victims are pressured to transfer funds to a "safety account" or install remote-access apps.

4. WhatsApp and Telegram Phishing

Fake job offers, investment groups, and "friend needs help" messages after account takeovers. Malicious QR codes shared in group chats can also redirect to phishing sites.

5. QR Code Phishing (Quishing)

Stickers placed over legitimate QR codes at hawker centres, bubble tea shops, or parking meters route victims to fake payment portals. Always verify the merchant name before completing any transaction.

6. Malicious Android APKs

A Singapore-specific threat: victims are told to install an APK file outside the Play Store to "track a parcel" or "claim a refund." These apps often contain accessibility-abuse malware that drains bank accounts.

How to Recognize a Phishing Attempt

Every phishing message shares a handful of tell-tale signals. Learning to spot them takes only a few minutes and can save you tens of thousands of dollars.

Red Flags Checklist

  1. Urgency and fear: "Your account will be closed in 24 hours."
  2. Unusual sender: Emails from gmail.com claiming to be from a bank, or SMS from unknown +65 or overseas numbers.
  3. Suspicious links: URLs that misspell brand names (dbs-secure-sg.com, singpass-login.net).
  4. Requests for OTPs, passwords, or SingPass details: No legitimate agency will ask for these.
  5. Attachments you did not expect: Especially .apk, .zip, .html, or macro-enabled Office files.
  6. Payment redirection: A vendor suddenly changes bank account details mid-conversation.
  7. Too-good-to-be-true offers: Guaranteed investment returns, free iPhones, or unexpected refunds.

Phishing Attack Types Compared

Attack Type Primary Channel Typical Lure Risk Level
SmishingSMSBank alerts, parcel deliveryHigh
Email PhishingEmailInvoices, tax refunds, IT resetsHigh
VishingPhone callPolice / bank impersonationVery High
QuishingQR codePayment portals, parkingMedium
APK MalwareChat / SMS linkFake apps for refundsVery High
BECEmailVendor payment changeVery High (SMEs)

How to Avoid Phishing Attacks: A Practical Playbook

Prevention is a mix of habits, tools, and verification steps. Follow this playbook consistently and you will neutralise the vast majority of phishing attempts targeting Singapore users.

1. Verify Before You Click

Never click links in unsolicited SMS or email. Instead, open the official app (DBS digibank, Singpass, SingPost) directly, or type the URL manually. When in doubt, call the organisation using the number printed on the back of your bank card or on the official government website — not the number provided in the message.

2. Inspect URLs Carefully

Look for exact domain matches. Legitimate DBS uses dbs.com.sg; anything else is suspect. Watch out for homoglyph attacks that swap letters (0 for O, rn for m). If a link uses a URL shortener, expand it first with a link preview tool. Reputable shorteners such as Lunyb offer link previews and analytics that help you verify destinations, whereas anonymous or unknown shorteners should be treated with caution.

3. Enable Strong Authentication

  • Turn on Singpass Face Verification and biometric login.
  • Enable Money Lock on your bank account to ring-fence savings from digital transfers.
  • Use hardware security keys (YubiKey, Google Titan) for email and cloud accounts.
  • Never share OTPs — banks and government agencies will never request them over the phone.

4. Use the ScamShield App

ScamShield, developed by the Singapore Police Force and the National Crime Prevention Council, blocks known scam calls and SMS, and lets you report suspicious messages with one tap. Install it on every family member's phone, especially elderly parents.

5. Keep Devices and Apps Updated

Patch iOS, Android, and desktop operating systems as soon as updates are released. Only install apps from the App Store or Google Play — never sideload APKs, no matter how convincing the story.

6. Harden Your Network

Enable encrypted DNS (DNS-over-HTTPS) in your browser or router to block known phishing domains at the network level. Consider a private browser such as Brave or Firefox with strict tracking protection. Home routers from Singtel, StarHub, and M1 increasingly offer built-in security filters — turn them on.

7. Train Your Team (For Businesses)

SMEs are disproportionately hit by Business Email Compromise. Run quarterly phishing simulations, enforce dual approval on outgoing payments above a set threshold, and require phone confirmation for any change in vendor bank details.

What to Do If You Fall Victim

Speed matters. Every minute after a phishing incident increases the chance that stolen funds are moved beyond recovery.

  1. Freeze your accounts immediately. Call your bank's 24/7 fraud hotline (DBS: 1800-339-6963, OCBC: 1800-363-3333, UOB: 1800-222-2121).
  2. Activate the kill switch in your banking app if available.
  3. Change your Singpass password and revoke authorised third-party apps.
  4. Change email and social media passwords, prioritising accounts that share the compromised password.
  5. Report the scam to the Singapore Police Force at 1800-255-0000, file a report at police.gov.sg/iwitness, and submit details to ScamShield.
  6. Wipe and factory-reset your phone if you installed a suspicious APK.
  7. Notify contacts if your account was used to send phishing messages onward.

Phishing Trends to Watch in 2026

Scam tactics evolve rapidly. Several trends are shaping the Singapore threat landscape in 2026:

  • AI-generated voice cloning: Scammers use short voice samples from social media to impersonate loved ones asking for emergency transfers.
  • Deepfake video calls: Fraudsters pose as CEOs or CFOs on Zoom to authorise fake invoices.
  • Full-screen browser overlays: Malicious sites imitate the entire Singpass or bank login flow, including a fake browser address bar.
  • Multi-channel scams: An SMS is followed by a WhatsApp call, then an email — building false credibility.
  • Investment scams on Telegram and TikTok: Fake analysts promising crypto or SGX returns.

Tools and Resources for Singaporeans

  • ScamShield app — call and SMS filtering, scam reporting.
  • Anti-Scam Centre hotline — 1800-722-6688.
  • CSA SingCERT — advisories and phishing takedown requests.
  • Money Lock — offered by all major Singapore retail banks.
  • Link preview tools — use a trusted shortener like Lunyb that shows the final destination before clicking. For a broader comparison of link management platforms, see our 2026 URL shortener buyer's guide and Rebrandly review.

Building a Phishing-Resistant Household

Cyber hygiene works best when practised as a family. Sit down with elderly parents and children to walk through common scam scripts. Agree on a family safe word to verify emergency requests over voice or video. Set up joint monitoring on shared accounts, and keep an open line of communication so anyone who receives a suspicious message feels comfortable asking before acting.

Frequently Asked Questions

How common are phishing attacks in Singapore?

Extremely common. Phishing-related scams consistently rank among the top three scam types reported to the Singapore Police Force each year, with collective losses running into hundreds of millions of Singapore dollars. Nearly every mobile user in Singapore has received at least one phishing SMS or call.

Will my bank refund me if I fall for a phishing scam?

Under the Shared Responsibility Framework (SRF) introduced by MAS and IMDA, banks and telcos may bear part of the loss if they fail to meet defined anti-scam duties. However, if you willingly shared OTPs, installed malicious apps, or authorised the transfer, you may bear most of the loss. Reporting quickly gives you the best chance of partial recovery.

How can I check if a link is safe before clicking?

Hover over the link on desktop to preview the URL, use a link expander for shortened URLs, and check the exact domain against the official brand. Reputable link management platforms like Lunyb provide destination previews and click analytics that help verify legitimacy before you commit.

What should I do if I clicked a phishing link but did not enter any details?

Close the browser tab immediately, clear your browser cache, run a mobile or desktop security scan, and monitor your accounts for the next 48 hours. If you were on a work device, notify your IT team. Merely visiting a phishing page is usually low-risk, but drive-by downloads on Android are possible.

Are older adults more vulnerable to phishing in Singapore?

Yes. Seniors are disproportionately targeted by government-impersonation and vishing scams. Help them install ScamShield, enable Money Lock, set daily transfer limits, and agree on a family verification step before any large financial decision. Regular, judgement-free conversations are the single most effective defence.

Final Thoughts

Phishing attacks in Singapore are not going away — they are becoming more localised, more automated, and more emotionally manipulative. The good news is that the fundamentals of defence remain simple: slow down, verify, never share OTPs, and use the protective tools available to you. Combine ScamShield, Money Lock, strong authentication, and healthy scepticism, and you will make yourself a very unattractive target. Share this guide with someone who needs it — a five-minute read today could prevent a life-changing loss tomorrow.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles