facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have surged into one of the most damaging categories of cybercrime, with victims collectively losing hundreds of millions of dollars every year. From fake DBS SMS alerts to bogus SingPost delivery notifications and cloned government portals, scammers are becoming increasingly sophisticated at impersonating trusted local brands. This guide explains how phishing works in the Singapore context, how to recognise the warning signs, and how to protect yourself, your family, and your business.

What Are Phishing Attacks?

Phishing is a form of social engineering where criminals impersonate a legitimate organisation to trick you into revealing sensitive information such as passwords, OTPs, credit card numbers, or Singpass credentials. The attacker's goal is almost always financial: unauthorised bank transfers, stolen identities, or ransomware footholds inside a company network.

In Singapore, phishing typically arrives through four main channels: SMS (smishing), email, phone calls (vishing), and increasingly, messaging apps like WhatsApp and Telegram. According to the Singapore Police Force's annual scam statistics, phishing scams consistently rank among the top three scam types by number of cases reported.

Why Singapore Is a High-Value Target

Singapore's high smartphone penetration, cashless economy, and concentration of wealth make it an attractive target for cybercriminals. Several local factors amplify the risk:

  • PayNow and instant transfers: Money can be moved and laundered within minutes.
  • Trust in institutions: Singaporeans generally trust official-looking messages from banks, IRAS, ICA, and MOM.
  • Multilingual population: Attackers craft messages in English, Mandarin, Malay, and Tamil to widen their reach.
  • Cross-border syndicates: Many phishing operations are run from overseas, making enforcement difficult.

The Most Common Phishing Attacks in Singapore

Understanding the most prevalent scam patterns is the first step toward avoiding them. Here are the phishing attacks Singaporeans encounter most often in 2026.

1. Fake Bank SMS and Emails

Impersonating DBS, OCBC, UOB, Standard Chartered, and Citibank, these messages typically warn of "suspicious activity," "locked accounts," or "unauthorised transactions." Victims are directed to a lookalike login page where they enter their credentials and OTP, which are captured in real time by the scammer.

2. Delivery and Parcel Scams

Messages claiming to be from SingPost, Ninja Van, or courier services like DHL and FedEx notify recipients about a "failed delivery" or unpaid customs fee. The link leads to a payment page that harvests card details.

3. Singpass and Government Impersonation Scams

Scammers impersonate IRAS (tax refunds), ICA (passport renewals), MOM (work pass issues), or the Ministry of Health. They lure victims into logging in through a fake Singpass page, giving attackers full access to government services and CPF.

4. E-Commerce and Marketplace Phishing

On Carousell, Facebook Marketplace, and Shopee, fake buyers or sellers send phishing links disguised as payment confirmations, delivery arrangements, or verification requests.

5. Job Scam Phishing

Fake recruiters on LinkedIn, WhatsApp, or Telegram offer high-paying part-time jobs. "Onboarding" requires you to log into a fake portal or transfer money as a "training deposit."

6. Business Email Compromise (BEC)

Targeting SMEs and MNCs, attackers spoof a CEO or supplier's email to authorise fraudulent wire transfers. Singapore consistently ranks among the top APAC destinations for BEC losses.

How to Recognise a Phishing Attempt

Phishing messages share telltale patterns. Once you learn them, spotting a scam becomes second nature.

Red Flags in the Message

  1. Urgency and threats: "Your account will be suspended in 24 hours."
  2. Generic greetings: "Dear Customer" instead of your name.
  3. Unusual sender addresses: Look at the full email domain, not just the display name.
  4. Grammar and formatting errors: Odd spacing, mismatched fonts, or awkward phrasing.
  5. Requests for OTP, password, or Singpass credentials: No legitimate bank or government agency will ever ask for these.
  6. Shortened or unfamiliar links: Hover over links before clicking to inspect the actual destination.

Red Flags in the URL

Attackers often register domains that look almost identical to real ones. Watch for:

  • Extra characters: dbs-secure-login.com instead of dbs.com.sg
  • Wrong top-level domain: .net, .xyz, or .info instead of .com.sg or .gov.sg
  • Hyphens and subdomains: singpass.login-portal.co
  • Homoglyphs: using "rn" to mimic "m" or "0" instead of "o"

Government sites in Singapore end in .gov.sg. If a URL claiming to be from Singpass, IRAS, or ICA doesn't end that way, it is almost certainly fake.

Phishing Channels Compared

ChannelCommon ImpersonationTypical PayloadDifficulty to Detect
SMS (Smishing)Banks, SingPost, IRASLink to fake login pageMedium
EmailCorporate suppliers, Microsoft 365Malicious attachment or linkMedium to High
Phone (Vishing)Police, MAS, banksVerbal instructions to transfer moneyHigh
WhatsApp / TelegramJob recruiters, friends, sellersInvestment scams, phishing linksHigh
QR Codes (Quishing)F&B outlets, hawker stalls, surveysSticker over legitimate QRVery High

How to Avoid Falling Victim

Prevention combines behaviour, tools, and verification habits. Adopt these practices consistently.

Verify Through Official Channels

If you receive a message from your bank, do not click the link. Open the official banking app directly, or call the number printed on the back of your card. For government agencies, go to the official website by typing the address yourself.

Enable the SMS Sender ID Registry

Since 2023, IMDA's Full SMS Sender ID Registry has significantly reduced spoofed SMS messages. Legitimate organisations register their alphanumeric sender IDs. Any SMS claiming to be from a bank but arriving from an unknown mobile number should be treated as suspicious.

Use the ScamShield App

Developed by the Singapore Police Force and the National Crime Prevention Council, ScamShield filters known scam SMS and blocks scam calls. It also lets you check suspicious messages against a live database.

Turn on Money Locks and Kill Switches

Most Singapore banks now offer a "money lock" feature that ring-fences a portion of your savings so it cannot be transferred out digitally, even if your credentials are compromised. Set one up if you haven't already.

Enable Multi-Factor Authentication (MFA)

Use hardware keys or authenticator apps rather than SMS OTPs where possible. SMS OTPs can be intercepted through SIM-swap attacks.

Inspect Shortened Links Before Clicking

Shortened URLs can hide malicious destinations. Use a reputable link-checking or preview tool to reveal the real target before you click. Trusted URL shorteners such as Lunyb include click analytics and link previews, making it easier to spot suspicious redirects. For a broader look at reliable options, see our 2026 buyer's guide to URL shorteners.

Keep Software Updated

Enable automatic updates on your phone, browser, and operating system. Many phishing kits exploit outdated browser vulnerabilities to install malware silently.

What to Do If You've Been Phished

Speed matters. The first 30 minutes are critical for recovering funds and preventing further damage.

  1. Call your bank immediately using the number on your card. Ask them to freeze the account and reverse any pending transactions.
  2. Change your passwords for the affected account and any account using the same password.
  3. Revoke Singpass sessions via the Singpass app if credentials may have been exposed, and reset your password.
  4. Report the incident to the Singapore Police Force at 1800-255-0000 or via the online i-Witness portal, and lodge a report on ScamShield.
  5. Notify friends and family if your messaging accounts were compromised so they don't fall for follow-up scams.
  6. Run an antivirus scan and consider a factory reset if malware may have been installed.

Protecting Businesses in Singapore from Phishing

SMEs are disproportionately targeted because they often lack dedicated security teams. Practical steps include:

  • Deploy email authentication: Set up SPF, DKIM, and DMARC on your domain to prevent spoofing.
  • Conduct regular phishing simulations: Train staff with realistic mock campaigns.
  • Implement least-privilege access: Limit who can approve wire transfers or change supplier details.
  • Require dual approval for outbound payments above a set threshold.
  • Use endpoint protection and encrypted DNS at the network level to block known phishing domains.
  • Follow CSA guidelines: The Cyber Security Agency of Singapore publishes free resources tailored for local businesses.

The Role of Safe Link Sharing

Marketers, community managers, and even individuals send links every day. If a recipient can't tell whether a link is safe, they're more likely to ignore it or, worse, click on a fake one. Using a reputable link management platform with branded domains, HTTPS by default, and transparent click tracking builds trust. It also helps you spot unusual patterns, such as sudden spikes from unfamiliar regions, that could indicate abuse of your links. If you're evaluating options, our Rebrandly review compares one of the popular commercial choices in the market.

Frequently Asked Questions

How do I report a phishing SMS or email in Singapore?

Forward suspicious SMS to 7726 (SPAM) and report the incident via the ScamShield app or at police.gov.sg. If you have lost money, call the Anti-Scam Helpline at 1800-722-6688 immediately and lodge a police report.

Will my bank refund me if I fall for a phishing scam?

Under the Shared Responsibility Framework introduced by MAS and IMDA, banks and telcos may bear part of the loss if they failed to meet specific anti-scam duties. However, if the victim voluntarily provided credentials or OTPs, recovery is not guaranteed. Prevention remains the best protection.

Are QR code phishing attacks ("quishing") common in Singapore?

Yes, quishing is a growing concern, particularly at F&B outlets, car parks, and hawker centres where scammers place stickers over legitimate QR codes. Always verify the destination URL after scanning and avoid entering payment details into unfamiliar pages.

Can antivirus software alone protect me from phishing?

No. Antivirus tools help block malicious downloads and known phishing sites, but many attacks rely purely on tricking you into typing credentials into a convincing fake page. A layered approach combining software, MFA, and skeptical habits is essential.

How can I verify if a link is safe before clicking?

Hover over the link to preview the URL, check that the domain matches the official one exactly (especially the .gov.sg or .com.sg suffix for local entities), and use a link preview or URL scanning service. When in doubt, navigate to the website manually rather than clicking.

Final Thoughts

Phishing attacks in Singapore will keep evolving as scammers experiment with AI-generated voice clones, deepfake videos, and increasingly localised social engineering. The good news is that the fundamentals of defence haven't changed: slow down, verify through official channels, protect your credentials with MFA, and treat every unexpected message as suspicious until proven otherwise. A few seconds of caution can save years of financial and emotional damage.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles