facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have grown more sophisticated, targeting everyone from DBS and OCBC customers to SingPass users and busy SMEs. In 2024 alone, the Singapore Police Force reported over S$1.1 billion lost to scams, with phishing consistently ranking among the top three attack methods. This guide breaks down how modern phishing works locally, the red flags to watch for, and the practical steps you can take today to protect yourself, your family, and your business.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a trusted organisation to trick you into revealing sensitive information such as passwords, OTPs, credit card numbers, or SingPass credentials. In Singapore, phishing typically arrives through SMS, WhatsApp, email, phone calls, or malicious QR codes, and often points to a fake login page that looks nearly identical to the real one.

Unlike random spam, modern phishing is highly targeted. Attackers study local branding, use Singlish phrasing, spoof numbers that appear to belong to local banks or government agencies, and time their campaigns around events like IRAS tax season, GST rebate payouts, or Singpost delivery peaks.

The Current Phishing Landscape in Singapore

The Cyber Security Agency of Singapore (CSA) and the Singapore Police Force continue to warn about a rising volume of phishing scams, particularly those combining SMS lures with malicious Android APK installations. Key trends include:

  • Bank impersonation scams targeting DBS, OCBC, UOB, Standard Chartered, and Citibank customers.
  • Government impersonation using SingPass, IRAS, ICA, MOM, and MOH branding.
  • Delivery scams pretending to be SingPost, Ninja Van, J&T, or DHL.
  • Job scams on WhatsApp and Telegram offering fake part-time roles.
  • QR code phishing (quishing) placed over legitimate codes at hawker centres, car parks, and shop fronts.

The Monetary Authority of Singapore (MAS) has responded with the Shared Responsibility Framework, requiring banks and telcos to bear part of the loss when they fail their duties. Even so, prevention on the user side remains the most effective defence.

Common Types of Phishing Attacks Targeting Singaporeans

1. SMS Phishing (Smishing)

Smishing is the most reported phishing vector in Singapore. You receive an SMS claiming there is an issue with your bank account, a suspicious transaction, or a locked SingPass. The message contains a shortened or lookalike URL that leads to a cloned login page.

Since the SMS Sender ID Registry (SSIR) became mandatory in 2023, unregistered sender IDs are automatically marked as "Likely-SCAM". Treat any such tag as a hard stop.

2. Email Phishing

Emails often impersonate IRAS (refunds), ICA (passport renewal), Netflix, Microsoft 365, or your employer's HR department. Common giveaways include mismatched sender domains, generic greetings, urgent language, and attachments disguised as invoices or payslips.

3. WhatsApp and Telegram Scams

Attackers pose as recruiters, delivery agents, or even friends whose accounts have been hijacked. A common script offers "easy part-time job at $50/task" and eventually pushes victims into transferring funds to a fake "task platform".

4. Voice Phishing (Vishing)

Callers claim to be from the Singapore Police Force, MOH, or a bank's fraud team, sometimes using spoofed +65 numbers. They pressure victims to install remote-access apps like AnyDesk or transfer money to a "safe account".

5. QR Code Phishing (Quishing)

Fraudsters paste malicious QR codes over legitimate ones at bubble tea shops, hawker stalls, and even parking meters. The QR leads to a fake payment page or downloads a malicious APK that steals banking credentials.

6. Spear Phishing and Business Email Compromise (BEC)

SMEs in Singapore are frequent BEC targets. An attacker studies your company, then emails your finance team pretending to be the CEO or a supplier, requesting an urgent bank transfer or a change of payment details.

How to Recognize a Phishing Attempt: 10 Red Flags

  1. Urgency and fear — "Your account will be suspended in 24 hours."
  2. Requests for OTPs, passwords, or SingPass details — no legitimate bank or agency will ever ask.
  3. Suspicious links — hover before clicking; look for misspellings like "dbs-secure.com" or "singpass-login.net".
  4. "Likely-SCAM" sender ID on SMS.
  5. Unusual sender email domains like @iras-sg.info instead of @iras.gov.sg.
  6. Poor grammar or awkward Singlish that doesn't match the brand's usual tone.
  7. Attachments you didn't expect, especially .apk, .zip, .html, or macro-enabled documents.
  8. Requests to install apps outside the Google Play Store or Apple App Store.
  9. Pressure to switch channels — "Continue this on WhatsApp" or "Call this number."
  10. Too-good-to-be-true offers — GST rebates, free vouchers, or high-paying easy jobs.

Real Examples of Phishing Scams in Singapore

Scam Type Impersonated Entity Typical Lure Attacker Goal
Bank SMS DBS / OCBC / UOB "Suspicious login detected" Steal ibanking credentials + OTP
Government email IRAS / SingPass "Claim your tax refund" Harvest SingPass 2FA
Delivery SMS SingPost / Ninja Van "Parcel held, pay S$0.50" Card details + APK install
Job scam Shopee / Lazada affiliate "Earn $300/day part-time" Trick victim into PayNow transfers
QR quishing Hawker payment Fake PayNow QR overlay Redirect payments
BEC CEO or supplier "Urgent invoice change" Divert corporate payments

How to Avoid Phishing Attacks: A Practical Checklist

For Individuals

  1. Enable the Money Lock feature offered by DBS, OCBC, UOB, and Standard Chartered to ring-fence part of your savings from digital transfers.
  2. Turn on ScamShield — the free app by the National Crime Prevention Council filters scam SMS and blocks known scam numbers.
  3. Never click links in SMS from banks. Open the official banking app directly instead.
  4. Verify unknown callers by hanging up and dialling the official number on the back of your card or from the agency's website.
  5. Use passkeys or hardware security keys where supported, and enable 2FA on every account.
  6. Keep your phone updated and never sideload APKs from links.
  7. Inspect QR codes physically before scanning — look for stickers pasted over the original.
  8. Use encrypted DNS (such as Cloudflare 1.1.1.1 or Quad9) to block known phishing domains at the network level.

For Businesses and SMEs

  1. Enforce DMARC, SPF, and DKIM on your email domain to prevent spoofing.
  2. Deploy an email security gateway with attachment sandboxing and URL rewriting.
  3. Run quarterly phishing simulations and targeted training for finance and HR teams.
  4. Implement a callback verification policy: any change in supplier bank details must be confirmed by phone using a previously known number.
  5. Require multi-person approval for outgoing transfers above a defined threshold.
  6. Adopt phishing-resistant MFA (FIDO2 keys or platform passkeys) for admin and finance accounts.

Why URL Inspection Matters

Most phishing attacks ultimately depend on you clicking a malicious link. Attackers hide destinations behind shortened URLs, homoglyph domains (using Cyrillic letters that look like Latin ones), or subdomains such as dbs.com.secure-login.xyz.

Before clicking any shortened or unfamiliar link, use a link preview tool or paste it into a URL expander. Reputable shorteners let you see the destination before you visit. For example, Lunyb is a URL shortener that focuses on transparent, privacy-respecting links and can be used to inspect or safely share URLs without exposing tracking parameters. If you want a broader look at trustworthy options, our 2026 buyer's guide to URL shorteners compares the main players, and our honest review of Lunyb covers what to look for in a safe link platform.

What to Do If You've Been Phished

  1. Freeze your accounts immediately using your banking app's kill switch (available on DBS, OCBC, UOB, and Citibank).
  2. Call your bank's 24/7 fraud hotline — for example, DBS at 1800-339-6963 or OCBC at 1800-363-3333.
  3. Change all affected passwords from a clean device, and revoke sessions.
  4. Report to the Singapore Police Force via the ScamShield app or at police.gov.sg/iwitness, and lodge a report at your nearest Neighbourhood Police Centre.
  5. Call the Anti-Scam Helpline at 1800-722-6688 for guidance.
  6. Reset SingPass at singpass.gov.sg if credentials may have been exposed.
  7. Factory reset your phone if you installed an APK or granted accessibility permissions.
  8. Notify contacts that your accounts may be compromised to prevent further spread.

Government and Industry Resources in Singapore

  • ScamShield — free scam-filtering app by NCPC.
  • CSA SingCERT — advisories at csa.gov.sg/singcert.
  • Anti-Scam Centre (ASC) — works with banks to freeze scam accounts within hours.
  • SPF I-Witness — online reporting portal.
  • MAS Shared Responsibility Framework — outlines when banks and telcos must compensate victims of phishing.

Building a Long-Term Anti-Phishing Habit

Awareness campaigns like "ACT Against Scams" (Add, Check, Tell) from the Singapore Police Force are useful mnemonics, but the real defence is habit. Treat every unexpected message as untrusted by default. Assume the sender ID can be spoofed. Assume the link is malicious. Verify through an independent, previously known channel before you act.

If you run a business, layer defences: technology (email authentication, endpoint protection, encrypted DNS), process (callback verification, dual approval), and people (regular training and phishing simulations). No single control will catch everything, but together they dramatically shrink your risk.

Frequently Asked Questions

How common are phishing attacks in Singapore?

Phishing consistently ranks in the top three scam types reported to the Singapore Police Force each year. In 2024, victims collectively lost hundreds of millions of dollars to phishing-related scams, with bank impersonation and job scams leading the volume.

Will my bank refund me if I fall for a phishing scam?

Under MAS's Shared Responsibility Framework, banks and telcos may bear part of the loss if they failed specific duties (for example, not enforcing 12-hour cooling-off for new device logins). However, if you willingly disclosed OTPs or approved transactions, recovery is not guaranteed. Report immediately — the Anti-Scam Centre can sometimes freeze funds within hours.

How do I check if a link in an SMS is safe?

Don't click. Instead, open your banking or government app directly, or type the official URL into your browser. If you must inspect a shortened URL, use a link expander or preview feature from a reputable shortener before visiting. Watch for lookalike domains such as "singpass-sg.com" instead of the official singpass.gov.sg.

Are iPhones safer than Android against phishing in Singapore?

iOS is more restrictive about installing apps outside the App Store, which blocks the APK-based malware common in Singapore scams. However, iPhone users are still fully exposed to SMS, email, and credential-phishing sites. Enable Lockdown Mode if you are a high-risk user and always keep iOS updated.

What should I do if I clicked on a phishing link but didn't enter any details?

Close the tab, clear your browser cache, and scan your device with a reputable mobile security tool. If you were on Android and were prompted to install an app, uninstall it, revoke any accessibility or SMS permissions granted, and consider a factory reset. Change any passwords you may have autofilled, and monitor your bank statements for the next few weeks.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles