Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore have surged into one of the most damaging categories of cybercrime, costing victims hundreds of millions of dollars each year. From fake DBS SMS alerts to convincing SingPost delivery scams, attackers are constantly refining their tactics to slip past busy professionals, elderly relatives, and even seasoned IT staff. This guide explains how phishing works in the Singapore context, what red flags to look for, and the practical steps you can take today to protect yourself, your family, and your business.
What Is a Phishing Attack?
A phishing attack is a form of social engineering where criminals impersonate a trusted party — a bank, government agency, delivery service, or colleague — to trick you into revealing sensitive information or authorising a fraudulent transaction. The goal is usually to steal login credentials, one-time passwords (OTPs), credit card details, or to install malware on your device.
In Singapore, phishing has evolved far beyond poorly written emails. Modern attacks use polished branding, spoofed local phone numbers, cloned government portals, and even AI-generated voice calls that mimic family members or executives.
Why Singapore Is a Prime Target
Singapore's high smartphone penetration, digital banking adoption, and reliance on services like Singpass and PayNow make it an attractive target. According to the Singapore Police Force's annual scam reports, phishing-related scams consistently rank among the top three fraud categories, with losses frequently exceeding S$70 million a year for banking phishing alone.
Common Types of Phishing Attacks in Singapore
Understanding the format of an attack is the first line of defence. Below are the most prevalent phishing variants seen locally.
1. SMS Phishing (Smishing)
Smishing messages often impersonate DBS, OCBC, UOB, IRAS, or SingPost. A typical example: "DBS Alert: Unusual login detected. Verify your account here: dbs-secure-sg.com". The link leads to a cloned banking portal designed to harvest your username, password, and OTP in real time.
2. Email Phishing
Attackers send emails posing as CPF, IRAS tax refunds, Ministry of Manpower notices, or corporate IT departments. These messages typically include an urgent call to action and a link to a fake login page. Business Email Compromise (BEC) — where a criminal impersonates a CEO or supplier — is a particularly costly variant for Singapore SMEs.
3. Voice Phishing (Vishing)
Callers pretend to be from the police, MAS, Immigration and Checkpoints Authority, or a bank's fraud team. They claim your identity has been used in a crime and pressure you to transfer money to a "safety account" or share your Singpass credentials.
4. QR Code Phishing (Quishing)
Fake QR codes are stuck on top of legitimate ones at hawker centres, parking meters, or bubble tea shops. Scanning takes you to a malicious payment page or a site that installs an Android APK capable of intercepting SMS OTPs.
5. Social Media and Messaging App Scams
WhatsApp, Telegram, and Facebook Marketplace are heavily abused. Common tactics include fake job offers, cryptocurrency investment pitches, and "friend in trouble" messages from hijacked accounts.
Red Flags: How to Recognize a Phishing Attempt
Almost every phishing attempt shares a handful of tell-tale signs. Train yourself to pause when you see any of the following:
- Urgency and fear — "Your account will be suspended in 24 hours."
- Unexpected links or attachments, especially from banks or government agencies (real Singapore banks stopped sending clickable links in SMS in 2022).
- Requests for OTPs, passwords, or Singpass credentials — legitimate institutions never ask for these.
- Slightly off domain names — for example
dbs-sg-login.cominstead ofdbs.com.sg. - Unusual payment requests — gift cards, cryptocurrency, or transfers to personal bank accounts.
- Poor grammar or awkward phrasing, though AI has made this red flag less reliable.
- Caller ID showing an overseas "+" prefix when the caller claims to be local — Singapore now labels these calls with a "+" warning.
Inspecting Suspicious URLs
Before clicking any link, hover over it (on desktop) or long-press it (on mobile) to preview the destination. Look carefully for:
- Misspellings:
singpost-sg.netvssingpost.com - Extra subdomains:
dbs.com.secure-login.xyz - Uncommon TLDs:
.top,.xyz,.click - Shortened links that don't resolve to a recognisable domain
If you need to share links with colleagues or customers, use a reputable shortener with link previews and analytics so recipients can verify destinations. Trustworthy services like Lunyb make it easy to create branded, transparent short links — and you can compare options in our 2026 URL shortener buyer's guide.
Real Examples of Phishing Attacks in Singapore
These recent scam patterns illustrate how sophisticated local phishing has become.
The OCBC SMS Scam (2021–2022)
Nearly 800 victims lost about S$13.7 million to spoofed SMS messages that appeared inside legitimate OCBC message threads. This incident directly triggered Singapore's SMS Sender ID Registry (SSIR) reforms and prompted banks to remove clickable links from SMS notifications.
Malicious Android APK Scams
Since 2023, scammers have pushed victims — often via Facebook ads for cheap seafood, cleaning services, or pet grooming — to install Android apps outside the Play Store. These APKs silently read SMS OTPs and drain bank accounts. MAS and the Singapore Police Force now recommend enabling anti-malware features in banking apps like DBS digibank, OCBC Digital, and UOB TMRW.
Singpass Impersonation
Phishing sites mimicking the Singpass login page harvest credentials that are later used to open bank accounts, apply for loans, or take over CPF submissions. Always launch Singpass from the official app or by typing singpass.gov.sg directly.
Phishing Red Flags at a Glance
| Signal | Legitimate Message | Phishing Message |
|---|---|---|
| Links in SMS | None (since 2022 for SG banks) | Clickable link to "verify" account |
| Sender ID | Registered ID (e.g. "DBS") | "Likely-SCAM" label or unknown number |
| Tone | Informational | Urgent, threatening, or too good to be true |
| Requested action | Log in via official app | Share OTP, install APK, transfer funds |
| Domain | dbs.com.sg, singpass.gov.sg | dbs-secure-sg.com, singpass-verify.xyz |
How to Protect Yourself from Phishing in Singapore
No single tool blocks every attack. A layered approach combining awareness, device hygiene, and account controls is essential.
Personal Best Practices
- Never click links in unsolicited SMS or email. Open the official app or type the URL manually.
- Enable Money Lock on your DBS, OCBC, UOB, or Standard Chartered account to ring-fence funds that cannot be transferred digitally.
- Turn on transaction alerts for every debit and credit above S$0.
- Use hardware or app-based two-factor authentication instead of SMS OTPs where possible.
- Only install apps from Google Play or the App Store. Enable Google Play Protect and your bank's built-in malware scanner.
- Register with the Do Not Call registry and treat any unsolicited call about "account issues" as suspicious.
- Verify unusual requests through a second channel — call the family member or colleague directly.
Device and Network Hygiene
- Keep iOS, Android, and browsers updated — most phishing kits exploit outdated software.
- Use encrypted DNS resolvers (like Cloudflare 1.1.1.1 or Quad9) that block known phishing domains at the network level.
- Install a reputable mobile security app that flags malicious links in messaging apps.
- Enable biometric or passkey sign-in for your email — a compromised email account is the master key to everything else.
Protecting Your Business
SMEs in Singapore are disproportionately affected because they lack dedicated security staff. Practical steps include:
- Deploy DMARC, SPF, and DKIM on all corporate domains to prevent email spoofing.
- Run quarterly phishing simulations for staff, focusing on invoice fraud and CEO impersonation.
- Enforce dual approval for any payment above a set threshold, with verbal confirmation via a known phone number.
- Adopt passkeys or FIDO2 security keys for admin accounts on Microsoft 365, Google Workspace, and cloud consoles.
- Use branded short links for all marketing communications so customers learn to trust your domain. Our Rebrandly review and shortener comparison can help you pick the right platform.
What to Do If You Fall for a Phishing Attack
Speed matters. If you suspect you've been phished, act within minutes, not hours.
- Freeze the affected accounts. Use the in-app "kill switch" offered by DBS, OCBC, UOB, and other major banks, or call their 24/7 fraud hotline.
- Change passwords for the compromised account and any others sharing the same credentials. Enable two-factor authentication everywhere.
- Revoke Singpass access at
singpass.gov.sgif you shared credentials, then reset your password and re-register 2FA. - Report to the Anti-Scam Centre by calling 1800-722-6688 or filing a police report at
police.gov.sg/iwitness. - Report the scam to ScamShield (via the app or by forwarding suspicious SMS to 9-SPF-SPF / 97795777).
- Scan your device for malware, and factory-reset if you installed a suspicious APK.
- Notify your contacts if your email or messaging accounts were hijacked, as attackers often pivot to your network.
Singapore Resources You Should Bookmark
- ScamShield app — filters known scam calls and SMS on iOS and Android.
- Anti-Scam Helpline: 1800-722-6688
- ScamAlert.sg — updated scam trends and advisories.
- CSA SingCERT — advisories and incident reporting for businesses.
- MAS and ABS advisories — updates on banking security measures like Money Lock and the Shared Responsibility Framework.
Frequently Asked Questions
How common are phishing attacks in Singapore?
Extremely common. The Singapore Police Force reports tens of thousands of scam cases annually, with phishing-related scams (banking, e-commerce, government official impersonation) consistently among the top categories. Total losses regularly exceed S$650 million across all scam types.
Will my bank refund me if I fall for a phishing scam?
Under Singapore's Shared Responsibility Framework (effective from December 2024), banks and telcos may bear part of the loss if they failed to meet specific anti-scam duties. However, if you willingly shared your OTP or credentials, or installed a malicious app despite warnings, you may still be held largely responsible. Recovery is never guaranteed, so prevention is critical.
Are shortened URLs safe to click?
Short links themselves aren't dangerous — the destination is what matters. Reputable shorteners like Lunyb offer link previews, HTTPS, and abuse monitoring. Be cautious with links from unknown senders, and use a URL expander or preview tool if you're unsure. You can read more in our honest Lunyb review.
How can I tell if a Singapore government website is real?
All genuine Singapore government websites end in .gov.sg. If a site claims to be from IRAS, CPF, ICA, or Singpass but uses another domain (like .com, .net, or .xyz), it is fraudulent. When in doubt, navigate directly by typing the official address.
What should elderly family members do to stay safe?
Help them install the ScamShield app, enable Money Lock on their bank accounts, set low daily transaction limits, and remove overseas transfer capabilities they don't need. Encourage a household rule: any unusual money request must be verified by a phone call to a trusted family member first.
Final Thoughts
Phishing attacks in Singapore will keep evolving as attackers adopt AI, deepfake audio, and cleaner-looking fake websites. The good news is that the fundamentals of protection haven't changed: pause before you click, verify through official channels, lock down your accounts, and never share OTPs or Singpass credentials. Combine that discipline with modern controls like Money Lock, passkeys, and reputable link tools, and you'll be a much harder target than the vast majority of victims.
Stay vigilant, share this guide with family and colleagues, and treat every urgent message as suspicious until proven otherwise.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Zero Trust Security Model Explained Simply: A 2026 Guide
Zero Trust flips traditional security on its head with a simple rule: never trust, always verify. This guide explains what Zero Trust is, how it works, and how to start implementing it — in plain English, without the jargon.
How to Know if Your Phone Is Hacked: 10 Warning Signs
Wondering if your smartphone has been compromised? Learn the 10 clearest warning signs your phone is hacked — from battery drain and data spikes to strange messages and unfamiliar apps — plus exactly what to do if you spot them.
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication (2FA) is the single most effective step you can take to protect your online accounts in 2026. Learn how it works, which methods are safest, and how to enable it on your most important accounts.
End-to-End Encryption Explained: How It Works and Why It Matters
End-to-end encryption keeps your messages private by ensuring only you and the recipient can read them — not even the service provider. This guide explains how E2EE works, where it's used, its real limits, and how to apply it in your daily digital life.