facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing has become one of the most persistent cyber threats facing Singaporeans. From fake DBS SMS alerts to bogus SingPass login pages, scammers are constantly refining their tactics to steal credentials, drain bank accounts, and hijack digital identities. According to the Singapore Police Force, scam and cybercrime losses continue to run into the hundreds of millions of dollars annually, with phishing consistently ranked among the top attack vectors.

This guide breaks down exactly how phishing attacks in Singapore work in 2026, the local scams you are most likely to encounter, and the practical steps you can take today to protect yourself, your family, and your business.

What Is a Phishing Attack?

A phishing attack is a form of social engineering in which criminals impersonate trusted organisations — banks, government agencies, delivery firms, or employers — to trick victims into revealing sensitive information or clicking malicious links. The goal is almost always the same: steal login credentials, one-time passwords (OTPs), payment card details, or install malware.

In Singapore, phishing typically arrives through four main channels:

  1. SMS (smishing): Fake messages that appear to come from banks, IRAS, or SingPost.
  2. Email: Spoofed invoices, HR notices, or delivery updates.
  3. Phone calls (vishing): Scammers posing as police, MAS, or bank officers.
  4. Messaging apps: WhatsApp and Telegram scams involving fake job offers or investment schemes.

Why Singapore Is a Prime Target

Singapore's high smartphone penetration, cashless payment adoption, and digital government services make it an attractive market for phishing operators. Several factors amplify the risk:

  • High banking digitalisation: Nearly all retail banking is done via apps, giving scammers a clear target.
  • SingPass as a single identity: One compromised SingPass account can unlock CPF, HDB, IRAS, and hundreds of private services.
  • Cross-border scam syndicates: Many phishing campaigns are run from overseas call centres targeting Singaporeans specifically.
  • Trust in official-looking communications: Locals are accustomed to receiving legitimate SMSes from banks and government agencies, which scammers exploit.

Common Phishing Attacks in Singapore

1. Bank Impersonation Scams (DBS, OCBC, UOB)

These remain the most damaging category. Victims receive SMS or emails warning of "unauthorised transactions" and are urged to click a link to "verify" their account. The link leads to a pixel-perfect clone of the bank's login page. Once credentials and OTPs are entered, scammers drain the account within minutes.

2. SingPass and Government Agency Phishing

Scammers impersonate IRAS (tax refunds), ICA (passport renewal), MOM (work pass issues), or the Ministry of Health. A common variant sends a fake "parcel held by Singapore Customs" message requesting payment of GST via a phishing site.

3. Delivery and E-commerce Scams

Fake SingPost, Ninja Van, or Shopee notifications claim a parcel cannot be delivered and ask for a small redelivery fee. The payment page harvests card details, which are then used for larger fraudulent transactions.

4. Job Scam Phishing

Victims are approached on WhatsApp or Telegram with high-paying part-time "task" jobs. Eventually they are directed to a fake platform requiring a deposit or login credentials linked to their bank account.

5. Investment and Cryptocurrency Phishing

Fake trading platforms, sometimes endorsed by deepfake videos of local celebrities or ministers, lure victims to "invest" through phishing portals that steal both money and identity documents.

6. Business Email Compromise (BEC)

SMEs in Singapore are frequent targets. Attackers spoof a supplier or CEO email and request urgent invoice payment changes, often costing companies tens of thousands of dollars per incident.

Red Flags: How to Recognise a Phishing Attempt

Most phishing attempts share telltale characteristics. Train yourself and your team to pause when you see any of the following:

Red FlagWhat It Looks LikeWhy It's Suspicious
Urgency and threats"Your account will be suspended in 24 hours"Legitimate banks never pressure you via SMS
Unfamiliar sender numbersSMS from +65 8xxx or foreign numbersLocal banks use registered Sender IDs, not mobile numbers
Suspicious linksdbs-secure-login.xyz or bit.ly shortenersReal bank URLs end in .com.sg or .sg
Requests for OTP"Please share the 6-digit code"No bank or agency will ever ask for your OTP
Generic greetings"Dear Customer" instead of your nameReal institutions personalise messages
Spelling and grammar errorsAwkward phrasing or missing punctuationProfessional organisations proofread communications
Unexpected attachments.zip, .exe, or macro-enabled .docx filesCommon malware delivery vector

How to Verify a Suspicious Message

When in doubt, follow this five-step verification process before clicking anything:

  1. Do not click the link. Screenshot the message first for reporting.
  2. Check the official Sender ID. All legitimate government and bank SMSes in Singapore now use the SG SMS Sender ID Registry. Messages from unregistered senders are automatically labelled "Likely-SCAM".
  3. Open the official app or website manually. Type the URL yourself or use the bookmarked app — never follow the SMS link.
  4. Call the official hotline. Use the number on the back of your bank card or the agency's official site, not the number in the message.
  5. Use ScamShield. The ScamShield app (by Open Government Products and the Singapore Police Force) automatically filters known scam SMSes and calls.

Protecting Yourself: Practical Defences

Enable Strong Authentication

  • Turn on Money Lock in your bank app to ring-fence a portion of your savings from digital transfers.
  • Use SingPass Face Verification instead of SMS OTP where possible.
  • Enable app-based authenticators (Google Authenticator, Authy) for non-banking accounts.

Harden Your Devices

  • Keep iOS and Android updated — most patches close phishing-related exploits.
  • Only install apps from the official App Store or Google Play. Sideloading APKs is the number one vector for banking malware in Singapore.
  • Turn on Google Play Protect and iOS Lockdown Mode if you are high-risk.

Use Safer Browsing Habits

Modern browsers such as Safari, Chrome, and Brave include built-in phishing protection through Google Safe Browsing and iCloud Private Relay. Combine this with encrypted DNS (such as Cloudflare 1.1.1.1 or Quad9) to block known malicious domains before they even load. When sharing links yourself — especially at work or in marketing — use a reputable link management platform like Lunyb so recipients can trust that the shortened URL is legitimate and monitored. If you are evaluating link tools, our 2026 URL shortener comparison covers the safest options.

Verify Short Links Before Clicking

Scammers frequently abuse generic short links to disguise phishing URLs. Before clicking a shortened link, expand it with a preview tool (many shorteners, including Lunyb, offer link previews). You can read more about how legitimate shorteners handle safety in our honest Lunyb review.

What to Do If You've Been Phished

Act within minutes, not hours. Every second matters once credentials are stolen.

  1. Freeze your bank account immediately. DBS, OCBC, and UOB all offer a "kill switch" in their apps or via hotline.
  2. Change all affected passwords, starting with your email (since it can reset everything else).
  3. Revoke SingPass sessions at singpass.gov.sg and reset your password.
  4. Report to the Anti-Scam Centre by calling 1800-722-6688 or filing a report at police.gov.sg/iwitness.
  5. Report to ScamShield so the number/URL is added to national blocklists.
  6. Notify your contacts if the attacker may impersonate you next.
  7. Monitor your credit through the Credit Bureau Singapore for unusual loan applications.

Advice for Singapore Businesses and SMEs

Phishing is not just a consumer problem. IMDA and CSA both list phishing and BEC as the top threats facing Singaporean SMEs. Recommended controls include:

  • Enforce MFA on Microsoft 365, Google Workspace, and all admin accounts — preferably with hardware keys (YubiKey) for finance staff.
  • Configure SPF, DKIM, and DMARC for your domain to prevent spoofing.
  • Run quarterly phishing simulations to identify vulnerable staff and provide targeted training.
  • Implement dual-approval workflows for any change of supplier bank details or payments above a set threshold.
  • Subscribe to SingCERT advisories for early warning of active campaigns targeting Singapore.
  • Use a branded, monitored URL shortener for customer communications so recipients can distinguish your links from scam links.

Official Singapore Resources

ResourcePurposeContact
Anti-Scam HelplineReport and get help with active scams1800-722-6688
ScamShield AppBlock scam SMS and callsscamshield.gov.sg
SingCERTCybersecurity advisories for businessescsa.gov.sg/singcert
Police i-WitnessFile a police report onlinepolice.gov.sg/iwitness
SPF Scam AlertLatest scam trendsscamalert.sg

Frequently Asked Questions

How do I report a phishing SMS in Singapore?

Forward the SMS to 9-SPF-SCAM (9773-7226) or report it through the ScamShield app. You can also file a report at police.gov.sg/iwitness. Reporting helps authorities take down phishing infrastructure faster.

Will my bank refund me if I fall victim to a phishing scam?

Under the Shared Responsibility Framework (SRF) that took effect in 2024, banks and telcos may bear part of the losses if they failed in their duties (for example, not blocking a known scam SMS). However, if you shared your OTP or PIN voluntarily, you may still bear most of the loss. Prevention remains far cheaper than recovery.

How can I tell if a Singapore government SMS is real?

Legitimate government SMSes come from the Sender ID "gov.sg" or the specific agency's registered ID (e.g. "IRAS", "ICA"). Since 2023, any government SMS not from a registered Sender ID will display as "Likely-SCAM". Additionally, gov.sg messages typically do not contain clickable links to sensitive login pages.

Are shortened URLs safe to click?

Shortened URLs are only as safe as the person or platform sharing them. Reputable shorteners scan destinations for malware and phishing, and offer link previews. If you receive a shortened link from an unknown sender, expand it first using a preview tool before clicking. For marketing and business use, choose a shortener with active abuse monitoring.

What should I do if I already entered my SingPass credentials on a fake site?

Immediately log in to the real singpass.gov.sg, change your password, and revoke all active sessions. Enable Face Verification as your default 2FA method. Then check CPF, IRAS, and HDB portals for any unauthorised activity, and file a police report. If you suspect identity theft, request a credit freeze with the Credit Bureau Singapore.

Final Thoughts

Phishing attacks in Singapore have grown more sophisticated, but they still rely on the same core trick: creating urgency to bypass your judgement. Slow down, verify through official channels, and never share OTPs or click unsolicited links. Combine strong authentication, updated devices, safe browsing habits, and national tools like ScamShield, and you will neutralise the vast majority of phishing attempts before they cost you a cent.

Stay vigilant, stay updated, and share this guide with family members — especially elderly relatives, who remain the most targeted group in Singapore.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles