facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··10 min read

Phishing attacks in Singapore have grown from clumsy email scams into highly targeted, professionally crafted campaigns that mimic banks, government agencies, delivery firms, and even the Singapore Police Force. According to the Singapore Police Force's annual scam report, phishing-related losses continue to run into the hundreds of millions of dollars each year, with victims spanning every age group and income bracket.

This guide explains what phishing looks like in the Singapore context, the specific tactics scammers use locally, and the practical steps you can take to protect yourself, your family, and your business.

What Is a Phishing Attack?

A phishing attack is a form of social engineering in which criminals impersonate a trusted organisation to trick you into revealing sensitive information, installing malware, or transferring money. The message usually arrives through email, SMS, WhatsApp, Telegram, or a phone call, and it almost always tries to create urgency or fear.

In Singapore, phishing has evolved into several distinct sub-types:

  • Email phishing — fake messages from "DBS", "OCBC", "IRAS", or "SingPost".
  • Smishing — SMS scams pretending to be from banks, ICA, LTA, or courier services.
  • Vishing — voice calls impersonating police officers, MAS staff, or bank fraud teams.
  • Quishing — malicious QR codes stuck over legitimate ones at hawker centres, carparks, and bubble tea shops.
  • Spear phishing — highly targeted attacks on employees of specific SMEs or MNCs.

Why Singapore Is a Prime Target

Singapore's high digital adoption, strong purchasing power, and reliance on services like PayNow, SingPass, and mobile banking make it especially attractive to phishing groups. A few structural factors amplify the risk:

  1. Near-universal smartphone use means SMS and messaging app scams reach almost everyone.
  2. Trusted government digital services like SingPass are frequently impersonated because citizens are conditioned to act on official-looking messages.
  3. Cross-border e-commerce generates constant "parcel delivery" notifications, which scammers exploit.
  4. Multilingual population allows attackers to craft messages in English, Mandarin, Malay, or Tamil.

Common Phishing Attacks in Singapore in 2026

1. Fake Bank Alerts (DBS, OCBC, UOB, Standard Chartered)

You receive an SMS or email claiming your account has been locked, a large PayNow transfer is pending, or your card was used overseas. The message includes a link to "verify" or "cancel" the transaction. The link leads to a pixel-perfect clone of the real bank login page.

2. SingPass and Government Impersonation

Scammers send emails or SMS claiming to be from IRAS (tax refunds), ICA (passport renewal), MOM (work pass issues), or MOH (health notifications). These often direct victims to fake SingPass login screens that harvest 2FA codes in real time.

3. Parcel Delivery Scams

"Your SingPost / Ninja Van / J&T parcel could not be delivered. Please update your address and pay a $0.50 redelivery fee." Once you enter card details, scammers charge much larger amounts or enrol your card in recurring subscriptions.

4. Job Scams on WhatsApp and Telegram

An unknown number offers part-time work "liking videos" or "boosting merchants" for $50–$300 a day. Victims are moved to a Telegram group, asked to top up funds to unlock commissions, and lose everything.

5. E-commerce and Marketplace Phishing

On Carousell, Facebook Marketplace, or Shopee, scammers send links to fake payment gateways that look like PayNow or the platform's checkout page.

6. QR Code Scams (Quishing)

Physical stickers placed on top of legitimate menu QR codes at F&B outlets redirect diners to fake payment or "survey reward" sites.

Red Flags: How to Recognise a Phishing Attempt

Most phishing messages share the same DNA. Learn to spot these signals and you'll catch the vast majority of attacks before any damage is done.

Red Flag What It Looks Like What a Legitimate Message Does
Urgency or fear "Your account will be closed in 2 hours!" Banks give reasonable notice and never threaten closure by SMS.
Suspicious link dbs-secure-verify.com, singpass-login.net Real domains end in .dbs.com.sg, .gov.sg, .singpass.gov.sg
Unexpected attachment Invoice.pdf.exe, statement.zip Statements are downloaded from within your banking app.
Requests for OTP or SingPass code "Please share the SMS code to verify." No legitimate agency will ever ask for your OTP.
Generic greeting "Dear customer" instead of your name Banks typically address you by full registered name.
Poor grammar or odd phrasing "Kindly do the needful immediately." Official Singapore communications are professionally edited.

How to Verify a Suspicious Link Before You Click

Shortened links are useful and legitimate, but they can also hide the destination. Before clicking any link — especially in SMS or WhatsApp — take these steps:

  1. Hover before you click on desktop. The real URL appears in the bottom-left corner of the browser.
  2. Long-press on mobile to preview where the link leads before opening it.
  3. Use a link preview tool to expand shortened URLs safely without visiting them.
  4. Check the domain carefully. "dbs.com.sg" is real; "dbs-com.sg" or "dbs.com-secure.sg" is not.
  5. Open the app directly instead of clicking. If DBS says there's a transfer, log in via the DBS app to check.

Reputable link shorteners such as Lunyb add value here because they provide transparent link management, analytics, and the ability to disable a link instantly if it is misused. If you're evaluating shorteners for business use, our 2026 buyer's guide to URL shorteners compares the safest options, and our honest Lunyb review covers its security features in depth.

What to Do If You Clicked a Phishing Link

Acting quickly can dramatically reduce the damage. Follow this sequence:

  1. Disconnect from the internet if you downloaded anything from the page.
  2. Change your passwords immediately, starting with your email and banking accounts. Use a different device if possible.
  3. Call your bank's 24/7 hotline — DBS 1800-339-6963, OCBC 1800-363-3333, UOB 1800-222-2121 — and request a card freeze.
  4. Report to ScamShield via the ScamShield app or 1799 helpline.
  5. Lodge a police report at www.police.gov.sg/iwitness within 24 hours.
  6. Enable Money Lock on your bank account to prevent unauthorised digital transfers of a portion of your balance.
  7. Reset your SingPass password if you entered any SingPass credentials.

Protecting Yourself: Everyday Habits That Work

Enable Strong Multi-Factor Authentication

Use SingPass Face Verification and app-based tokens rather than SMS OTPs where possible. SMS can be intercepted or socially engineered; app-based authenticators cannot.

Use a Password Manager

A password manager will only autofill credentials on the exact domain it stored them for. If it refuses to fill in your "DBS login" page, that's a huge clue the page is fake.

Turn On Bank Security Features

All major Singapore banks now offer:

  • Money Lock — ring-fences a portion of funds from digital transfers.
  • Kill switch — instantly freezes your account from the app.
  • Transaction limits — cap daily PayNow and overseas transactions.
  • Device binding — only registered devices can perform sensitive actions.

Install the ScamShield App

Developed by the National Crime Prevention Council and Open Government Products, ScamShield blocks known scam calls and SMS and lets you report suspicious messages with one tap.

Keep Software Updated

Apply iOS, Android, and browser updates within days of release. Many phishing kits exploit vulnerabilities that have already been patched.

Use Encrypted DNS and a Secure Browser

Enabling DNS-over-HTTPS in Chrome, Safari, or Firefox helps block access to known malicious domains at the network level. Privacy-focused browsers like Brave add anti-phishing lists by default.

Phishing Attacks Targeting Singapore Businesses

SMEs and MNCs in Singapore face two dominant business-focused attacks: Business Email Compromise (BEC) and invoice fraud. Both usually start with a phishing email that harvests a finance staffer's Microsoft 365 credentials. Attackers then monitor real email threads and inject fake payment instructions at the perfect moment.

Best Practices for Business Protection

  • Mandate MFA on every corporate email and SaaS account.
  • Implement DMARC, SPF, and DKIM on your email domain to prevent spoofing.
  • Require dual approval and voice call verification for any payment change or transfer above a defined threshold.
  • Run quarterly phishing simulations and short training refreshers.
  • Use branded, trackable links from platforms like Rebrandly or Lunyb so employees and customers can distinguish official company links from spoofs.
  • Segment access — finance staff should not share admin accounts with marketing.

Pros and Cons of Common Anti-Phishing Tools

Pros

  • ScamShield blocks a very high percentage of known scam numbers and messages in Singapore.
  • Password managers eliminate credential reuse and auto-detect fake domains.
  • Bank Money Lock caps the maximum loss even if credentials are stolen.
  • Email authentication (DMARC) stops most domain spoofing at the inbox level.

Cons

  • No tool blocks 100% of new, previously unseen phishing sites.
  • Some legitimate SMS from overseas businesses get flagged as scams.
  • Employees still need training — technology alone doesn't stop human error.
  • Adding too many security prompts can lead to "alert fatigue", making users click through warnings.

Reporting Phishing in Singapore

Every report helps authorities take down infrastructure faster and warn others. Use these channels:

What Happened Where to Report
Suspicious SMS or call ScamShield app, or forward SMS to 9-SPF-SPF (9773-7773)
You lost money Police (1800-255-0000) and your bank's fraud hotline immediately
Phishing email Forward to report@scamshield.gov.sg and to your email provider's abuse address
Fake website Report via SingCERT at csa.gov.sg/singcert
Suspicious short link Report via the shortener's abuse page (e.g. Lunyb offers a direct report link on every profile)

Frequently Asked Questions

How much money is lost to phishing in Singapore each year?

Phishing and related scams cost Singapore residents and businesses hundreds of millions of dollars annually, according to the Singapore Police Force's Annual Scams and Cybercrime Brief. Losses have generally trended upwards year on year, though banking security features like Money Lock and the Shared Responsibility Framework have started to reduce individual loss sizes.

Will my bank refund me if I fall for a phishing scam?

Under Singapore's Shared Responsibility Framework introduced by MAS and IMDA, banks and telcos may bear part of the loss if they failed in specific duties (e.g. not sending required alerts). However, if you willingly disclosed your OTP or SingPass credentials, you may still be liable for most or all of the loss. Always report immediately — the sooner you act, the higher the chance of recovery.

Are shortened URLs safe to click?

Shortened URLs from reputable services are safe by design, but scammers can create short links too. Always preview the destination before clicking, especially if the message is unexpected. Business-grade shorteners like Lunyb allow you to see analytics, disable compromised links, and use custom branded domains that customers can trust.

Can I get phished on WhatsApp or Telegram?

Yes — messaging app phishing is now one of the fastest-growing categories in Singapore. Common tactics include fake job offers, "friend in trouble" impersonation, fake investment groups, and cloned business accounts. Never share OTPs or verification codes on chat, and enable two-step verification in WhatsApp and Telegram settings.

What should I teach my elderly parents about phishing?

Focus on three simple rules: (1) never share any OTP, SingPass code, or password with anyone — not even police or bank staff; (2) hang up on any call that creates urgency or asks you to transfer money, then call the organisation back on its official number; (3) if in doubt, call a family member before clicking or paying. Install ScamShield on their phone and set conservative daily transfer limits with their bank.

Final Thoughts

Phishing attacks in Singapore will keep evolving, but the fundamentals of defence stay the same: slow down, verify independently, and never share your credentials or OTPs. Combine good personal habits with the security features already built into your bank apps, SingPass, and ScamShield, and you'll block the overwhelming majority of attacks before they cost you a cent. Share this guide with family members and colleagues — awareness is still the single most effective defence against phishing.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles