facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have grown into one of the most damaging cybercrime categories in the country, costing victims hundreds of millions of dollars each year. From fake SingPost delivery texts to cloned DBS and OCBC login pages, scammers have become highly sophisticated at impersonating trusted local brands. This guide explains how phishing works in the Singapore context, how to recognise the warning signs, and the practical steps you can take to protect yourself, your family, and your business.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a legitimate person, brand, or authority to trick you into revealing sensitive information, such as passwords, OTPs, credit card numbers, or SingPass credentials. The stolen data is then used to drain bank accounts, hijack digital identities, or launch further attacks against your contacts.

In Singapore, the Singapore Police Force and the Cyber Security Agency (CSA) consistently rank phishing among the top scam typologies. According to the Singapore Police Force's annual scam statistics, phishing scams alone have accounted for tens of thousands of reported cases and losses exceeding S$100 million in recent years.

Why Singapore Is a Prime Target for Phishing

Singapore's high smartphone penetration, widespread digital banking adoption, and reliance on services like PayNow, SingPass, and MyInfo make it a lucrative target. Attackers exploit local trust in these systems by carefully cloning their look and feel.

Common Local Factors Attackers Exploit

  • Digital-first banking: Most Singaporeans manage banking entirely through mobile apps, making fake app alerts convincing.
  • Government service familiarity: Residents are used to receiving SMS from IRAS, MOM, ICA, and HDB, which scammers impersonate.
  • Delivery culture: Frequent e-commerce means fake SingPost, Ninja Van, and Shopee delivery messages blend in easily.
  • Multilingual environment: Attackers craft messages in English, Mandarin, Malay, and Tamil to widen their reach.

The Most Common Types of Phishing Attacks in Singapore

Understanding the categories of phishing helps you spot them faster. Below are the dominant forms currently affecting Singapore users.

1. SMS Phishing (Smishing)

Fake text messages remain the most common vector. They often claim your bank account is locked, a parcel is stuck at customs, or your SingPass has expired. The message includes a shortened or spoofed link that leads to a cloned login page.

2. Email Phishing

Emails pretending to be from DBS, OCBC, UOB, IRAS, or Microsoft 365 attempt to harvest corporate and personal credentials. Business Email Compromise (BEC) is a subset that specifically targets finance staff at SMEs.

3. Voice Phishing (Vishing)

Callers impersonate bank officers, police, or Ministry of Health staff. They pressure victims into transferring funds or disclosing OTPs, often using spoofed +65 numbers.

4. QR Code Phishing (Quishing)

Fake QR stickers placed over legitimate ones at hawker centres, bubble tea shops, or on "survey" flyers redirect users to malicious payment or login pages.

5. Social Media and Messaging App Scams

WhatsApp, Telegram, and Facebook Messenger are used to impersonate friends, offer fake job listings, or promote bogus investment platforms promising unrealistic returns.

Real Phishing Scenarios Singaporeans Encounter

Recognising real-world patterns makes theoretical advice practical. Here are examples inspired by actual reports.

The Fake Bank OTP Request

You receive an SMS: "DBS Alert: Unusual login detected from JB. Verify at dbs-secure-sg.com or your account will be suspended." The link mimics the real DBS site pixel-for-pixel, prompting you to enter your username, PIN, and OTP. Within minutes, funds are transferred to a mule account.

The Parcel Delivery Scam

An SMS claims a SingPost parcel cannot be delivered due to unpaid customs fees of S$1.20. The tiny amount lowers your guard, but entering your card details on the fake page hands attackers full card credentials for larger fraudulent charges later.

The Job Offer on WhatsApp

A stranger offers you a "part-time review job" paying S$200 daily. After a few small legitimate payouts, they ask you to top up to unlock higher commissions, which you never receive.

How to Recognise a Phishing Attempt

Most phishing messages share telltale signs. Train yourself to pause and check for the following indicators before clicking or replying.

Red Flags Checklist

  1. Urgency or fear: "Your account will be closed in 24 hours."
  2. Unexpected links: Especially shortened links from unknown senders or domains that only look similar to real ones (e.g., ocbc-verify.com instead of ocbc.com).
  3. Requests for OTPs or passwords: No legitimate Singapore bank or government agency will ever ask for these.
  4. Poor grammar or odd phrasing: Especially in messages claiming to come from official bodies.
  5. Generic greetings: "Dear Customer" instead of your name.
  6. Mismatched sender details: An email claiming to be from IRAS but sent from a Gmail address.
  7. Attachments you didn't request: Especially .zip, .exe, or macro-enabled Office files.

Comparison: Legitimate vs. Phishing Messages

AttributeLegitimate MessagePhishing Message
Sender IDRegistered SMS sender ID (e.g., "DBS", "OCBC") via SSIR registryUnknown mobile number or spoofed short code
LinksOfficial domain (dbs.com.sg, singpass.gov.sg)Look-alike domains, IP addresses, or URL shorteners
ToneInformational, no pressureUrgent, threatening, or too good to be true
RequestsDirects you to log in via the official appAsks for password, OTP, NRIC, or card details
PersonalisationUses your registered nameGeneric salutation

How to Avoid Phishing Attacks in Singapore

Prevention combines habit changes, technical protections, and using verified tools. Here is a layered defence approach.

1. Verify Before You Click

Never tap links in unsolicited SMS or email. Instead, open the official app or type the URL yourself. For government matters, always start at gov.sg or the official agency site.

2. Enable Money Lock and Transaction Limits

All major Singapore banks now offer a "Money Lock" feature that ring-fences part of your savings from digital transfers. Combine this with low daily transfer limits so a successful phishing attempt causes minimal damage.

3. Use Strong, Unique Passwords and 2FA

Use a password manager to generate unique passwords for every account. Enable two-factor authentication using an authenticator app or hardware key rather than SMS where possible.

4. Keep Devices and Apps Updated

Install iOS, Android, and browser updates promptly. The Singapore banking apps now use anti-malware scanning that blocks logins if sideloaded apps are detected—do not disable this protection.

5. Inspect Shortened Links Safely

Because attackers often disguise malicious destinations behind shortened URLs, use a trustworthy link-management platform that offers link previews and click analytics. Reputable shorteners such as Lunyb allow recipients to preview the destination before visiting, which helps you avoid blindly landing on a cloned bank page. For a broader comparison of safe options, see our 2026 buyer's guide to URL shorteners.

6. Use Encrypted DNS and a Secure Browser

Enable DNS-over-HTTPS in your browser or router. Combined with a privacy-focused browser that blocks known phishing domains, this adds a strong network-level filter before a malicious page even loads.

7. Register with ScamShield

The ScamShield app, developed by the National Crime Prevention Council and Open Government Products, filters known scam SMS and calls. It is free for both iOS and Android users in Singapore.

What to Do If You've Been Phished

Speed matters. Within the first hour, you can often limit or reverse the damage.

  1. Contact your bank immediately using the hotline printed on the back of your card. All three local banks have 24/7 fraud lines.
  2. Freeze your accounts and cards through the mobile app's kill switch feature.
  3. Change passwords for the compromised account and any other account sharing that password.
  4. Report to the Singapore Police Force via the ScamShield helpline at 1799 or file an e-report at police.gov.sg.
  5. Report the phishing site to the Singapore Cyber Emergency Response Team (SingCERT) so it can be taken down.
  6. Notify affected contacts if the attacker gained access to your email or messaging accounts.

Protecting Your Business from Phishing

SMEs in Singapore are increasingly targeted because they hold valuable customer data but often lack dedicated security teams.

Essential Business Controls

  • Email authentication: Deploy SPF, DKIM, and DMARC to stop attackers from spoofing your domain.
  • Staff training: Conduct simulated phishing exercises quarterly.
  • Least-privilege access: Ensure employees only access systems relevant to their role.
  • Endpoint protection: Use reputable EDR software on all company devices.
  • Branded link management: Sending customers links from a recognisable, verified branded domain (rather than a raw or unknown short link) reduces the chance they fall for impersonation. Learn more in our Rebrandly review or the shortener comparison guide.

The Role of Awareness and Community Reporting

Phishing thrives on isolation. Talking openly about scam attempts—whether in family chats, workplace channels, or community groups—strengthens collective defence. The Singapore government's "I can ACT against scams" campaign encourages residents to Add security features, Check for signs, and Tell the authorities and others.

Elderly relatives and new residents unfamiliar with local brands are especially vulnerable. A quick weekly conversation about the latest scam trend can prevent tragic financial loss.

Frequently Asked Questions

How do I report a phishing SMS in Singapore?

Forward the SMS to 9OSCAMS (that is, 96726267), the official ScamShield reporting number, or report it through the ScamShield app. You can also file a police report online at police.gov.sg if money was lost.

Will my bank refund me if I fall for a phishing scam?

Under Singapore's Shared Responsibility Framework (SRF), which took effect in 2024, banks and telcos may bear liability if they fail their prescribed duties. However, if you willingly disclosed OTPs or credentials, recovery is not guaranteed. Report the incident within minutes to maximise your chances.

Are shortened links always dangerous?

No. Shortened links are simply redirects and can be perfectly safe when created by trusted platforms with link previews, malware scanning, and analytics. The risk arises when an unknown sender uses a shortener to hide a suspicious destination. Always preview the final URL before clicking.

What is the difference between phishing and smishing?

Phishing is the umbrella term for social-engineering attacks that trick victims into revealing information. Smishing specifically refers to phishing carried out via SMS, while vishing refers to voice-call phishing and quishing refers to malicious QR codes.

How can I check if a website is a phishing site?

Check the URL carefully for misspellings, look for a valid HTTPS certificate issued to the correct organisation, and paste the domain into Google Safe Browsing or VirusTotal. When in doubt, close the tab and access the service via its official app instead.

Final Thoughts

Phishing attacks in Singapore are not going away—they are evolving to exploit new services, payment rails, and AI-generated content. The good news is that awareness combined with a few technical safeguards blocks the vast majority of attempts. Verify every link, protect your credentials with 2FA, use safe link-management tools, and report suspicious activity quickly. By making these habits second nature, you turn yourself from an easy target into a hardened one, and you help protect the wider Singapore community at the same time.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles