Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore have become one of the most persistent cyber threats facing consumers, businesses, and government agencies. From fake SMSes impersonating DBS and OCBC to bogus SingPost delivery notifications and cloned IRAS tax refund pages, scammers are becoming increasingly sophisticated. According to the Singapore Police Force, phishing scams alone accounted for hundreds of millions of dollars in losses in recent years, and the numbers continue to climb.
This guide will help you recognise phishing attempts, understand the tactics used by attackers targeting Singaporeans, and adopt practical habits to protect yourself, your family, and your business.
What Are Phishing Attacks?
Phishing is a form of social engineering where attackers impersonate a trusted entity, such as a bank, government agency, or well-known brand, to trick you into revealing sensitive information or performing an action that benefits the attacker. The goal is typically to steal login credentials, One-Time Passwords (OTPs), credit card details, NRIC numbers, or install malware on your device.
Phishing can be delivered through multiple channels:
- Email phishing — fraudulent emails that look like they come from legitimate senders.
- Smishing — phishing via SMS messages.
- Vishing — voice phishing over phone calls, often using spoofed local numbers.
- Quishing — malicious QR codes placed on posters, receipts, or emails.
- Social media phishing — fake profiles or ads on Facebook, Instagram, and Telegram.
Why Singapore Is a Prime Target
Singapore's high digital adoption rate, mature banking infrastructure, and affluent population make it an attractive target for cybercriminals. A few reasons phishing thrives here:
- High banking penetration — Nearly every adult uses digital banking through DBS, OCBC, UOB, Standard Chartered, or Citibank, giving scammers a large pool of potential victims.
- Government digital services — Singaporeans routinely interact with SingPass, IRAS, CPF, and HDB online, making impersonation scams believable.
- E-commerce and delivery culture — With frequent parcel deliveries from Shopee, Lazada, and SingPost, fake delivery notifications feel routine.
- Multilingual population — Attackers craft messages in English, Mandarin, Malay, and Tamil to broaden their reach.
- Trust in authority — Singaporeans generally trust official communications, which scammers exploit by mimicking government tone and branding.
Common Phishing Scams in Singapore
1. Bank Impersonation Scams
The most damaging phishing scams in Singapore involve fake messages from local banks. Victims receive an SMS or email claiming unusual activity on their account, a locked card, or a pending fund transfer. The link leads to a near-perfect clone of the bank's login page. Once credentials and OTPs are entered, scammers drain the account within minutes.
2. Government Agency Scams (SingPass, IRAS, ICA, MOM)
Scammers impersonate MyInfo, IRAS tax refunds, ICA passport renewals, or MOM work pass notifications. Some claim you owe unpaid fines or are entitled to a rebate. The fake login page harvests SingPass credentials, which are then used to apply for loans or open accounts in your name.
3. Delivery and Parcel Scams
Fake SMSes from "SingPost", "Ninja Van", or "DHL" ask you to pay a small customs fee or reschedule delivery. The linked page collects card details and OTPs.
4. Job Scams on Telegram and WhatsApp
Victims receive unsolicited job offers promising easy commissions for reviewing hotels, liking videos, or completing tasks. These often escalate into requests for upfront payments or bank credentials.
5. Investment and Crypto Scams
Phishing pages mimic MAS-regulated brokers or crypto exchanges, luring victims with unrealistic returns. Deepfake videos of local celebrities and politicians have been used to promote these scams.
6. QR Code Scams (Quishing)
Recent cases in Singapore involved fraudulent QR codes stuck on bubble tea shops and F&B outlets, redirecting customers to fake survey pages that harvest banking credentials.
Red Flags: How to Spot a Phishing Attempt
Learning to identify phishing signals is your first line of defence. Watch out for these warning signs:
| Red Flag | What It Looks Like | Why It's Suspicious |
|---|---|---|
| Urgent language | "Your account will be suspended in 24 hours" | Legitimate banks rarely threaten immediate account closure via SMS. |
| Suspicious sender | Email from "dbs-support@secure-alert.com" | Official DBS emails come from @dbs.com domains only. |
| Shortened or odd URLs | bit.ly/dbs-login or dbs-sg.verify-account.co | Banks use their own verified domains, not third-party shorteners. |
| Requests for OTP | "Please share the OTP sent to your phone" | No legitimate bank or agency will ever ask for your OTP. |
| Generic greetings | "Dear Valued Customer" | Your bank knows your name and typically addresses you personally. |
| Spelling and grammar errors | "Kindly to verify your acount immediately" | Official Singapore communications are professionally proofread. |
| Unexpected attachments | Invoice.zip, refund.exe | Attachments from unknown senders often contain malware. |
How to Protect Yourself from Phishing
1. Verify Before You Click
Never click links in unsolicited SMSes or emails. If your bank supposedly contacts you, open the official mobile app or type the URL manually into your browser. For SingPass or government agencies, log in directly via singpass.gov.sg.
2. Use the ScamShield App
Developed by the Singapore Police Force and Open Government Products, ScamShield blocks scam calls and filters suspicious SMSes. Install it on both iOS and Android.
3. Enable Money Lock and Transaction Limits
DBS, OCBC, and UOB now offer "Money Lock" features that ring-fence funds from digital transfers. Combine this with low daily transaction limits for extra safety.
4. Turn On Multi-Factor Authentication
Use app-based authenticators (Google Authenticator, Microsoft Authenticator) rather than SMS OTPs where possible. Biometric login through the bank's app adds another layer.
5. Inspect URLs Carefully
Hover over links before clicking. Watch for lookalike domains such as "dbs-sg.com" instead of "dbs.com.sg", or Unicode characters that mimic Latin letters. If you use a link management tool such as Lunyb to shorten and track your own links, you can also preview destinations before sharing them with customers or colleagues, reducing the risk of forwarding tampered URLs. For a broader look at trusted link tools, see our 2026 URL shortener buyer's guide.
6. Keep Software and Devices Updated
Enable automatic updates for iOS, Android, Windows, and macOS. Most phishing-related malware exploits known vulnerabilities that patches have already fixed.
7. Use Encrypted DNS and Secure Browsers
Switch to encrypted DNS services (such as Cloudflare 1.1.1.1 or Quad9) which block known phishing domains at the network level. Modern browsers like Brave, Firefox, and Chrome also warn you about deceptive sites.
8. Educate Family Members
Elderly parents and young children are prime targets. Have regular conversations about scams, and set up their devices with restricted transfer limits and scam-blocking apps.
What Businesses in Singapore Should Do
Small and medium enterprises (SMEs) are increasingly targeted through Business Email Compromise (BEC), where attackers impersonate suppliers or executives to redirect invoice payments. Protect your business with these steps:
- Deploy DMARC, SPF, and DKIM on your email domain to prevent spoofing.
- Train staff quarterly using simulated phishing exercises. CSA (Cyber Security Agency of Singapore) offers free SG Cyber Safe resources.
- Enforce dual approval for all fund transfers above a set threshold.
- Verify supplier bank changes by phone using a previously known number, never one provided in a new email.
- Log and monitor all outbound links shared in marketing campaigns. Reputable link platforms like Lunyb allow you to audit click activity and disable compromised links quickly.
- Adopt endpoint protection and keep an incident response plan ready.
What to Do If You've Been Phished
Speed matters. If you suspect you've fallen for a phishing attack, take these steps immediately:
- Call your bank's 24-hour fraud hotline. DBS: 1800 339 6963, OCBC: 1800 363 3333, UOB: 1800 222 2121. Request an immediate freeze on your accounts and cards.
- Change passwords for the compromised account and any others sharing that password, starting with your email and SingPass.
- Revoke active sessions in banking, SingPass, and email settings.
- Report to the police via the ScamShield helpline at 1799 or file a report at police.gov.sg.
- Report to CSA via SingCERT at csa.gov.sg if a business account or company system was affected.
- Scan your device for malware and consider a factory reset if you clicked an attachment.
- Alert your contacts if your email or social accounts were compromised, so they don't fall for follow-up scams.
Singapore's Legal and Regulatory Response
Singapore has significantly strengthened its anti-scam framework in recent years. The Protection from Scams Act, passed in 2025, empowers the police to issue restriction orders on the bank accounts of suspected scam victims to prevent further losses. The Shared Responsibility Framework introduced by MAS and IMDA outlines how banks and telcos share liability with victims of phishing scams, provided both parties met their prescribed duties.
The SMS Sender ID Registry (SSIR) now requires organisations to register their alphanumeric Sender IDs, so any SMS claiming to be from "DBS" or "IRAS" without registration is automatically flagged as "Likely-SCAM". This has already reduced smishing volumes significantly.
Building a Scam-Resistant Mindset
Technology alone cannot stop phishing. The most effective defence is a healthy scepticism: pause before you click, verify through official channels, and assume that any unsolicited message asking for action is suspicious until proven otherwise. Encourage this mindset in your household and workplace.
Also remember that scammers exploit emotion, urgency, greed, fear, and curiosity. If a message triggers a strong emotional response, that itself is a signal to slow down. Take a screenshot, check with a friend, or call the organisation directly using a number from their official website.
Frequently Asked Questions
How common are phishing attacks in Singapore?
Phishing is consistently one of the top scam types reported to the Singapore Police Force, with tens of thousands of cases each year. Losses regularly exceed hundreds of millions of dollars annually, making it one of the most financially damaging cybercrimes in the country.
Will my bank refund me if I fall for a phishing scam?
Under Singapore's Shared Responsibility Framework, banks and telcos may be required to compensate you if they failed in their duties, such as not blocking a scam SMS or not sending real-time transaction alerts. However, if you shared your OTP or credentials directly, recovery is not guaranteed. Report the incident immediately to maximise your chances.
How can I check if a link is safe before clicking?
Hover over the link on desktop to preview the URL. On mobile, long-press the link. Compare the domain against the official website of the organisation. You can also use link checkers like Google Safe Browsing, VirusTotal, or URLVoid to scan suspicious URLs before visiting them.
Are QR code scams really a threat in Singapore?
Yes. Several high-profile quishing cases have been reported at F&B outlets and public spaces, where scammers pasted fraudulent QR codes over legitimate ones. Always verify that a QR code hasn't been tampered with, and be cautious of any code that asks you to log in or enter banking details.
What should I do if I receive a suspicious SMS?
Do not click any links. Forward the message to 9SPF-SMS (97727677) to report it, or use the ScamShield app to flag it. Delete the message and, if possible, block the sender. If the message claims to be from your bank, contact the bank directly using the number printed on the back of your card.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Zero Trust Security Model Explained Simply: A 2026 Guide
Zero Trust flips traditional cybersecurity on its head with a simple rule: never trust, always verify. This guide breaks down the Zero Trust security model in plain language, explains its core principles, and shows how organizations of any size can start implementing it.
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication adds a critical second layer of security beyond passwords, blocking over 99.9% of automated account attacks. Learn how 2FA works, which methods are most secure, and how to enable it on your most important accounts in 2026.
Password Manager vs Browser Passwords: Which Is Safer in 2026?
Browser-saved passwords are convenient, but dedicated password managers offer far stronger security, cross-platform support, and phishing protection. Here's how the two compare in 2026 — and when each option makes sense.
Data Breaches 2026: What You Need to Know
Data breaches in 2026 are faster and more sophisticated, driven by AI-powered phishing and supply-chain attacks. This guide covers the biggest trends, how modern breaches unfold, and practical steps individuals and businesses can take to stay protected.