facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have become one of the most persistent cyber threats facing consumers, businesses, and government agencies. From fake SMSes impersonating DBS and OCBC to bogus SingPost delivery notifications and cloned IRAS tax refund pages, scammers are becoming increasingly sophisticated. According to the Singapore Police Force, phishing scams alone accounted for hundreds of millions of dollars in losses in recent years, and the numbers continue to climb.

This guide will help you recognise phishing attempts, understand the tactics used by attackers targeting Singaporeans, and adopt practical habits to protect yourself, your family, and your business.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a trusted entity, such as a bank, government agency, or well-known brand, to trick you into revealing sensitive information or performing an action that benefits the attacker. The goal is typically to steal login credentials, One-Time Passwords (OTPs), credit card details, NRIC numbers, or install malware on your device.

Phishing can be delivered through multiple channels:

  • Email phishing — fraudulent emails that look like they come from legitimate senders.
  • Smishing — phishing via SMS messages.
  • Vishing — voice phishing over phone calls, often using spoofed local numbers.
  • Quishing — malicious QR codes placed on posters, receipts, or emails.
  • Social media phishing — fake profiles or ads on Facebook, Instagram, and Telegram.

Why Singapore Is a Prime Target

Singapore's high digital adoption rate, mature banking infrastructure, and affluent population make it an attractive target for cybercriminals. A few reasons phishing thrives here:

  1. High banking penetration — Nearly every adult uses digital banking through DBS, OCBC, UOB, Standard Chartered, or Citibank, giving scammers a large pool of potential victims.
  2. Government digital services — Singaporeans routinely interact with SingPass, IRAS, CPF, and HDB online, making impersonation scams believable.
  3. E-commerce and delivery culture — With frequent parcel deliveries from Shopee, Lazada, and SingPost, fake delivery notifications feel routine.
  4. Multilingual population — Attackers craft messages in English, Mandarin, Malay, and Tamil to broaden their reach.
  5. Trust in authority — Singaporeans generally trust official communications, which scammers exploit by mimicking government tone and branding.

Common Phishing Scams in Singapore

1. Bank Impersonation Scams

The most damaging phishing scams in Singapore involve fake messages from local banks. Victims receive an SMS or email claiming unusual activity on their account, a locked card, or a pending fund transfer. The link leads to a near-perfect clone of the bank's login page. Once credentials and OTPs are entered, scammers drain the account within minutes.

2. Government Agency Scams (SingPass, IRAS, ICA, MOM)

Scammers impersonate MyInfo, IRAS tax refunds, ICA passport renewals, or MOM work pass notifications. Some claim you owe unpaid fines or are entitled to a rebate. The fake login page harvests SingPass credentials, which are then used to apply for loans or open accounts in your name.

3. Delivery and Parcel Scams

Fake SMSes from "SingPost", "Ninja Van", or "DHL" ask you to pay a small customs fee or reschedule delivery. The linked page collects card details and OTPs.

4. Job Scams on Telegram and WhatsApp

Victims receive unsolicited job offers promising easy commissions for reviewing hotels, liking videos, or completing tasks. These often escalate into requests for upfront payments or bank credentials.

5. Investment and Crypto Scams

Phishing pages mimic MAS-regulated brokers or crypto exchanges, luring victims with unrealistic returns. Deepfake videos of local celebrities and politicians have been used to promote these scams.

6. QR Code Scams (Quishing)

Recent cases in Singapore involved fraudulent QR codes stuck on bubble tea shops and F&B outlets, redirecting customers to fake survey pages that harvest banking credentials.

Red Flags: How to Spot a Phishing Attempt

Learning to identify phishing signals is your first line of defence. Watch out for these warning signs:

Red FlagWhat It Looks LikeWhy It's Suspicious
Urgent language"Your account will be suspended in 24 hours"Legitimate banks rarely threaten immediate account closure via SMS.
Suspicious senderEmail from "dbs-support@secure-alert.com"Official DBS emails come from @dbs.com domains only.
Shortened or odd URLsbit.ly/dbs-login or dbs-sg.verify-account.coBanks use their own verified domains, not third-party shorteners.
Requests for OTP"Please share the OTP sent to your phone"No legitimate bank or agency will ever ask for your OTP.
Generic greetings"Dear Valued Customer"Your bank knows your name and typically addresses you personally.
Spelling and grammar errors"Kindly to verify your acount immediately"Official Singapore communications are professionally proofread.
Unexpected attachmentsInvoice.zip, refund.exeAttachments from unknown senders often contain malware.

How to Protect Yourself from Phishing

1. Verify Before You Click

Never click links in unsolicited SMSes or emails. If your bank supposedly contacts you, open the official mobile app or type the URL manually into your browser. For SingPass or government agencies, log in directly via singpass.gov.sg.

2. Use the ScamShield App

Developed by the Singapore Police Force and Open Government Products, ScamShield blocks scam calls and filters suspicious SMSes. Install it on both iOS and Android.

3. Enable Money Lock and Transaction Limits

DBS, OCBC, and UOB now offer "Money Lock" features that ring-fence funds from digital transfers. Combine this with low daily transaction limits for extra safety.

4. Turn On Multi-Factor Authentication

Use app-based authenticators (Google Authenticator, Microsoft Authenticator) rather than SMS OTPs where possible. Biometric login through the bank's app adds another layer.

5. Inspect URLs Carefully

Hover over links before clicking. Watch for lookalike domains such as "dbs-sg.com" instead of "dbs.com.sg", or Unicode characters that mimic Latin letters. If you use a link management tool such as Lunyb to shorten and track your own links, you can also preview destinations before sharing them with customers or colleagues, reducing the risk of forwarding tampered URLs. For a broader look at trusted link tools, see our 2026 URL shortener buyer's guide.

6. Keep Software and Devices Updated

Enable automatic updates for iOS, Android, Windows, and macOS. Most phishing-related malware exploits known vulnerabilities that patches have already fixed.

7. Use Encrypted DNS and Secure Browsers

Switch to encrypted DNS services (such as Cloudflare 1.1.1.1 or Quad9) which block known phishing domains at the network level. Modern browsers like Brave, Firefox, and Chrome also warn you about deceptive sites.

8. Educate Family Members

Elderly parents and young children are prime targets. Have regular conversations about scams, and set up their devices with restricted transfer limits and scam-blocking apps.

What Businesses in Singapore Should Do

Small and medium enterprises (SMEs) are increasingly targeted through Business Email Compromise (BEC), where attackers impersonate suppliers or executives to redirect invoice payments. Protect your business with these steps:

  1. Deploy DMARC, SPF, and DKIM on your email domain to prevent spoofing.
  2. Train staff quarterly using simulated phishing exercises. CSA (Cyber Security Agency of Singapore) offers free SG Cyber Safe resources.
  3. Enforce dual approval for all fund transfers above a set threshold.
  4. Verify supplier bank changes by phone using a previously known number, never one provided in a new email.
  5. Log and monitor all outbound links shared in marketing campaigns. Reputable link platforms like Lunyb allow you to audit click activity and disable compromised links quickly.
  6. Adopt endpoint protection and keep an incident response plan ready.

What to Do If You've Been Phished

Speed matters. If you suspect you've fallen for a phishing attack, take these steps immediately:

  1. Call your bank's 24-hour fraud hotline. DBS: 1800 339 6963, OCBC: 1800 363 3333, UOB: 1800 222 2121. Request an immediate freeze on your accounts and cards.
  2. Change passwords for the compromised account and any others sharing that password, starting with your email and SingPass.
  3. Revoke active sessions in banking, SingPass, and email settings.
  4. Report to the police via the ScamShield helpline at 1799 or file a report at police.gov.sg.
  5. Report to CSA via SingCERT at csa.gov.sg if a business account or company system was affected.
  6. Scan your device for malware and consider a factory reset if you clicked an attachment.
  7. Alert your contacts if your email or social accounts were compromised, so they don't fall for follow-up scams.

Singapore's Legal and Regulatory Response

Singapore has significantly strengthened its anti-scam framework in recent years. The Protection from Scams Act, passed in 2025, empowers the police to issue restriction orders on the bank accounts of suspected scam victims to prevent further losses. The Shared Responsibility Framework introduced by MAS and IMDA outlines how banks and telcos share liability with victims of phishing scams, provided both parties met their prescribed duties.

The SMS Sender ID Registry (SSIR) now requires organisations to register their alphanumeric Sender IDs, so any SMS claiming to be from "DBS" or "IRAS" without registration is automatically flagged as "Likely-SCAM". This has already reduced smishing volumes significantly.

Building a Scam-Resistant Mindset

Technology alone cannot stop phishing. The most effective defence is a healthy scepticism: pause before you click, verify through official channels, and assume that any unsolicited message asking for action is suspicious until proven otherwise. Encourage this mindset in your household and workplace.

Also remember that scammers exploit emotion, urgency, greed, fear, and curiosity. If a message triggers a strong emotional response, that itself is a signal to slow down. Take a screenshot, check with a friend, or call the organisation directly using a number from their official website.

Frequently Asked Questions

How common are phishing attacks in Singapore?

Phishing is consistently one of the top scam types reported to the Singapore Police Force, with tens of thousands of cases each year. Losses regularly exceed hundreds of millions of dollars annually, making it one of the most financially damaging cybercrimes in the country.

Will my bank refund me if I fall for a phishing scam?

Under Singapore's Shared Responsibility Framework, banks and telcos may be required to compensate you if they failed in their duties, such as not blocking a scam SMS or not sending real-time transaction alerts. However, if you shared your OTP or credentials directly, recovery is not guaranteed. Report the incident immediately to maximise your chances.

How can I check if a link is safe before clicking?

Hover over the link on desktop to preview the URL. On mobile, long-press the link. Compare the domain against the official website of the organisation. You can also use link checkers like Google Safe Browsing, VirusTotal, or URLVoid to scan suspicious URLs before visiting them.

Are QR code scams really a threat in Singapore?

Yes. Several high-profile quishing cases have been reported at F&B outlets and public spaces, where scammers pasted fraudulent QR codes over legitimate ones. Always verify that a QR code hasn't been tampered with, and be cautious of any code that asks you to log in or enter banking details.

What should I do if I receive a suspicious SMS?

Do not click any links. Forward the message to 9SPF-SMS (97727677) to report it, or use the ScamShield app to flag it. Delete the message and, if possible, block the sender. If the message claims to be from your bank, contact the bank directly using the number printed on the back of your card.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles