facebook-pixel

Phishing Attacks in Singapore: Recognize and Avoid Them in 2026

L
Lunyb Security Team
··9 min read

Phishing attacks in Singapore have evolved from clumsy misspelt emails into sophisticated, multi-channel scams that cost victims millions of dollars each year. According to the Singapore Police Force's Annual Scams and Cybercrime Brief, scam-related losses continue to climb, with phishing consistently ranking among the top three scam typologies. Whether you are a DBS customer, a Singpass user, or someone who occasionally buys concert tickets online, understanding how phishing works in the local context is now a basic digital survival skill.

This guide breaks down the specific phishing tactics targeting Singapore residents in 2026, how to spot them in real time, and what to do if you have already clicked a suspicious link.

What Are Phishing Attacks?

Phishing is a form of social engineering where attackers impersonate a trusted organisation to trick you into revealing sensitive information such as passwords, OTPs, credit card numbers, or Singpass credentials. The attack typically arrives through email, SMS (smishing), phone calls (vishing), WhatsApp, or fake websites that closely mimic legitimate ones.

In Singapore, phishing attacks are particularly effective because scammers exploit the country's high digital adoption. With almost every resident using PayNow, Singpass, and mobile banking apps daily, a single moment of inattention can drain a bank account within minutes.

Why Singapore Is a Prime Target

  • High digital banking penetration: Over 90% of adults use mobile banking.
  • Widespread Singpass usage: A single compromised Singpass account gives access to government, healthcare, and financial services.
  • Multilingual population: Scammers craft messages in English, Mandarin, Malay, and Tamil to widen their net.
  • Strong purchasing power: Higher average account balances make each successful attack more profitable.

Common Types of Phishing Attacks in Singapore

Local scammers have refined their playbook. Here are the most prevalent categories reported by the Singapore Police Force, MAS, and the Cyber Security Agency of Singapore (CSA) in recent years.

1. Bank Impersonation Scams (DBS, OCBC, UOB)

The infamous OCBC phishing incident of 2021-2022, which cost victims over S$13 million, set a template that scammers still use today. Victims receive an SMS claiming their account is locked, containing a link to a fake bank login page. Once credentials and OTPs are entered, funds are transferred out within minutes.

2. Singpass Phishing

Fake Singpass login pages are used to hijack accounts, which are then leveraged to open bank accounts, apply for loans, or commit identity fraud. Legitimate Singpass communication never asks you to log in via an SMS or email link.

3. Parcel Delivery Scams (SingPost, Ninja Van, J&T)

You receive an SMS saying your parcel could not be delivered and requesting a small "redelivery fee" of S$1 or S$2. The tiny amount is a psychological trick; the real goal is to capture your card details for larger unauthorised charges.

4. Government Impersonation (IRAS, MOH, ICA)

Scammers pose as tax officers claiming you owe GST, or as ICA officers threatening deportation. These often start with a robocall in Mandarin, then escalate to a phishing link or a fraudulent bank transfer request.

5. Job Scams via WhatsApp and Telegram

Victims are offered easy "part-time" jobs liking videos or reviewing hotels. After a few small payouts to build trust, they are asked to "top up" to unlock higher commissions - and the money disappears.

6. Investment and Cryptocurrency Phishing

Fake investment platforms mimic Binance, MAS-licensed brokers, or well-known local finfluencers. Users are directed to counterfeit trading dashboards that show fake profits until they try to withdraw.

How to Recognize a Phishing Attempt

Modern phishing messages are polished, but they still leave fingerprints. Here is a checklist you can run through in under 30 seconds.

  1. Check the sender ID. Since 2023, all legitimate SMS from registered Singapore organisations must use the SMS Sender ID Registry. Any SMS from a mobile number claiming to be a bank is almost certainly a scam.
  2. Hover before you click. On desktop, hover over links to see the real URL. On mobile, long-press. Watch for lookalike domains like dbs-sg-secure.com or singpass-verify.net.
  3. Look for urgency and fear. "Your account will be closed in 24 hours" is a classic pressure tactic.
  4. Verify unusual requests. No bank, MAS, or government agency will ever ask for your full password, PIN, or OTP.
  5. Spot generic greetings. "Dear Customer" instead of your name is a red flag, though targeted (spear) phishing may include real details.
  6. Inspect the domain carefully. The real DBS site is dbs.com.sg, not dbs-com.sg or dbs.secure-login.com.

Phishing Red Flags Comparison Table

Signal Legitimate Message Phishing Message
Sender ID Registered name (e.g. DBS, OCBC, gov.sg) Random mobile number or lookalike ID
Link Domain Official domain (dbs.com.sg, singpass.gov.sg) Misspelt or subdomain trick (dbs-sg.com)
Request Type Informational, directs to app Asks for OTP, password, or card details
Tone Neutral, informative Urgent, threatening, or too-good-to-be-true
Grammar Professional, consistent Odd phrasing, mixed languages, typos

How to Protect Yourself from Phishing in Singapore

Prevention is far cheaper than recovery. The following practical steps combine tools already available to Singapore residents with universal security hygiene.

1. Enable the Money Lock Feature

DBS, OCBC, UOB, and other MAS-regulated banks now offer a "Money Lock" that ring-fences a portion of your funds so they cannot be transferred digitally, even if scammers gain access. Consider locking your emergency savings.

2. Use the ScamShield App

Developed by the Singapore Police Force and Open Government Products, ScamShield filters known scam SMS and calls. Install it from the App Store or Google Play and enable the SMS filter.

3. Turn On Two-Factor Authentication (2FA)

Use app-based authenticators such as Google Authenticator or hardware keys like YubiKey rather than SMS-based OTPs where possible. SMS OTPs can be intercepted or socially engineered.

4. Verify Short Links Before Clicking

Shortened links are a common phishing tool because they hide the real destination. Before clicking any shortened URL, expand it using a link-preview service or a trusted shortener platform. Reputable shorteners like Lunyb provide analytics and transparent link previews so recipients know exactly where they are going - a stark contrast to random bit.ly links pasted in unsolicited SMS. If you build your own campaigns, using a trustworthy shortener also protects your brand reputation. Learn more in our honest Lunyb review.

5. Use Encrypted DNS and a Secure Browser

Enable encrypted DNS (DNS over HTTPS) in Chrome, Firefox, or your device settings using providers like Cloudflare (1.1.1.1) or Quad9. This blocks connections to many known phishing domains at the network level, before the page even loads.

6. Keep Software and Apps Updated

Most successful phishing follow-ups exploit outdated browsers or banking apps. Enable auto-updates on iOS, Android, Windows, and macOS.

7. Separate Banking from Daily Browsing

Consider using a dedicated device or user profile purely for banking and Singpass. This drastically reduces the chance that a compromised browser session leaks credentials.

What to Do If You've Been Phished

Speed matters. If funds are transferred out, the first hour is critical.

  1. Call your bank immediately. Use the 24/7 anti-scam hotline printed on the back of your card - not any number from the suspicious message.
    • DBS/POSB: 1800-339-6963
    • OCBC: 1800-363-3333
    • UOB: 1800-222-2121
  2. Call the Anti-Scam Helpline: 1800-722-6688 (operated by NCPC and SPF).
  3. Freeze your Singpass via the Singpass app or singpass.gov.sg.
  4. File a police report at police.gov.sg or any Neighbourhood Police Centre. A report is required for insurance claims and disputes.
  5. Change all passwords for affected accounts and any that share the same password.
  6. Monitor your credit via the Credit Bureau Singapore for unauthorised loan applications.
  7. Report the scam to ScamShield to help protect others.

Phishing Trends to Watch in 2026

Attackers innovate quickly. Here is what Singapore users should watch out for this year.

AI-Generated Voice Scams (Deepfake Vishing)

Scammers can now clone a family member's voice from a 10-second social media clip and call you claiming to be in trouble. Agree on a family "safe word" that only relatives know.

QR Code Phishing ("Quishing")

Malicious QR codes are being stuck over legitimate ones at hawker centres, parking machines, and event posters. Always verify the URL your camera decodes before proceeding to payment.

Multi-Channel Attacks

A single scam may now start with an email, follow up with a WhatsApp message, and end with a phone call from someone posing as a "bank fraud officer." The consistency across channels makes victims lower their guard.

Compromised Legitimate Accounts

Increasingly, phishing messages come from hacked friends' WhatsApp or Telegram accounts, making them extremely convincing. Always verify unusual money requests through a separate channel like a phone call.

Pros and Cons of Common Anti-Phishing Measures

Pros

  • ScamShield and Money Lock are free and government-endorsed.
  • Hardware 2FA keys offer near-total protection against credential theft.
  • Encrypted DNS blocks entire categories of phishing domains passively.
  • Dedicated banking devices dramatically reduce attack surface.

Cons

  • ScamShield cannot filter every new scam number in real time.
  • Money Lock reduces liquidity and requires branch visits to unlock.
  • Hardware keys cost S$50-S$80 each and are not supported by every service.
  • User education remains the weakest link - no tool replaces vigilance.

FAQ: Phishing Attacks in Singapore

Will my bank refund me if I fall for a phishing scam?

Under the Shared Responsibility Framework (SRF) that took effect in December 2024, banks and telcos may be liable if they failed in their duties (e.g., not sending real-time alerts). However, if you willingly gave away your OTP or credentials, recovery is not guaranteed. Reporting within the first hour maximises the chance of freezing outgoing funds.

How do I check if a website is a real Singapore bank?

Type the URL manually into your browser (e.g., dbs.com.sg, ocbc.com, uob.com.sg). Check for HTTPS and a valid certificate issued to the bank's registered entity. Better yet, use the official mobile app rather than a browser.

Is it safe to click short links from strangers?

No. Any unexpected short link, especially one requesting payment or login, should be treated as suspicious. Use a link expander or a reputable shortening service that shows previews. For safe link-sharing practices, see our 2026 buyer's guide to URL shorteners.

What is the Singapore Anti-Scam Command?

The Anti-Scam Command (ASCom) is a dedicated Singapore Police Force unit that works with banks, telcos, and online platforms to trace, freeze, and recover scam-related funds. You can reach them via 1800-722-6688 or by filing a report at police.gov.sg.

Can antivirus software prevent phishing?

Modern security suites (Bitdefender, Kaspersky, Malwarebytes) include web-protection modules that block many phishing domains, but they are not foolproof against newly registered scam sites. Combine antivirus with browser-level protections, encrypted DNS, and human vigilance.

Final Thoughts

Phishing attacks in Singapore are not going away - they are becoming more localised, more polished, and more multi-channel. The good news is that most scams still rely on the same emotional triggers: urgency, fear, and greed. By slowing down, verifying independently, and layering tools like ScamShield, Money Lock, encrypted DNS, and trusted link services, you can dramatically reduce your risk.

Share this guide with parents, grandparents, and friends. In Singapore's tightly connected digital economy, one person's caution helps protect an entire network.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles