facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··10 min read

Phishing attacks in Singapore have evolved from clumsy email scams into sophisticated, multi-channel campaigns that drain bank accounts in minutes. In 2024 alone, Singaporeans lost over SGD 650 million to scams, with phishing consistently ranking among the top three attack vectors tracked by the Singapore Police Force and the Cyber Security Agency (CSA). From spoofed SingPass logins to fake DBS and OCBC SMS alerts, attackers are exploiting the trust Singaporeans place in local institutions.

This guide explains how phishing works in the Singapore context, the red flags to watch for, and the practical steps you can take to protect yourself, your family, and your business.

What Is Phishing?

Phishing is a type of social engineering attack where criminals impersonate trusted entities — banks, government agencies, delivery services, or employers — to trick victims into revealing sensitive information such as passwords, OTPs, credit card numbers, or SingPass credentials. The term covers email (phishing), SMS (smishing), voice calls (vishing), and messages sent through WhatsApp, Telegram, or social media.

In Singapore, phishing has become particularly dangerous because scammers often combine channels. A victim might receive an SMS that looks like it's from OCBC, click a link to a convincing fake login page, and then receive a phone call from a "bank officer" asking them to confirm an OTP — completing the attack within minutes.

Why Singapore Is a Prime Target

Singapore's high digital adoption, concentration of wealth, and widespread use of mobile banking make it an attractive target for cybercriminals. Several factors amplify the risk:

  • High smartphone penetration: Over 90% of Singaporeans use mobile banking apps, giving scammers a direct line to financial accounts.
  • PayNow and instant transfers: Money moves in seconds, leaving little time to reverse fraudulent transactions.
  • Trust in SMS alerts: Singaporeans are conditioned to trust SMS from banks and government agencies, which scammers exploit through sender ID spoofing.
  • Multilingual population: Attackers tailor messages in English, Mandarin, Malay, and Tamil to maximize reach.
  • Dense corporate environment: Business email compromise (BEC) targeting SMEs and MNCs has surged.

Common Types of Phishing Attacks in Singapore

1. SMS Phishing (Smishing)

Smishing remains the most prevalent attack vector in Singapore. Victims receive SMS messages impersonating DBS, OCBC, UOB, Singpost, IRAS, or ICA. A typical message reads: "DBS Alert: Unusual login detected. Verify your account immediately: hxxps://dbs-verify.co".

The Infocomm Media Development Authority (IMDA) introduced the SMS Sender ID Registry (SSIR) in 2023 to reduce spoofing, but attackers now use plain numeric sender IDs or hijack overseas gateways to bypass controls.

2. Fake Banking Websites

Scammers build pixel-perfect replicas of DBS iBanking, OCBC Digital, and UOB TMRW login pages. These sites often use lookalike domains like dbs-sg.com, ocbc-login.net, or uob-secure.co. Once credentials and OTPs are entered, attackers immediately initiate PayNow or FAST transfers.

3. SingPass Impersonation Scams

SingPass is the gateway to over 2,700 government and private services. Scammers send phishing emails or SMS claiming your SingPass is "suspended" or needs "re-verification," directing victims to fake login portals. Compromised SingPass accounts can be used to apply for loans, open bank accounts, or access CPF.

4. Parcel Delivery Scams

With e-commerce booming, fake Singpost, Ninja Van, J&T, and Shopee delivery notifications are widespread. Messages claim a parcel is "held at customs" and request a small fee — which captures credit card details for later large-scale fraud.

5. Job Scams on Telegram and WhatsApp

"Work from home" and "part-time task" scams often begin with phishing-style recruitment messages. Victims are lured into fake platforms where they "earn commissions" before being asked to top up funds that disappear.

6. Business Email Compromise (BEC)

BEC targets finance teams at Singapore SMEs. Attackers compromise or spoof executive email accounts and instruct staff to wire payments to fraudulent accounts, often citing M&A confidentiality.

Red Flags: How to Recognize a Phishing Attempt

Most phishing attempts share common warning signs. Train yourself to spot these before clicking:

  1. Urgency and fear: "Your account will be suspended in 24 hours" or "Unauthorized transaction detected."
  2. Unexpected links: Hover over links before clicking. Legitimate DBS links go to dbs.com.sg, not dbs-verify.xyz.
  3. Requests for OTPs or passwords: No Singapore bank, MAS, or government agency will ever ask you to share an OTP, PIN, or password.
  4. Grammatical errors or awkward phrasing: Though AI has made scams more polished, odd capitalization or unusual Singlish phrasing still appears.
  5. Mismatched sender details: An email signed "OCBC Bank" from a Gmail or outlook.com address is a scam.
  6. Attachments you didn't request: PDFs, .zip files, or Office documents from unknown senders often carry malware.
  7. Too-good-to-be-true offers: Lucky draws, GST vouchers, or "CDC refunds" requiring you to click a link.

Phishing Channels Compared

ChannelCommon ImpersonationRisk LevelPrimary Defense
SMS (Smishing)DBS, OCBC, UOB, Singpost, IRASVery HighNever click SMS links; use official apps
EmailMicrosoft 365, SingPass, employersHighVerify sender domain; check headers
Voice callsSPF, MAS, bank officers, ICAHighHang up and call official hotline
WhatsApp/TelegramRecruiters, friends, group adminsMedium-HighVerify identity through alternate channel
Social media adsShopee, Lazada, investment platformsMediumGo directly to official app or site

How to Verify Suspicious Links Safely

If you receive a shortened or unfamiliar URL, don't click it blindly. Instead:

  1. Preview the destination: Many legitimate URL shorteners, including Lunyb, allow users to preview the final destination before visiting. If you want to understand how trustworthy modern shorteners work, see our honest Lunyb review and our 2026 shortener buyer's guide.
  2. Use link scanners: Services like VirusTotal, URLScan.io, and Google Safe Browsing analyze URLs for malicious behavior.
  3. Check the domain carefully: Look for subtle misspellings like "dbs-sg.com" instead of "dbs.com.sg".
  4. Inspect the SSL certificate: HTTPS alone doesn't mean safe — phishing sites also use HTTPS. Click the padlock and verify the certificate owner.
  5. Open on a sandboxed device: If you must open a suspicious link, do so on a device without saved credentials.

Steps to Take If You've Been Phished

If you suspect you've fallen victim to a phishing attack in Singapore, act within minutes:

  1. Call your bank immediately. DBS: 1800-339-6963, OCBC: 1800-363-3333, UOB: 1800-222-2121. Request an immediate freeze on your accounts.
  2. Activate your Money Lock (available via DBS, OCBC, UOB apps) to prevent further digital transfers.
  3. Report to the Singapore Police Force via the ScamShield app, the anti-scam hotline (1799), or at police.gov.sg.
  4. Change your passwords for banking, SingPass, email, and any linked services. Use unique passwords for each.
  5. Revoke SingPass sessions and enable SingPass Face Verification if not already active.
  6. Scan your devices for malware using reputable antivirus software.
  7. Monitor your credit through the Credit Bureau Singapore for signs of fraudulent loan applications.

Proactive Protection: Building Your Personal Defense

Enable Multi-Factor Authentication Everywhere

Beyond SMS OTPs (which can be intercepted via SIM swapping), use app-based authenticators like Google Authenticator, Microsoft Authenticator, or hardware keys such as YubiKey for high-value accounts.

Use the ScamShield App

Developed by Open Government Products and the National Crime Prevention Council, ScamShield filters known scam calls and SMS. It's free on iOS and Android and should be installed on every Singaporean's phone.

Lock Down Your SingPass

Enable Face Verification, review authorized apps monthly, and set up SingPass notifications so you're alerted to every login attempt.

Separate Banking from Browsing

Consider using a dedicated device or browser profile exclusively for banking. This limits exposure to malicious scripts or browser extensions that could capture credentials.

Use Encrypted DNS

Services like Cloudflare's 1.1.1.1 for Families or Quad9 block known phishing and malware domains at the DNS level before your browser even loads them.

Keep Software Updated

Install OS, browser, and app updates promptly. Many phishing kits exploit known vulnerabilities that patches would otherwise close.

Protecting Your Business from Phishing in Singapore

SMEs and enterprises in Singapore face escalating phishing threats. The CSA's Cyber Essentials and Cyber Trust marks provide baseline frameworks. Key business controls include:

  • Email authentication: Implement SPF, DKIM, and DMARC with a reject policy to block spoofed emails impersonating your domain.
  • Security awareness training: Run quarterly simulated phishing campaigns. Measure click rates and provide targeted coaching.
  • Payment verification protocols: Require dual approval and callback verification for any wire transfer above a defined threshold.
  • Endpoint detection and response (EDR): Deploy modern EDR tools that detect credential theft and lateral movement.
  • Branded link management: Use branded short links so staff and customers can recognize legitimate URLs. Our comparison of Rebrandly and other branded link platforms outlines the options available.

Phishing vs. Other Common Scams in Singapore

Scam TypePrimary MethodTypical LossReporting Channel
PhishingFake sites capturing credentialsSGD 1K–100K+SPF, bank, ScamShield
Investment scamsFake trading platformsSGD 10K–500K+MAS, SPF
Job scamsFake tasks, commission top-upsSGD 500–50KMOM, SPF
Government impersonationFake SPF, ICA, IRAS callsSGD 5K–200K+Anti-Scam Hotline 1799
Love/romance scamsLong-term emotional groomingSGD 10K–1M+SPF

The Future of Phishing in Singapore

AI-generated phishing is already reshaping the threat landscape. Large language models produce flawless English, Mandarin, and Malay phishing messages at scale. Voice cloning allows scammers to impersonate family members or executives convincingly. Deepfake video calls have been used in a notable 2024 Hong Kong case where an employee transferred USD 25 million after a fake video meeting with "executives."

Singapore's response includes the Shared Responsibility Framework (SRF) rolled out by MAS in 2024, which allocates liability between banks, telcos, and consumers for phishing losses. However, prevention remains the most reliable defense. As attackers grow more sophisticated, user vigilance paired with layered technical controls — authenticators, DNS filtering, trusted link previews, and verified branded URLs — becomes essential.

Frequently Asked Questions

How do I report a phishing attack in Singapore?

Report to the Singapore Police Force via the Anti-Scam Hotline at 1799, through the ScamShield app, or at police.gov.sg/iwitness. For phishing SMS, forward the message to 7726 (SPAM) with your telco. If a bank account is affected, call your bank's 24/7 fraud hotline immediately before filing a police report.

Will my bank refund me if I was phished?

Under Singapore's Shared Responsibility Framework (effective December 2024), banks and telcos may bear losses if they failed in their duties — such as not sending real-time transaction alerts or allowing spoofed sender IDs. However, if you shared OTPs or credentials voluntarily, you may bear most of the loss. Act within minutes and document everything to improve your case.

Is clicking a phishing link enough to compromise my phone?

In most cases, simply clicking a link only loads a webpage — the real danger is entering credentials or downloading apps. However, some advanced attacks exploit browser vulnerabilities (zero-click or one-click exploits) to install spyware. Keep your OS and browser updated, and never install APK files from SMS links on Android.

How can I check if a URL is safe before clicking?

Use link scanners like VirusTotal, URLScan.io, or Google Safe Browsing. Hover over links to preview destinations, and look for subtle domain misspellings. Reputable URL shorteners offer link previews so you can see where a short link leads before visiting. Always type bank and government URLs directly rather than clicking links from messages.

What's the single most important habit to prevent phishing?

Never enter credentials or OTPs after clicking a link from an unsolicited SMS, email, or chat message. Always open your banking or SingPass app directly from your home screen. If a message claims urgent action is required, hang up and call the official hotline printed on the back of your bank card or on the organization's official website.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles