facebook-pixel

Phishing Attacks in Singapore: How to Recognize and Avoid Them

L
Lunyb Security Team
··11 min read

Phishing attacks in Singapore have evolved from clumsy email scams into sophisticated, multi-channel operations that cost victims hundreds of millions of dollars each year. According to the Singapore Police Force's Annual Scams and Cybercrime Brief, scam-related losses hit record highs in recent years, with phishing consistently ranking among the top three threats affecting consumers and businesses alike.

Whether you bank with DBS, use PayNow daily, or receive SingPass notifications on your phone, understanding how modern phishing works is no longer optional. This guide walks you through the most common phishing tactics targeting Singaporeans, how to recognize them in real time, and the practical steps you can take to protect yourself, your family, and your business.

What Is Phishing and Why Singapore Is a Prime Target

Phishing is a form of social engineering where attackers impersonate trusted organizations to trick victims into revealing credentials, authorizing payments, or installing malicious software. Singapore is particularly attractive to phishing operators for several reasons.

The city-state has one of the highest smartphone penetration rates in the world, near-universal digital banking adoption, and widespread use of government digital services like SingPass and MyInfo. High average incomes and dense use of QR-code payments create a rich target environment. Attackers also know that Singaporeans frequently receive legitimate SMS alerts from banks, government agencies, and delivery services, which makes malicious messages easier to blend in.

The Scale of the Problem

Recent data from the Singapore Police Force and the Cyber Security Agency of Singapore (CSA) shows that phishing scams, e-commerce scams, and job scams dominate the complaints list. Losses from phishing alone regularly exceed S$100 million per year, with individual victims sometimes losing their entire life savings in a single incident.

Common Types of Phishing Attacks Targeting Singaporeans

Phishing is no longer limited to email. Attackers now use SMS, voice calls, messaging apps, and even physical QR codes. Here are the most prevalent variants circulating in Singapore today.

1. SMS Phishing (Smishing)

Smishing uses text messages to impersonate banks, telcos, SingPost, or government agencies. A typical message might read: "DBS Alert: Suspicious login detected. Verify now at dbs-verify-sg.com or your account will be frozen." The link leads to a near-perfect replica of the real banking login page.

Singapore responded to this threat with the SMS Sender ID Registry (SSIR), which blocks unregistered sender IDs. However, attackers have adapted by using plain mobile numbers, overseas gateways, and even Rich Communication Services (RCS) messages.

2. Voice Phishing (Vishing)

In vishing attacks, scammers call pretending to be from the Immigration & Checkpoints Authority (ICA), Inland Revenue Authority of Singapore (IRAS), the police, or a bank's fraud department. They often use spoofed local numbers and claim the victim is implicated in money laundering, has an unpaid tax bill, or needs to "verify" a transaction. Victims are pressured to transfer funds or share One-Time Passwords (OTPs).

3. Email Phishing

Traditional email phishing remains common, particularly against businesses. Attackers impersonate suppliers, Microsoft 365 login prompts, DHL or FedEx delivery notifications, and HR systems. Business Email Compromise (BEC), where attackers impersonate a CEO or CFO to authorize fraudulent wire transfers, has caused some of the largest single losses in Singapore's corporate sector.

4. Messaging App Scams (WhatsApp, Telegram)

Takeover scams on WhatsApp are rampant. An attacker who has compromised one account messages the victim's contacts claiming to need an OTP "sent to the wrong number." Once provided, the attacker hijacks the victim's own WhatsApp account and repeats the cycle.

5. QR Code Phishing (Quishing)

Quishing involves placing malicious QR codes on physical surfaces, menus, parking meters, or inside fake flyers. Scanning the code sends the victim to a fake PayNow or payment page. A high-profile case in Singapore involved QR stickers placed on bubble tea shop surveys that led to victims losing six-figure sums.

6. Malicious Android App Downloads

One of the most damaging trends in Singapore has been scams that convince victims to sideload Android APK files, often disguised as food-ordering apps, pet-grooming services, or Lunar New Year promotions. These apps request accessibility permissions and silently drain bank accounts.

How to Recognize a Phishing Attempt

Modern phishing is polished, but almost every attack contains at least one of the warning signs below. Train yourself to pause and check whenever you see them.

Red Flags in Messages and Emails

  1. Urgency or fear: "Your account will be frozen in 24 hours." Legitimate banks rarely use such ultimatums over SMS.
  2. Unexpected links: Any link asking you to log in, verify identity, or reset a password that you did not initiate.
  3. Mismatched domains: dbs-sg-verify.com, singpass-login.net, or iras-refund.sg are not official domains. Real government sites end in .gov.sg.
  4. Requests for OTPs or passwords: No legitimate bank, government agency, or company employee will ever ask for your OTP.
  5. Generic greetings: "Dear Customer" instead of your name, though sophisticated attacks now personalize messages using leaked data.
  6. Grammar and spelling errors: Less common now with AI-generated text, but still a signal when present.
  7. Requests to install an app from outside the Play Store or App Store.

Red Flags in Phone Calls

  • Caller claims to be from a government agency and threatens arrest or deportation.
  • You are asked to transfer money to a "safe account" for investigation.
  • Pressure to stay on the line and not tell anyone, including family.
  • Caller already knows personal details, used to build false credibility.

A Quick Comparison of Phishing Channels

Different channels require slightly different defenses. The table below summarizes what to watch for in each.

Channel Common Impersonation Primary Risk Best Defense
SMS Banks, SingPost, ICA, telcos Credential theft via fake login pages Never tap links in SMS; open the app directly
Email Microsoft 365, DHL, suppliers, CEOs Account takeover, wire fraud Verify sender domain, use MFA, confirm by phone
Voice Call Police, IRAS, bank fraud team Coerced transfers, OTP disclosure Hang up and call the official number yourself
WhatsApp Friends, family, bosses Account takeover, money requests Enable 2-step verification; verify voice-to-voice
QR Codes PayNow merchants, surveys Malicious app installation, payment fraud Preview the URL before opening; avoid random QR codes

How to Verify a Suspicious Link Safely

If you are unsure whether a link is genuine, do not click it. Instead, follow these verification steps.

  1. Long-press the link on mobile to preview the full URL before opening.
  2. Check the exact domain, reading from right to left. The real domain is the part immediately before .com, .sg, or .gov.sg.
  3. Expand shortened links using a trusted link preview tool before visiting. A reputable shortener like Lunyb provides transparent link information and analytics so recipients can see where a link truly leads. You can read more in our honest review of Lunyb.
  4. Open the official app or website manually rather than clicking the link. For banks, use the mobile app directly. For government services, type singpass.gov.sg into your browser.
  5. Report the message to ScamShield (scamshield.gov.sg) and your telco by forwarding SMS to 7726.

Protecting Yourself: Practical Steps for Individuals

Technology alone will not stop phishing. A combination of secure habits, device settings, and awareness is the strongest defense.

Enable Strong Authentication

  • Turn on Multi-Factor Authentication (MFA) for every account that offers it, especially email, banking, SingPass, and social media.
  • Prefer app-based authenticators (Google Authenticator, Microsoft Authenticator) or hardware keys over SMS-based OTPs when possible.
  • Set up biometric login on your banking apps and use the Money Lock feature offered by DBS, OCBC, and UOB to ring-fence savings from any digital transfer.

Harden Your Devices

  • Install the ScamShield app from the Singapore government. It blocks known scam calls and SMS automatically.
  • Keep your operating system and apps updated. Patches close vulnerabilities that phishing malware exploits.
  • On Android, disable installation of apps from unknown sources. Never sideload APK files, no matter how legitimate the request sounds.
  • Use a privacy-focused browser with built-in phishing protection, and enable encrypted DNS (such as DNS over HTTPS) to reduce exposure to malicious domains.

Build Safer Habits

  • Adopt a 24-hour rule: for any unsolicited request involving money or credentials, wait a day and verify through a second channel.
  • Agree on a family "safe word" to confirm identity if someone claims to be a relative in trouble.
  • Separate your financial life from your social life. Use a dedicated email for banking that is not shared on social media or shopping sites.
  • Review bank statements weekly, not monthly. Early detection limits damage.

Protecting Your Business from Phishing in Singapore

Businesses face additional risks because a single compromised employee can expose customer data, trigger ransomware, or authorize fraudulent payments. Singapore's Personal Data Protection Act (PDPA) also imposes mandatory breach notification requirements, meaning phishing incidents can carry legal consequences.

Technical Controls

  1. Deploy email authentication protocols: SPF, DKIM, and DMARC with enforcement set to reject or quarantine.
  2. Enable advanced phishing protection in Microsoft 365 or Google Workspace, including impersonation detection and safe-link rewriting.
  3. Enforce MFA across all accounts, with conditional access policies that block logins from unusual countries.
  4. Segment the network so that a compromised laptop cannot immediately reach financial systems or customer databases.
  5. Use branded, trackable short links from a reputable provider for all customer communications so recipients can learn to recognize your legitimate domain. See our 2026 buyer's guide to URL shorteners for a comparison of trusted options.

Human Controls

  • Run quarterly phishing simulations and provide short, targeted training for anyone who clicks.
  • Create a clear, blame-free reporting channel. Employees should feel safe forwarding a suspicious email without fear.
  • Enforce dual approval for any payment above a threshold, with verbal confirmation via a known phone number.
  • Maintain an updated incident response plan that includes PDPC notification steps, bank contact details, and legal counsel.

What to Do If You Fall Victim to Phishing

Even careful people make mistakes, especially when tired or distracted. Acting within the first hour dramatically improves your chances of limiting damage.

  1. Call your bank immediately using the number on the back of your card. Request an account freeze and card cancellation. Singapore banks have 24/7 anti-scam hotlines.
  2. Change your passwords starting with your email, since email controls password resets everywhere else.
  3. Revoke active sessions on your banking apps, email, and social media accounts.
  4. Report to the Singapore Police Force via the Anti-Scam Centre hotline 1800-722-6688 or at police.gov.sg/iwitness. For urgent cases, call 999.
  5. File a report with ScamShield so the number or URL can be added to the national block list.
  6. Notify the PDPC within 72 hours if personal data of customers was exposed (for businesses).
  7. Scan your devices for malware and consider a factory reset if you installed a suspicious app.

The Future of Phishing in Singapore

Phishing is becoming harder to detect. Generative AI now produces flawless English and Mandarin messages, deepfake audio can mimic a CEO's voice in a vishing call, and attackers increasingly combine data from past breaches to make messages feel personal. In response, Singapore is expanding initiatives like the Shared Responsibility Framework, which allocates liability between banks, telcos, and consumers for scam losses, and tightening rules around SMS sender authentication and digital banking safeguards.

For individuals, the lesson is clear: assume that any unsolicited message is suspicious until proven otherwise, and build verification habits that do not depend on how convincing a message looks. For businesses, defense in depth, combining strong technical controls with ongoing staff training and robust incident response, remains the only reliable approach.

Frequently Asked Questions

How do I report a phishing SMS or scam call in Singapore?

Forward phishing SMS to 7726 (SPAM) via your telco, report through the ScamShield app, or submit details at scamshield.gov.sg. For scam calls or financial loss, contact the Anti-Scam Helpline at 1800-722-6688 or file an i-Witness report at police.gov.sg.

Will my bank refund me if I lose money to phishing in Singapore?

Under Singapore's Shared Responsibility Framework, banks and telcos may bear part of the loss if they failed to meet their duties, such as not blocking a known scam SMS or not sending required alerts. However, if you shared OTPs, approved transactions, or installed malicious apps, you may be deemed partly or fully responsible. Always report immediately to maximize your chances of recovery.

Is it safe to click shortened links I receive by message?

Shortened links are safe when they come from a trusted sender and a reputable shortening service. The risk is that short links hide the final destination. Before clicking, use a link preview tool to expand the URL, or ask the sender to confirm. Reputable services provide link transparency and analytics so recipients can verify legitimacy.

How can I tell if a SingPass or government message is real?

Official SingPass messages come through the SingPass app or from Gov.sg-registered sender IDs. Genuine government websites always end in .gov.sg. If in doubt, do not click any links. Instead, open the SingPass app directly or visit singpass.gov.sg by typing the address manually.

What should I do first if I accidentally entered my banking details on a phishing site?

Call your bank's 24/7 anti-scam hotline immediately to freeze the account and cancel cards. Then change your internet banking password from a different, trusted device, revoke active sessions, and file a police report. Speed matters most in the first 30 to 60 minutes.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles