facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

Singapore has become one of the most cashless societies in the world, with QR-based payments through PayNow, SGQR, NETS, and GrabPay woven into daily life. Unfortunately, that same convenience has created a lucrative attack surface for fraudsters. QR code scams — often called quishing (QR + phishing) — cost Singaporeans millions of dollars each year, with the Singapore Police Force repeatedly warning the public about tampered stickers at hawker centres, fake bubble tea surveys, and counterfeit parking notices.

This guide explains exactly how QR code scams in Singapore work, the most common variants circulating in 2026, and the practical steps you can take to protect yourself, your family, and your business.

What Are QR Code Scams?

A QR code scam is a type of phishing attack where criminals use a Quick Response (QR) code to redirect victims to a malicious website, trigger an unauthorised payment, or trick them into installing malware. Because QR codes are unreadable to the human eye, victims cannot tell whether the code leads to a legitimate site or a fraudulent one until it is too late.

In Singapore, scammers exploit the country's high trust in QR-based systems like SGQR and PayNow. A single sticker pasted over a legitimate code at a coffee shop, taxi stand, or shared bicycle can funnel dozens of victims to a fake login page within hours.

Why Singapore Is a Prime Target

  • High QR adoption: SGQR unifies over 30 payment schemes, so scanning is second nature.
  • Digital banking penetration: Nearly every adult uses DBS, OCBC, UOB, or a digital bank app.
  • Tourist and hawker culture: Codes are printed on paper, laminated menus, and even taped to walls — easy to swap.
  • Trust in government branding: Scammers impersonate IRAS, LTA, ICA, and SingPass to lower victims' defences.

Common QR Code Scams in Singapore (2026)

The Singapore Police Force and the Cyber Security Agency (CSA) have documented several recurring patterns. Recognising them is the first line of defence.

1. The Bubble Tea Survey Scam

This scam made national headlines when a 60-year-old woman lost S$20,000 after scanning a QR code on a flyer offering a free cup of milk tea. The code prompted her to download a third-party Android app that contained malware, giving scammers remote access to her banking app.

2. Tampered Hawker and F&B Codes

Scammers paste their own QR sticker over the legitimate SGQR code at a stall. Diners scan, pay, and the money goes directly to a mule account. The stall owner only realises hours later when reconciling sales.

3. Fake Parking Fine Notices

Fraudulent notices resembling HDB or URA parking enforcement letters are placed on windscreens. The QR code leads to a fake payment page harvesting credit card details.

4. Counterfeit IRAS or SingPass Notifications

Letters or emails claiming tax refunds or SingPass verification requirements contain QR codes that lead to convincing phishing portals designed to steal 2FA codes.

5. Shared Bicycle and E-Scooter Overlays

Fake codes are stuck onto shared bikes. Instead of unlocking the bike, they charge inflated rental fees or steal payment card details.

6. Delivery and Courier Scams

Missed-delivery slips from fake couriers (impersonating SingPost, Ninja Van, or J&T) ask recipients to scan a QR code to reschedule — leading to malware-laden APK downloads.

How Quishing Works: A Step-by-Step Breakdown

Understanding the mechanics helps you spot the red flags before you scan.

  1. Lure creation: Scammers design a believable pretext — a free drink, an urgent fine, a parcel notification.
  2. Code deployment: The QR code is printed on stickers, flyers, letters, or embedded in emails and SMS.
  3. Redirection: Scanning opens a URL that mimics a bank, government agency, or payment portal.
  4. Data capture or malware install: The victim enters credentials, OTPs, or is prompted to sideload an Android APK.
  5. Account takeover: With credentials and remote access, scammers empty bank accounts, often within minutes.

Red Flags to Watch For

Before you scan any QR code in Singapore, run through this mental checklist:

  • Is the QR code a sticker on top of another sticker? Peel back gently — a common tampering sign.
  • Does the code appear on an unsolicited flyer, letter, or email?
  • Are you being asked to download an APK file or install an app outside the Google Play Store or Apple App Store?
  • Does the destination URL look slightly off — e.g., "dbs-sg.net" instead of "dbs.com.sg"?
  • Is there artificial urgency ("Pay within 2 hours or face penalty")?
  • Does the landing page ask for your SingPass, OTP, or full card details for something that shouldn't need them?

Legitimate QR vs. Scam QR: Quick Comparison

FeatureLegitimate QR CodeScam QR Code
PlacementPrinted on official signage, laminated, or embedded in menuSticker over another sticker, taped hastily, on unsolicited flyer
Destination URLOfficial domain (e.g., dbs.com.sg, iras.gov.sg)Look-alike domain or shortened URL from an untrusted source
Action requestedOpens app, shows payment recipient's registered nameRequests APK install, login credentials, or OTP
Recipient name (PayNow)Matches the stall or business you're payingRandom personal name or unrelated entity
UrgencyNone — you scan at your own paceCountdown timers, threats of fines or account suspension

How to Stay Safe: Practical Defences

1. Always Preview the URL Before Opening

Most modern smartphones (iOS 15+, Android 12+) display the destination URL as a preview before opening. Read it carefully. If the domain doesn't match the brand you expect, close the preview immediately.

2. Verify PayNow Recipient Names

Before confirming any PayNow transaction, check that the registered recipient name matches the merchant. If you're paying "Ah Huat Kopitiam" but the app shows "Tan Ah Kow," cancel.

3. Never Install Apps from QR Codes

Legitimate Singapore businesses and government agencies will never ask you to sideload an APK. Always download apps directly from the Google Play Store, Apple App Store, or Huawei AppGallery.

4. Enable Money Lock and Transaction Limits

DBS, OCBC, UOB, and other Singapore banks offer a "Money Lock" feature that ring-fences a portion of your savings from digital transfers. Combine this with low daily transfer limits for maximum protection.

5. Use Trusted URL Shortener Previews

If you frequently share or receive shortened links, use a reputable service that provides safe-preview features. Platforms like Lunyb allow you to inspect where a link resolves before opening it, adding a critical safety layer against quishing links embedded in shortened URLs. You can also review the best URL shorteners of 2026 to compare security features.

6. Keep Your Phone's OS and Security Patches Updated

Many quishing malware families exploit unpatched vulnerabilities. Turn on automatic updates for both your OS and banking apps.

7. Use Google Play Protect and iOS Lockdown Mode

Play Protect scans sideloaded apps for malware in real time. On iPhones, Lockdown Mode blocks many exploit chains used by sophisticated attackers.

8. Report Suspicious Codes Immediately

If you encounter a suspicious QR code:

  • Call the Anti-Scam Helpline at 1799.
  • Report at ScamShield.gov.sg.
  • File a police report at police.gov.sg/iwitness.
  • Notify the venue owner so the tampered sticker can be removed.

What to Do If You've Been Scammed

Speed is critical. Every minute counts once a scammer has your credentials.

  1. Freeze your bank accounts immediately through your banking app's "kill switch" or by calling the bank's 24-hour hotline.
  2. Change your SingPass password and revoke any suspicious linked apps.
  3. Uninstall any app you downloaded via the QR code and run a full malware scan. If in doubt, perform a factory reset.
  4. File a police report within 24 hours — this is often required for bank reimbursement claims under Singapore's Shared Responsibility Framework.
  5. Contact ScamShield and document everything: screenshots, timestamps, URLs, and any communications.
  6. Alert your contacts — scammers often use compromised accounts to target friends and family.

Advice for Businesses and Hawkers

If you run a stall, café, or retail store, you have a duty to protect your customers too.

  • Laminate or frame your SGQR and PayNow codes so tampering is obvious.
  • Inspect codes daily — look for any overlay stickers.
  • Display your registered business name prominently so customers can verify it matches the PayNow recipient.
  • Train staff to spot tampering and to handle customer complaints promptly.
  • Use tamper-evident stickers that leave a "VOID" mark when peeled.

The Role of Government and Banks

Singapore has stepped up enforcement significantly. Key initiatives include:

  • Shared Responsibility Framework (SRF): Banks and telcos share liability for phishing losses when they fail to meet defined duties.
  • ScamShield app: Filters scam SMS and calls, and now flags suspicious URLs.
  • Money Lock: Available across all major retail banks.
  • Anti-Scam Command (ASCom): A dedicated police unit coordinating rapid fund recovery.
  • Singpass Face Verification: Added friction for high-risk logins.

Frequently Asked Questions

Are QR code scams really that common in Singapore?

Yes. The Singapore Police Force has repeatedly flagged quishing as one of the fastest-growing scam vectors. Losses regularly exceed several million dollars per quarter, with elderly victims and small business owners most affected.

Can I tell if a QR code is malicious just by looking at it?

Not from the code pattern itself — QR codes are unreadable to humans. But you can spot warning signs around the code: overlay stickers, poor print quality, mismatched branding, or suspicious placement. Always preview the destination URL before opening.

Is PayNow safe to use?

PayNow itself is safe — the risk lies in scanning tampered codes or paying the wrong recipient. Always verify the registered name shown in your banking app matches the business you intend to pay, and enable transaction alerts.

What should I do if I already scanned a suspicious QR code but didn't enter any details?

Close the browser tab, clear your browser cache, and run a mobile security scan. If you didn't submit credentials, install an app, or grant permissions, you are likely safe — but monitor your bank statements closely for the next few weeks.

Will my bank reimburse me if I fall victim to a QR code scam?

Under Singapore's Shared Responsibility Framework, reimbursement depends on whether the bank and telco met their duties and whether you took reasonable precautions. Reporting quickly — ideally within hours — and filing a police report significantly improves your chances of recovering funds.

Final Thoughts

QR codes are here to stay in Singapore's payment landscape, and so are the scammers who exploit them. The good news: with a few habits — previewing URLs, verifying PayNow recipient names, refusing to sideload apps, and using tools that give you visibility into where a link leads — you can neutralise the vast majority of quishing attempts.

Stay sceptical of urgency, verify before you scan, and share this guide with the people in your life who may be most at risk. A moment of caution beats a lifetime of regret.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles