QR Code Scams in Singapore: How to Stay Safe in 2026
Singapore has become one of the most cashless societies in the world, with QR-based payments through PayNow, SGQR, NETS, and GrabPay woven into daily life. Unfortunately, that same convenience has created a lucrative attack surface for fraudsters. QR code scams — often called quishing (QR + phishing) — cost Singaporeans millions of dollars each year, with the Singapore Police Force repeatedly warning the public about tampered stickers at hawker centres, fake bubble tea surveys, and counterfeit parking notices.
This guide explains exactly how QR code scams in Singapore work, the most common variants circulating in 2026, and the practical steps you can take to protect yourself, your family, and your business.
What Are QR Code Scams?
A QR code scam is a type of phishing attack where criminals use a Quick Response (QR) code to redirect victims to a malicious website, trigger an unauthorised payment, or trick them into installing malware. Because QR codes are unreadable to the human eye, victims cannot tell whether the code leads to a legitimate site or a fraudulent one until it is too late.
In Singapore, scammers exploit the country's high trust in QR-based systems like SGQR and PayNow. A single sticker pasted over a legitimate code at a coffee shop, taxi stand, or shared bicycle can funnel dozens of victims to a fake login page within hours.
Why Singapore Is a Prime Target
- High QR adoption: SGQR unifies over 30 payment schemes, so scanning is second nature.
- Digital banking penetration: Nearly every adult uses DBS, OCBC, UOB, or a digital bank app.
- Tourist and hawker culture: Codes are printed on paper, laminated menus, and even taped to walls — easy to swap.
- Trust in government branding: Scammers impersonate IRAS, LTA, ICA, and SingPass to lower victims' defences.
Common QR Code Scams in Singapore (2026)
The Singapore Police Force and the Cyber Security Agency (CSA) have documented several recurring patterns. Recognising them is the first line of defence.
1. The Bubble Tea Survey Scam
This scam made national headlines when a 60-year-old woman lost S$20,000 after scanning a QR code on a flyer offering a free cup of milk tea. The code prompted her to download a third-party Android app that contained malware, giving scammers remote access to her banking app.
2. Tampered Hawker and F&B Codes
Scammers paste their own QR sticker over the legitimate SGQR code at a stall. Diners scan, pay, and the money goes directly to a mule account. The stall owner only realises hours later when reconciling sales.
3. Fake Parking Fine Notices
Fraudulent notices resembling HDB or URA parking enforcement letters are placed on windscreens. The QR code leads to a fake payment page harvesting credit card details.
4. Counterfeit IRAS or SingPass Notifications
Letters or emails claiming tax refunds or SingPass verification requirements contain QR codes that lead to convincing phishing portals designed to steal 2FA codes.
5. Shared Bicycle and E-Scooter Overlays
Fake codes are stuck onto shared bikes. Instead of unlocking the bike, they charge inflated rental fees or steal payment card details.
6. Delivery and Courier Scams
Missed-delivery slips from fake couriers (impersonating SingPost, Ninja Van, or J&T) ask recipients to scan a QR code to reschedule — leading to malware-laden APK downloads.
How Quishing Works: A Step-by-Step Breakdown
Understanding the mechanics helps you spot the red flags before you scan.
- Lure creation: Scammers design a believable pretext — a free drink, an urgent fine, a parcel notification.
- Code deployment: The QR code is printed on stickers, flyers, letters, or embedded in emails and SMS.
- Redirection: Scanning opens a URL that mimics a bank, government agency, or payment portal.
- Data capture or malware install: The victim enters credentials, OTPs, or is prompted to sideload an Android APK.
- Account takeover: With credentials and remote access, scammers empty bank accounts, often within minutes.
Red Flags to Watch For
Before you scan any QR code in Singapore, run through this mental checklist:
- Is the QR code a sticker on top of another sticker? Peel back gently — a common tampering sign.
- Does the code appear on an unsolicited flyer, letter, or email?
- Are you being asked to download an APK file or install an app outside the Google Play Store or Apple App Store?
- Does the destination URL look slightly off — e.g., "dbs-sg.net" instead of "dbs.com.sg"?
- Is there artificial urgency ("Pay within 2 hours or face penalty")?
- Does the landing page ask for your SingPass, OTP, or full card details for something that shouldn't need them?
Legitimate QR vs. Scam QR: Quick Comparison
| Feature | Legitimate QR Code | Scam QR Code |
|---|---|---|
| Placement | Printed on official signage, laminated, or embedded in menu | Sticker over another sticker, taped hastily, on unsolicited flyer |
| Destination URL | Official domain (e.g., dbs.com.sg, iras.gov.sg) | Look-alike domain or shortened URL from an untrusted source |
| Action requested | Opens app, shows payment recipient's registered name | Requests APK install, login credentials, or OTP |
| Recipient name (PayNow) | Matches the stall or business you're paying | Random personal name or unrelated entity |
| Urgency | None — you scan at your own pace | Countdown timers, threats of fines or account suspension |
How to Stay Safe: Practical Defences
1. Always Preview the URL Before Opening
Most modern smartphones (iOS 15+, Android 12+) display the destination URL as a preview before opening. Read it carefully. If the domain doesn't match the brand you expect, close the preview immediately.
2. Verify PayNow Recipient Names
Before confirming any PayNow transaction, check that the registered recipient name matches the merchant. If you're paying "Ah Huat Kopitiam" but the app shows "Tan Ah Kow," cancel.
3. Never Install Apps from QR Codes
Legitimate Singapore businesses and government agencies will never ask you to sideload an APK. Always download apps directly from the Google Play Store, Apple App Store, or Huawei AppGallery.
4. Enable Money Lock and Transaction Limits
DBS, OCBC, UOB, and other Singapore banks offer a "Money Lock" feature that ring-fences a portion of your savings from digital transfers. Combine this with low daily transfer limits for maximum protection.
5. Use Trusted URL Shortener Previews
If you frequently share or receive shortened links, use a reputable service that provides safe-preview features. Platforms like Lunyb allow you to inspect where a link resolves before opening it, adding a critical safety layer against quishing links embedded in shortened URLs. You can also review the best URL shorteners of 2026 to compare security features.
6. Keep Your Phone's OS and Security Patches Updated
Many quishing malware families exploit unpatched vulnerabilities. Turn on automatic updates for both your OS and banking apps.
7. Use Google Play Protect and iOS Lockdown Mode
Play Protect scans sideloaded apps for malware in real time. On iPhones, Lockdown Mode blocks many exploit chains used by sophisticated attackers.
8. Report Suspicious Codes Immediately
If you encounter a suspicious QR code:
- Call the Anti-Scam Helpline at 1799.
- Report at ScamShield.gov.sg.
- File a police report at police.gov.sg/iwitness.
- Notify the venue owner so the tampered sticker can be removed.
What to Do If You've Been Scammed
Speed is critical. Every minute counts once a scammer has your credentials.
- Freeze your bank accounts immediately through your banking app's "kill switch" or by calling the bank's 24-hour hotline.
- Change your SingPass password and revoke any suspicious linked apps.
- Uninstall any app you downloaded via the QR code and run a full malware scan. If in doubt, perform a factory reset.
- File a police report within 24 hours — this is often required for bank reimbursement claims under Singapore's Shared Responsibility Framework.
- Contact ScamShield and document everything: screenshots, timestamps, URLs, and any communications.
- Alert your contacts — scammers often use compromised accounts to target friends and family.
Advice for Businesses and Hawkers
If you run a stall, café, or retail store, you have a duty to protect your customers too.
- Laminate or frame your SGQR and PayNow codes so tampering is obvious.
- Inspect codes daily — look for any overlay stickers.
- Display your registered business name prominently so customers can verify it matches the PayNow recipient.
- Train staff to spot tampering and to handle customer complaints promptly.
- Use tamper-evident stickers that leave a "VOID" mark when peeled.
The Role of Government and Banks
Singapore has stepped up enforcement significantly. Key initiatives include:
- Shared Responsibility Framework (SRF): Banks and telcos share liability for phishing losses when they fail to meet defined duties.
- ScamShield app: Filters scam SMS and calls, and now flags suspicious URLs.
- Money Lock: Available across all major retail banks.
- Anti-Scam Command (ASCom): A dedicated police unit coordinating rapid fund recovery.
- Singpass Face Verification: Added friction for high-risk logins.
Frequently Asked Questions
Are QR code scams really that common in Singapore?
Yes. The Singapore Police Force has repeatedly flagged quishing as one of the fastest-growing scam vectors. Losses regularly exceed several million dollars per quarter, with elderly victims and small business owners most affected.
Can I tell if a QR code is malicious just by looking at it?
Not from the code pattern itself — QR codes are unreadable to humans. But you can spot warning signs around the code: overlay stickers, poor print quality, mismatched branding, or suspicious placement. Always preview the destination URL before opening.
Is PayNow safe to use?
PayNow itself is safe — the risk lies in scanning tampered codes or paying the wrong recipient. Always verify the registered name shown in your banking app matches the business you intend to pay, and enable transaction alerts.
What should I do if I already scanned a suspicious QR code but didn't enter any details?
Close the browser tab, clear your browser cache, and run a mobile security scan. If you didn't submit credentials, install an app, or grant permissions, you are likely safe — but monitor your bank statements closely for the next few weeks.
Will my bank reimburse me if I fall victim to a QR code scam?
Under Singapore's Shared Responsibility Framework, reimbursement depends on whether the bank and telco met their duties and whether you took reasonable precautions. Reporting quickly — ideally within hours — and filing a police report significantly improves your chances of recovering funds.
Final Thoughts
QR codes are here to stay in Singapore's payment landscape, and so are the scammers who exploit them. The good news: with a few habits — previewing URLs, verifying PayNow recipient names, refusing to sideload apps, and using tools that give you visibility into where a link leads — you can neutralise the vast majority of quishing attempts.
Stay sceptical of urgency, verify before you scan, and share this guide with the people in your life who may be most at risk. A moment of caution beats a lifetime of regret.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Know if Your Phone Is Hacked: 10 Warning Signs
Wondering how to know if your phone is hacked? Learn the 10 warning signs security experts watch for — from battery drain to strange account activity — plus exact steps to confirm a compromise and lock attackers out fast.
What Data Does Google Have on You? A Complete 2026 Breakdown
Google collects an enormous amount of data about you, from searches and locations to voice recordings and third-party website visits. This guide breaks down every category, shows you how to view your data, and explains how to delete it and reduce future tracking.
Data Breaches 2026: What You Need to Know to Stay Protected
Data breaches in 2026 are faster, more automated, and increasingly AI-powered. This guide breaks down the latest trends, the industries most at risk, and practical steps individuals and businesses can take to protect themselves before, during, and after an incident.
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication blocks over 99.9% of automated account attacks, yet most people still rely on passwords alone. This guide explains how 2FA works, which methods are safest, and how to set it up on the accounts that matter most.