facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR codes have become part of everyday life in Singapore. You scan them to pay for kopi at a hawker centre, order food at restaurants, top up EZ-Link cards, join Wi-Fi networks, and access government services. Unfortunately, this convenience has also created a growing attack surface. Since 2023, the Singapore Police Force and the Cyber Security Agency of Singapore (CSA) have repeatedly warned the public about a sharp rise in quishing — phishing attacks that use malicious QR codes.

This guide explains how QR code scams work in Singapore, the most common tactics scammers use locally, red flags to watch for, and what to do if you have already scanned a suspicious code.

What Are QR Code Scams?

A QR code scam is a fraud technique where criminals trick victims into scanning a malicious Quick Response (QR) code. The code typically redirects the victim to a fake website, initiates an unauthorised payment, or prompts them to install a malicious app. Because a QR code is just a machine-readable pattern, users cannot tell by looking whether it is safe or dangerous.

In Singapore, QR code scams have caused millions of dollars in losses. One widely reported case in 2023 involved a 60-year-old woman who lost S$20,000 after scanning a QR code stuck on the glass door of a bubble tea shop, believing she was completing a customer survey for a free drink.

Why Singapore Is a Prime Target

  • High QR adoption: PayNow, NETS QR, and SGQR are used almost everywhere, so scanning is second nature.
  • Trust in official-looking materials: Scammers exploit familiar branding from banks, IRAS, SingPost, LTA, and MOH.
  • Mobile-first behaviour: Most transactions happen on smartphones, where URLs are truncated and harder to inspect.
  • Cross-border messaging: Scam messages via WhatsApp, Telegram, and SMS can originate from overseas numbers that are hard to trace.

Common Types of QR Code Scams in Singapore

1. Sticker Overlay Scams at F&B Outlets

Scammers physically paste a fake QR code sticker over a legitimate one at hawker stalls, cafes, or bubble tea shops. Victims scan it thinking they are participating in a survey, loyalty programme, or free-drink promotion. The link leads to a fake app download that installs malware capable of stealing banking credentials.

2. Fake Parking & LTA Fine Notices

Fraudsters place counterfeit notices on windshields featuring a QR code to "pay your outstanding fine." The code opens a spoofed HDB, URA, or LTA page requesting card details or SingPass login information.

3. PayNow & Bank "Verification" Codes

Victims receive an SMS or WhatsApp message claiming to be from DBS, UOB, OCBC, or Standard Chartered, asking them to "verify" their account by scanning a QR code. The code launches a phishing page that mirrors the real banking login screen.

4. Fake Delivery & SingPost Notices

A missed-delivery card is left in your letterbox with a QR code to "reschedule delivery" or pay a small customs fee. The redirect page harvests card details and one-time passwords.

5. Marketplace & Carousell Payment Scams

A "buyer" on Carousell insists on paying via a QR code they send you. Instead of paying you, the code triggers a transfer from your account, or opens a spoofed PayNow confirmation page that captures your credentials.

6. Fake Charity & Donation Drives

Scammers set up booths or posters mimicking legitimate charities such as NKF or Community Chest. Donors scan the QR to give, but funds flow into scammer-controlled wallets.

7. Cryptocurrency & Investment QR Codes

Social media ads or Telegram groups promise high returns and provide a QR code to "top up" an investment wallet. Once funds are transferred, they are unrecoverable.

How QR Code Scams Actually Work

Understanding the attack chain helps you spot red flags earlier. A typical quishing attack follows these steps:

  1. Placement or delivery: The scammer places a physical sticker, sends a message, or posts an online ad containing the malicious QR code.
  2. Trigger: The victim scans the code, usually while distracted or in a rush.
  3. Redirect: The code opens a shortened or obfuscated URL that leads to a fake website designed to look identical to a trusted brand.
  4. Harvest: The victim enters login details, card numbers, OTPs, or SingPass credentials.
  5. Malicious app (optional): Some scams prompt an APK download outside the Play Store, granting attackers Accessibility permissions to hijack the phone.
  6. Exploitation: Scammers drain bank accounts, apply for loans, or use stolen SingPass access to commit further fraud.

Red Flags: How to Spot a Malicious QR Code

Physical Red Flags

  • A sticker that looks freshly applied over another sticker or laminate.
  • Peeling edges, mismatched colours, or a QR code that doesn't align with the surrounding printed material.
  • QR codes taped to lamp posts, ATMs, bus stops, or public bulletin boards without official branding.
  • Handwritten notes urging urgency ("Scan now for free gift!").

Digital Red Flags

  • The URL preview looks nothing like the brand's official domain (e.g., dbs-verify-sg.top instead of dbs.com.sg).
  • The page asks for your full card number, CVV, OTP, or SingPass password.
  • You are prompted to download an APK file directly rather than through the Play Store or App Store.
  • The site uses urgency tactics: "Your account will be suspended in 24 hours."
  • Grammar and spelling errors, or subtle logo differences.

How to Stay Safe: 10 Practical Steps

  1. Preview before you tap. Both iOS and Android show the destination URL after scanning. Read it carefully before opening.
  2. Check the domain. Legitimate Singapore government sites end in .gov.sg. Banks use their official domains (e.g., dbs.com.sg, uob.com.sg). If in doubt, type the URL manually.
  3. Never install APKs from a QR code. Always download apps from the Google Play Store or Apple App Store.
  4. Enable Money Lock. DBS, OCBC, UOB, and Standard Chartered offer Money Lock features that ring-fence funds from digital transfers.
  5. Use ScamShield. Install the official ScamShield app by the Singapore Police Force and Open Government Products to block scam SMS and calls.
  6. Turn on 2FA everywhere. Use app-based authenticators rather than SMS OTPs where possible.
  7. Inspect physical QR codes. At hawker stalls and shops, check if a sticker has been layered on top of another. When in doubt, ask the staff for the payment number instead.
  8. Use link-expansion tools. If a QR code produces a shortened link, expand it with a reputable link checker before visiting.
  9. Keep your phone updated. Security patches from Apple and Google routinely close vulnerabilities that malicious pages try to exploit.
  10. Slow down. Almost every successful scam relies on urgency. Take 30 seconds to think before scanning or entering credentials.

Safer Link Handling for Businesses and Content Creators

If you run a Singapore business, hawker stall, or content channel that publishes QR codes, you are also a potential victim — scammers can impersonate your brand. Consider these practices:

  • Use branded short links. Custom domains make it obvious when a link is not yours. Trusted services like Lunyb allow you to create branded, trackable short URLs and monitor click patterns for suspicious activity. For a broader comparison of options, see our 2026 URL shorteners buyer's guide.
  • Laminate and seal physical QR codes. Use tamper-evident stickers so overlays are visible.
  • Rotate campaign links. Regenerate codes for promotions so old links can't be reused by scammers.
  • Educate your customers. Publish your official domain prominently and remind customers you will never ask for OTPs or SingPass details.

If you're weighing branded link providers, our Rebrandly review and honest review of Lunyb break down features, pricing, and safety controls.

Comparison: Safe vs Risky QR Code Scenarios

ScenarioSafe IndicatorRisky Indicator
Hawker centre paymentPrinted SGQR label with stall name & UENLoose sticker with only a QR image
Bank messageSent via official banking app inboxWhatsApp / SMS with QR + urgent language
Parking / LTA fineDirects to a .gov.sg domainRedirects to a lookalike domain like lta-sg-pay.com
Charity donationQR at a licensed fundraising event with permit numberQR on random street posters or Telegram forwards
Marketplace dealYou initiate PayNow using the seller's verified UENBuyer sends a QR that "pays you" after scanning

What to Do If You've Already Scanned a Suspicious QR Code

  1. Don't panic — but act quickly. Close the browser tab immediately and don't enter any information.
  2. Disconnect from the internet. Turn on airplane mode if you suspect malware was installed.
  3. Uninstall unknown apps. Check Settings > Apps for anything you don't remember installing, especially apps with Accessibility permissions.
  4. Contact your bank. Call the 24/7 anti-scam hotlines: DBS 1800-339-6963, OCBC 1800-363-3333, UOB 1800-222-2121. Freeze accounts and cards.
  5. Change credentials. Update your Singpass, iBanking, and email passwords from a different, trusted device.
  6. Report to authorities. Call the Anti-Scam Helpline at 1800-722-6688 or file a report at police.gov.sg. Also report to ScamShield.
  7. Run a security scan. Use Google Play Protect or a reputable mobile security app to sweep for malware.
  8. Monitor accounts for weeks. Some scammers wait before draining funds. Enable transaction alerts.

How Singapore Is Fighting Back

The government has rolled out multiple initiatives to combat QR code and digital scams:

  • Shared Responsibility Framework (SRF): Launched in December 2024, requiring banks and telcos to share liability for phishing scam losses when they fail to fulfil their duties.
  • Money Lock: Adopted by all major local banks to protect a portion of savings from digital transfers.
  • ScamShield Suite: A national initiative combining the ScamShield app, hotline, and bot for reporting suspicious content.
  • SPF Anti-Scam Command (ASCom): A dedicated police unit that has recovered hundreds of millions in scam proceeds since 2022.
  • Singpass Face Verification: Now required for high-risk transactions to prevent account takeover.

Despite these measures, prevention still starts with individual awareness. Technology can slow scammers down, but a moment of caution before scanning remains your strongest defence.

Frequently Asked Questions

Can simply scanning a QR code hack my phone?

Scanning a QR code by itself will not install malware. The danger comes from what happens after the scan — visiting a phishing site, entering credentials, or downloading a malicious APK. Always preview the URL and never install apps from outside the official stores.

Are SGQR and PayNow QR codes safe to use?

Yes, the SGQR and PayNow standards are secure. Risks arise when scammers physically overlay fake stickers on legitimate codes, or send fake QR images through messaging apps. Always verify the recipient's name and UEN on the confirmation screen before authorising payment.

How do I report a QR code scam in Singapore?

Call the Anti-Scam Helpline at 1800-722-6688, file a report at police.gov.sg, and submit the scam details through the ScamShield app. If money was transferred, contact your bank's 24/7 fraud hotline immediately — the first hour is critical for recovery.

Will my bank refund me if I fall for a QR code scam?

Under the Shared Responsibility Framework, banks and telcos can be held liable if they fail to meet specific anti-scam duties. However, refunds are not automatic and depend heavily on the circumstances. Reporting quickly and preserving evidence (screenshots, messages, URLs) strengthens your case.

Is it safe to scan QR codes at hawker centres and coffee shops?Generally yes, but inspect the sticker before scanning. Look for signs of tampering — layered stickers, mismatched printing, or codes taped over an existing one. When in doubt, ask the stall owner to confirm their PayNow name or UEN before transferring.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles