QR Code Scams in Singapore: How to Stay Safe in 2026
QR codes are everywhere in Singapore, from hawker centres and MRT posters to parking meters and restaurant menus. That convenience has also created a booming attack surface for scammers. In 2023 alone, victims in Singapore lost over S$300,000 to a single wave of QR code food-survey scams, and the numbers have only climbed since. This guide explains exactly how QR code scams in Singapore work, the red flags to watch for, and the practical steps you can take today to protect your money and personal data.
What Are QR Code Scams?
A QR code scam, sometimes called "quishing" (QR phishing), is a form of fraud where criminals trick victims into scanning a malicious QR code that redirects them to a fake website, downloads malware, or authorises a payment. Because QR codes are just machine-readable links, you cannot tell where they lead until your phone opens the destination — and by then, the damage may already be done.
In Singapore, QR codes are deeply integrated into daily life through PayNow, SGQR, NETS, and government services like Singpass. That trust is exactly what scammers exploit. A sticker slapped over a legitimate QR code can silently redirect thousands of dollars to a fraudster's wallet, or harvest banking credentials via a convincing spoof of a DBS, OCBC, or UOB login page.
Why Singapore Is a Prime Target
Several factors make Singapore especially vulnerable to QR code fraud:
- High QR code adoption: SGQR unified payments across providers in 2018, making QR scanning second nature for most Singaporeans.
- Cashless culture: PayNow, GrabPay, and bank apps encourage scan-to-pay behaviour at every merchant.
- Trust in institutions: Singaporeans generally trust official-looking signage, which scammers imitate closely.
- Mobile-first banking: Most banking transactions occur on smartphones, the same device used to scan codes.
- Tourism and F&B density: High foot traffic in food courts and shopping districts gives scammers plenty of surfaces to plant fake stickers.
Common Types of QR Code Scams in Singapore
1. The Bubble Tea and Food Survey Scam
This is the most publicised scam of the past two years. A friendly-looking person hands you a flyer or points to a QR code offering a free drink, cash voucher, or survey reward. Scanning leads to an app download (usually a third-party APK) that hijacks your phone, records your banking credentials, and drains your account overnight while you sleep. Police have reported single victims losing more than S$70,000 in one night.
2. Fake Payment QR Codes at Merchants
Scammers place their own PayNow or SGQR sticker over a legitimate merchant's code — at hawker stalls, parking meters, or even carpark payment kiosks. Customers pay the fraudster instead of the business. Merchants only realise something is wrong at the end of the day when takings don't match receipts.
3. Parking and LTA Impersonation
Fake parking summons or LTA notices left on windshields include a QR code to "pay your fine." The link leads to a spoof government portal that harvests Singpass credentials or credit card details.
4. Delivery and Package Scams
A missed delivery slip in your letterbox instructs you to scan a QR code to reschedule. The destination mimics SingPost, Ninja Van, or Shopee, requesting a small "redelivery fee" that captures your card details.
5. Charity and Donation Scams
Fake volunteers approach shoppers near MRT stations with QR codes for supposed charities. Some are outright theft; others harvest personal data for later phishing attempts.
6. Phishing Emails with Embedded QR Codes
Increasingly, phishing emails contain QR codes instead of clickable links to bypass corporate email filters. Employees scan with their personal phones — outside company security — and land on credential-harvesting pages.
How a QR Code Scam Actually Works: Step by Step
- Bait: The scammer places a QR code somewhere trustworthy — a menu, poster, sticker, or email.
- Scan: You point your camera at the code without knowing where it leads.
- Redirect: Your browser opens a shortened or obfuscated URL that either mimics a real site or triggers an APK download on Android.
- Payload: You are asked to log in, pay a small fee, or install an "app" for a promotion.
- Compromise: Credentials are stolen, malware is installed, or a fraudulent payment is authorised.
- Extraction: Funds are transferred out of your account, often to mule accounts overseas within minutes.
Red Flags: How to Spot a Malicious QR Code
Before you scan any QR code in Singapore, run through this mental checklist:
- Sticker over a sticker: Look closely at physical codes. A fresh sticker placed over an older one is a major warning sign.
- Unsolicited offers: Free bubble tea, surveys with cash rewards, or "lucky draws" pushed by strangers on the street.
- Requests to install an app: Legitimate promotions in Singapore never require you to sideload an APK from a browser.
- Urgency: "Pay within 30 minutes to avoid a fine" or "claim before the offer expires" tactics.
- Mismatched URLs: The preview URL doesn't match the brand — e.g., a "DBS" code opening dbs-secure-login[.]xyz.
- Requests for Singpass or 2FA codes: No legitimate merchant needs your Singpass to give you a discount.
- Poor grammar or design: Government and bank pages in Singapore are polished. Typos are a giveaway.
Practical Steps to Stay Safe
Before You Scan
- Ask yourself whether you sought out this code, or whether it was pushed on you.
- Inspect the physical code for tampering. Peel gently at the corner if you're unsure — genuine merchants won't mind.
- Prefer scanning through your banking app's built-in scanner (DBS PayLah!, OCBC Digital, UOB TMRW) rather than your generic camera app. Banking apps validate SGQR payloads and block known scam URLs.
After You Scan
- Check the URL preview before tapping. iOS and Android both show a link preview above the "Open" button.
- Look for HTTPS and the correct domain. Real DBS is dbs.com.sg, not dbs-sg[.]com or dbs.secure-login[.]net.
- Never download an APK from a browser. Only install apps from the Google Play Store or Apple App Store.
- If a payment screen appears, confirm the recipient name matches the merchant before authorising.
Device-Level Protection
- Enable Google Play Protect on Android and keep "Install unknown apps" disabled for all browsers.
- Turn on Singapore banks' anti-malware kill switches (available in DBS, OCBC, UOB, and Citibank apps) which lock your account the moment sideloaded apps are detected.
- Use encrypted DNS (Cloudflare 1.1.1.1 or NextDNS) to block known phishing domains at the network level.
- Keep iOS and Android updated — many quishing payloads rely on unpatched browser vulnerabilities.
- Enable biometric confirmation for every outgoing transfer above a low threshold in your banking app.
Comparing Safe vs Unsafe QR Code Behaviour
| Situation | Safe Practice | Unsafe Practice |
|---|---|---|
| Paying at a hawker stall | Scan through DBS PayLah! or bank app; confirm recipient name | Scan random sticker with camera; approve without checking name |
| Approached by a promoter | Politely decline; verify promotion on brand's official website | Scan the flyer's QR and install the recommended "app" |
| Parking fine on windshield | Check LTA OneMotoring website directly | Scan the QR on the ticket and pay immediately |
| Email with QR code | Ignore and log in to the service directly in a browser | Scan with phone camera outside corporate security |
| Missed parcel notice | Log in to the courier's official app or website | Scan the QR and pay a "redelivery fee" |
What to Do If You've Been Scammed
Speed matters. Every minute that passes gives scammers more time to move funds through mule accounts. If you suspect you've fallen victim:
- Activate your bank's kill switch immediately — DBS, OCBC, UOB, and most local banks have this feature inside their apps and on hotlines.
- Call your bank's 24/7 fraud hotline to freeze accounts and reverse recent transactions where possible.
- Change your Singpass password and revoke any suspicious linked apps at singpass.gov.sg.
- Uninstall any suspicious apps, then factory reset the device to eliminate persistent malware.
- Report to the Singapore Police Force via the ScamShield app, 1800-255-0000 hotline, or police.gov.sg/iwitness.
- Report to ScamShield so the malicious URL and number are added to national blocklists.
- Notify contacts if the malware may have accessed your messaging apps — scammers often impersonate victims to trick friends.
The Role of URL Shorteners in QR Code Safety
Most QR codes contain long, complex URLs, so legitimate businesses often shorten them for reliability and tracking. Unfortunately, generic short links can also hide malicious destinations. This is where reputable shortening services with click analytics and malware scanning matter.
If you run a business creating QR codes for menus, promotions, or payment pages, using a trustworthy shortener such as Lunyb gives you branded links, real-time analytics, and the ability to disable a compromised link instantly if someone clones your campaign. For a broader comparison of options, see our 2026 buyer's guide to URL shorteners and our honest Lunyb review.
For consumers, the takeaway is simpler: if a QR code resolves to a shortener you don't recognise, don't proceed unless the destination preview clearly matches the brand you expect.
Advice for Merchants and Businesses
Business owners in Singapore have a duty of care to prevent their premises from being used as scam vectors. Practical steps include:
- Laminate or frame your SGQR sticker so tampering is obvious.
- Inspect payment codes daily — before the morning rush and after closing.
- Cross-check daily takings against merchant app statements every evening.
- Train staff to recognise the "sticker over sticker" pattern.
- Use branded short links (not generic bit.ly-style links) so customers can verify authenticity at a glance.
- Display a printed notice: "Our only PayNow QR is displayed here. Report tampering to management."
What Singapore Authorities Are Doing
The Monetary Authority of Singapore (MAS) and the Singapore Police Force have introduced several countermeasures:
- Money Lock: Available at all major banks — funds locked with Money Lock cannot be transferred out digitally.
- Shared Responsibility Framework: Effective from 2024, this framework distributes liability for phishing scam losses between banks, telcos, and consumers who follow safe practices.
- ScamShield app: Blocks known scam calls and SMS, and lets you check suspicious messages.
- Anti-malware measures in banking apps: Automatic detection of sideloaded apps and screen-sharing during sensitive banking sessions.
- SPF Anti-Scam Command: Works directly with banks to freeze mule accounts, often within minutes of a report.
Frequently Asked Questions
Are QR codes on hawker stalls in Singapore generally safe?
Yes, the vast majority are safe, especially SGQR codes issued by banks and payment providers. The risk arises when a fraudster places a fake sticker over the genuine one. Always confirm the recipient name in your banking app before approving payment, and report anything suspicious to the stall owner.
Can just scanning a QR code hack my phone?
Scanning alone typically only opens a URL — it doesn't install anything by itself. The danger starts when you tap the link, install a prompted app, or enter credentials on the destination page. Modern iOS and updated Android devices are largely safe against drive-by installs, but keep your OS updated to close browser vulnerabilities.
How do I check where a QR code leads without opening it?
Most smartphone cameras display a URL preview before you tap "Open." You can also use a QR reader that shows the full destination and warns about known malicious domains. If the URL uses a shortener you don't recognise, expand it using a link-expander tool before visiting.
Will my bank refund me if I fall for a QR code scam?
Under Singapore's Shared Responsibility Framework, banks and telcos may bear part of the loss if they failed in their duties, but consumers who ignore security warnings or install sideloaded apps often bear most of the loss themselves. Activate your bank's kill switch immediately and report to police within 24 hours to maximise your chances of recovery.
Is it safer to use my camera app or a dedicated QR scanner?
For payments, use your bank's in-app scanner (DBS PayLah!, OCBC Digital, UOB TMRW, GrabPay). These validate SGQR payloads and cross-check destinations against fraud blocklists. For general use, the native iOS or Android camera app is fine, provided you review the URL preview before opening.
Final Thoughts
QR code scams in Singapore are evolving faster than public awareness, but they rely almost entirely on rushed decisions and misplaced trust. A five-second pause — to check the sticker, confirm the URL, and verify the recipient — defeats the vast majority of attacks. Combine that habit with your bank's Money Lock, kill switch, and ScamShield, and you'll be significantly harder to target than the average victim. When you scan next, scan slowly.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Know if Your Phone Is Hacked: 10 Warning Signs
Worried your phone might be compromised? Learn the 10 clearest warning signs your phone is hacked — from battery drain to unexpected 2FA codes — plus a step-by-step recovery plan and prevention tips to keep your device secure.
What Data Does Google Have on You? A Complete 2026 Breakdown
Google collects an enormous amount of data on every user — from searches and locations to voice recordings and emails. This 2026 guide breaks down exactly what Google knows about you, how to see it, and step-by-step ways to reduce or delete it.
End-to-End Encryption Explained: How It Works and Why It Matters
End-to-end encryption is the gold standard for protecting messages, files, and calls from prying eyes. This guide breaks down how it works, why it matters, and where it falls short — in plain, practical language anyone can follow.
Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore are more sophisticated than ever, targeting bank accounts, Singpass credentials, and PayNow transfers. Learn how to recognize red flags, what to do if you clicked, and how to protect yourself and your business.