QR Code Scams in Singapore: How to Stay Safe in 2026
Quick response codes have quietly become part of daily life in Singapore. You scan them to pay for kopi at a hawker centre, top up your EZ-Link card, join a WhatsApp group at a networking event, or check in at a clinic. That convenience, unfortunately, is exactly what scammers have learned to exploit. QR code scams — sometimes called "quishing" (QR + phishing) — have become one of the fastest-growing cyber threats reported by the Singapore Police Force and the Cyber Security Agency (CSA).
This guide explains how these scams work, walks through real cases reported locally, and gives you a practical checklist to stay safe whether you are a shopper, a small business owner, or an employee handling company devices.
What Are QR Code Scams?
A QR code scam is a fraud technique where criminals use a manipulated or fake QR code to redirect victims to malicious websites, trigger unauthorised payments, or trick them into downloading malware. Because the destination of a QR code is not human-readable, users cannot easily tell a legitimate code from a fraudulent one just by looking at it.
In Singapore, the Singapore Police Force has repeatedly warned about the surge in such cases, with losses often running into thousands — and in some reported instances, hundreds of thousands — of dollars per victim. The Monetary Authority of Singapore (MAS) has also worked with banks to tighten authentication after a wave of high-profile bubble tea and food survey scams.
Why Singapore Is a Prime Target
- High QR adoption: PayNow, SGQR, NETS QR, and GrabPay have made QR payments ubiquitous.
- Trust in institutions: Scammers impersonate SPF, IRAS, ICA, SingPost, and local banks — brands residents instinctively trust.
- Multilingual population: Attackers craft messages in English, Mandarin, Malay, and Tamil to broaden their reach.
- Cross-border logistics: Many scam infrastructure servers are hosted overseas, making takedowns slower.
How QR Code Scams Work in Singapore
Most scams follow a predictable pattern. Understanding the flow makes them much easier to spot.
- Bait: A scammer places a fake QR code — either physically (stickers on hawker stalls, parking meters, shop windows) or digitally (email, SMS, social media, WhatsApp).
- Scan: The victim scans the code, expecting a menu, a survey, a payment page, or a reward.
- Redirect: The code opens a spoofed website that looks like a legitimate bank, government agency, or delivery service.
- Harvest or Install: The victim is asked to log in, enter card details, or download an "official" app (usually an Android APK outside the Play Store).
- Drain: Once credentials or device access is obtained, funds are transferred out, often within minutes.
Common Scam Scenarios
1. The Bubble Tea and Hawker Survey Scam
Victims are approached in person or online with an offer of free bubble tea, milk tea vouchers, or a $5 hawker meal in exchange for filling in a survey. The QR code leads to an APK download that installs malware granting remote access to the phone. Once the victim logs into a banking app, the scammer takes over the session.
2. Fake Parking and Traffic Fine Notices
Stickers with QR codes are placed on cars or parking meters claiming an outstanding fine. Scanning leads to a fake HDB, LTA, or URA payment page that captures card details.
3. Sticker-Over-Sticker at Hawker Stalls
Scammers physically paste their own PayNow or SGQR sticker on top of the merchant's real one. Customers pay, thinking the money reaches the stall owner, but it lands in the scammer's account. Stallholders have reported losing an entire day's takings this way.
4. Delivery and SingPost Redelivery Scams
An SMS or email claims a parcel is undeliverable and asks you to scan a QR code to reschedule. The link leads to a fake SingPost or Ninja Van site that requests card details for a "small redelivery fee".
5. Fake e-Invoices and IRAS Refunds
Business owners receive PDF invoices with embedded QR codes for payment. Employees scan and pay without verifying — the account belongs to the attacker, not the vendor.
Real Warning Signs to Watch For
Before you scan any QR code in Singapore, ask yourself these questions:
- Was the code sent by someone I did not expect to hear from?
- Is it printed on a sticker that looks pasted over something else?
- Does the offer feel too generous (free food, cash rewards, tax refunds)?
- Am I being rushed to act — "pay within 24 hours or face penalties"?
- Does the resulting URL use an odd domain (e.g. iras-sg.co instead of iras.gov.sg)?
- Am I being asked to download an app outside the Play Store or App Store?
If the answer to any of these is yes, stop. Legitimate Singapore agencies never ask you to sideload apps, and banks never request full card details or OTPs via a scanned link.
Comparison: Legitimate vs. Scam QR Code Behaviour
| Aspect | Legitimate QR Code | Scam QR Code |
|---|---|---|
| Destination domain | Ends in .gov.sg, .com.sg, or a well-known bank domain | Look-alike domain, uses .xyz, .top, .co, or IP addresses |
| Action required | Opens a website or payment app you already have | Asks you to download an APK or grant accessibility permissions |
| Payment flow | Uses PayNow, SGQR, or bank app with clear merchant name | Merchant name looks personal or unrelated to the shop |
| Urgency | None — you can verify before paying | Countdown timers, threats of fines or account closure |
| Data requested | Minimal (amount, reference) | Full card number, CVV, OTP, NRIC, SingPass login |
How to Stay Safe: A Practical Checklist
For Individuals
- Preview the URL before opening. Both iOS and Android show the destination link at the top of the camera preview when you hover over a QR code. Read it carefully before tapping.
- Never sideload apps. If a page asks you to enable "Install unknown apps" on Android, close it immediately. Legitimate Singapore apps live on the Play Store or App Store.
- Verify PayNow recipients. When paying at a hawker stall, check that the recipient's name matches the shop or owner. If it shows an unrelated personal name, do not confirm the transfer.
- Turn on Money Lock and transaction limits in your DBS, OCBC, UOB, or GXS app. This adds a friction layer that has stopped many scam transfers cold.
- Use the ScamShield app from the National Crime Prevention Council. It blocks known scam links and numbers.
- Check shortened links carefully. Scammers often hide malicious URLs behind link shorteners. If you personally need to share a link, use a reputable shortener with click analytics like Lunyb so both you and your recipients can trust the destination.
For Small Businesses and Hawkers
- Laminate or frame your QR code so tampering is obvious.
- Inspect your sticker daily. Look for pasted layers, subtle colour shifts, or a merchant name that no longer matches yours.
- Enable payment notifications and reconcile at the end of each shift.
- Train staff to politely ask customers to show the transfer confirmation screen with the correct merchant name.
- Report tampering immediately via the ScamShield helpline (1799) and your acquiring bank.
For Employees Handling Company Devices
- Never scan QR codes from unsolicited emails, even if they appear to come from a colleague or vendor.
- Confirm invoice payment details by phone using a number from the vendor's official website — not the number on the invoice.
- Use mobile device management (MDM) that blocks sideloaded apps.
- Turn on DNS-level filtering such as Cloudflare 1.1.1.1 for Families or Quad9, which blocks known malicious domains at the network layer.
What to Do If You Have Already Scanned a Scam QR Code
Speed matters. If you suspect you have been caught by a QR code scam, work through this list in order:
- Disconnect the device. Turn on airplane mode to cut any active malware session.
- Call your bank's 24/7 fraud hotline and freeze the account. DBS: 1800 339 6963. OCBC: 1800 363 3333. UOB: 1800 222 2121.
- Report to the police at the ScamShield hotline 1799 or file a report on police.gov.sg/iwitness.
- Change your SingPass password and revoke any suspicious authorisations at singpass.gov.sg.
- Factory reset the phone if you installed an unknown APK. Restore only from a clean backup made before the incident.
- Enable two-factor authentication on all email, e-wallet, and cloud accounts.
- Notify your employer if the incident happened on a work device.
How Singapore Is Fighting Back
The response from local authorities has intensified sharply since 2023:
- Anti-Scam Command (ASCom) under SPF now coordinates directly with banks to freeze suspicious accounts within minutes.
- Money Lock features from all three local banks let customers ring-fence savings that cannot be transferred digitally.
- ScamShield is now integrated into iOS and Android call and message filtering.
- MAS Shared Responsibility Framework defines when banks and telcos must compensate scam victims.
- SGQR+ aims to standardise QR payments and reduce the risk of sticker-swap fraud.
These are helpful, but no framework replaces personal vigilance. The final line of defence is still the person holding the phone.
The Bigger Picture: URL Hygiene Matters
Almost every QR scam ends the same way — with a suspicious URL. That is why building good link habits is one of the highest-return security practices you can adopt. Preview links before you tap them, hover over shortened links on desktop, and if you run a business, use a trusted shortening service so your own customers learn to expect predictable, branded destinations.
For a broader look at how to evaluate link shorteners for trust and security, see our 2026 buyer's guide to URL shorteners and our Rebrandly review for a look at enterprise-grade options.
Frequently Asked Questions
Are QR code payments in Singapore still safe to use?
Yes. PayNow, SGQR, and NETS QR remain safe when used correctly. The vulnerability is not the technology itself but the physical or social manipulation around it. Always verify the merchant name on your payment confirmation screen before tapping "Send".
Can scanning a QR code alone infect my phone?
Simply opening the URL usually will not install anything on a modern, updated iPhone or Android. The infection typically requires an extra step — you download an APK, grant accessibility permissions, or enter credentials on a phishing page. Keep your operating system updated and never sideload apps, and the risk drops dramatically.
What should I do if I paid a scam PayNow QR by mistake?
Call your bank's fraud hotline immediately — ideally within minutes. The Anti-Scam Command can sometimes freeze the receiving account before funds are withdrawn. Then file a police report at 1799 or via i-Witness. Save screenshots of the QR code, the recipient name, and the transfer confirmation as evidence.
How can hawker stall owners prevent sticker-swap scams?
Laminate the SGQR code, frame it behind a plastic cover, or move it behind the counter so customers scan from a fixed, tamper-resistant position. Check the sticker at open and close every day, and enable real-time payment notifications so you notice missing transactions quickly.
Will ScamShield block every scam QR code?
No app blocks everything. ScamShield is excellent at catching known scam numbers, SMS templates, and reported malicious URLs, but new campaigns appear daily. Treat it as one layer in a defence-in-depth strategy that also includes updated software, cautious link previewing, transaction limits, and healthy scepticism of any offer that feels too good to be true.
Final Thoughts
QR codes are not going away — they are too convenient, and Singapore's payment infrastructure is built around them. The realistic goal is not to avoid QR codes but to scan them with the same care you would use before signing a contract. Preview the URL, verify the recipient, refuse to sideload apps, and lock down your bank accounts with Money Lock and transaction limits.
Scammers rely on speed and social pressure. Slowing down for five seconds before you tap "Confirm" is the single most effective defence you have.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Irish Data Breaches 2026: What You Need to Know
Irish data breaches in 2026 are hitting record highs, with the DPC issuing billion-euro fines and new laws like NIS2 and the AI Act adding complexity. Here's what Irish businesses and consumers need to know — from the 72-hour reporting rule to practical steps for protecting your data.
How Hackers Use Shortened URLs to Spread Malware in 2026
Shortened URLs hide their destinations — which is exactly why cybercriminals love them. This in-depth guide explains how hackers weaponize short links to spread malware, phishing, and ransomware in 2026, and how to spot, preview, and defend against malicious links before you click.
What Data Does Google Have on You? A Complete 2026 Breakdown
Google collects far more data than most users realize — from search queries and location trails to inferred interests and third‑party browsing. This guide breaks down every category, shows how to view your data, and shares practical steps to shrink your footprint in 2026.
How to Know if Your Phone Is Hacked: 10 Warning Signs
Worried your phone has been compromised? Learn the 10 clearest warning signs your phone is hacked, how to confirm an intrusion, and the exact steps to lock down your device and accounts fast.