facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··11 min read

Singapore has one of the highest smartphone penetration rates in the world, and QR codes are everywhere — from hawker centre payment stands to MRT posters, parking coupons, and restaurant menus. Unfortunately, that same convenience has opened the door to a fast-growing category of fraud: QR code scams, also known as "quishing" (QR + phishing). The Singapore Police Force and the Cyber Security Agency of Singapore (CSA) have issued multiple advisories, and losses tied to QR-based scams now run into millions of dollars each year.

This guide explains exactly how QR code scams work in Singapore, the most common local variants circulating in 2026, and the practical steps you can take to protect yourself, your family, and your business.

What Are QR Code Scams?

A QR code scam is a form of phishing where criminals use a Quick Response (QR) code to redirect victims to a malicious website, prompt a fraudulent payment, or trigger a malware download. Because a QR code is just a machine-readable pattern, humans cannot tell by looking at it whether it is safe or dangerous — you only find out after your phone opens the link.

In Singapore, scammers exploit the fact that QR-based payments (PayNow, SGQR, NETS QR) and QR-based logins are part of daily life. A single tap on a poisoned code can lead to a fake SingPass page, a spoofed bank login, or an unauthorised e-wallet transfer.

Why QR Codes Are So Attractive to Scammers

  • No visible URL: Unlike a suspicious email link, a QR code hides its destination until it is scanned.
  • Trust by context: A sticker on a hawker stall or a poster at a bus stop feels official.
  • Mobile-first: Phishing pages look more convincing on small screens where address bars are truncated.
  • Cheap to deploy: Printing and pasting a sticker over a legitimate code costs almost nothing.

The Rise of QR Code Scams in Singapore

According to the Singapore Police Force's annual scam reports, phishing scams — including those launched via QR codes — remain among the top five scam types by both case count and financial loss. High-profile local incidents have involved fake bubble tea surveys, counterfeit parking coupons at HDB carparks, tampered PayNow codes at hawker stalls, and fraudulent "MAS advisory" letters mailed to households with a QR code leading to a spoofed bank page.

What makes Singapore particularly attractive to fraudsters is the widespread trust in digital government and banking services. When victims see a QR code linked to a message referencing IRAS, ICA, SPF, or a local bank, they are more likely to scan without hesitation.

Common QR Code Scams Targeting Singaporeans

1. Fake Survey and Free Gift Scams

You are approached at a shopping mall, MRT station, or coffee shop and asked to "scan this QR code to complete a short survey for a free drink or voucher." The code leads to a page that asks for your bank login, credit card details, or SingPass credentials. In several publicised cases, victims later found unauthorised transactions or that their bank accounts had been drained.

2. Tampered Payment QR Codes at Merchants

Scammers paste their own PayNow or SGQR sticker over the legitimate one at hawker stalls, taxi stands, or small retailers. Customers scan and pay — but the funds go to a mule account, not the merchant. The stall owner only realises later when reconciling sales.

3. Fake Parking Coupon or LTA Fine QR Codes

Fraudulent notices left on windshields claim you have an outstanding parking fine or an LTA-issued penalty, with a QR code to "pay immediately to avoid escalation." The link mimics OneMotoring or a bank payment page.

4. Fake Bank or MAS Letters

Physical letters or emails, sometimes with convincing local branding, ask you to scan a QR code to "verify your account," "update your particulars," or "reactivate your SingPass." The destination is a phishing site that harvests two-factor authentication codes in real time.

5. Delivery and Parcel Scams

With the boom in cross-border e-commerce, scammers leave fake "missed delivery" notices from SingPost, Ninja Van, or Qxpress. Scanning the QR code opens a page that requests a small "redelivery fee" — and captures full card details in the process.

6. Cryptocurrency and Investment Scams

QR codes are placed in Telegram groups, Facebook ads, or even printed flyers promising high returns. Scanning leads to a fake trading platform or directly triggers a crypto wallet transfer that cannot be reversed.

7. Fake Charity and Donation Codes

Around festive seasons or after disasters, scammers set up fake donation drives with QR codes leading to their own PayNow numbers instead of registered charities.

How a QR Code Scam Actually Works: Step by Step

  1. The bait: The scammer places a QR code somewhere trusted — a sticker, poster, letter, email, or social media ad.
  2. The scan: You open your camera app or a scanner and point it at the code.
  3. The redirect: Your browser loads a URL, often a shortened or lookalike domain such as dbs-verify-sg.com or singpass-login.info.
  4. The harvest: The page mimics a real login, payment, or verification screen and captures your credentials, OTP, or card details.
  5. The exploit: Within minutes, the criminal logs into your real account (often from overseas), transfers funds, or adds their device as a trusted one to bypass future 2FA.

Warning Signs of a Malicious QR Code

  • A sticker that looks freshly pasted over another sticker, with misaligned edges or bubbles.
  • Unexpected urgency: "Scan now or your account will be locked."
  • Requests for SingPass, full NRIC, OTP, or internet banking password after scanning.
  • Shortened or unfamiliar domains that do not match the organisation's real website.
  • Spelling and grammatical errors on the landing page.
  • Pages that ask you to install an APK or sideload an app outside the Google Play Store or Apple App Store.
  • Payment amounts that differ from what the merchant told you.

10 Practical Ways to Stay Safe from QR Code Scams

1. Preview the URL Before Opening It

Modern iOS and Android camera apps show a preview of the link before you tap. Read the full domain carefully. If it does not match what you expect (for example, a "DBS" code leading to a .xyz or .info domain), do not proceed.

2. Never Enter SingPass or Banking Credentials After Scanning a QR Code

No Singapore bank, MAS, IRAS, ICA, or government agency will ask you to log in via a QR code from an unsolicited letter, email, or SMS. Always open the official app or type the URL manually.

3. Verify Payment QR Codes with the Merchant

Before paying at a hawker stall or small shop, confirm the recipient name shown in your banking app matches the business. If it shows an unfamiliar personal name, stop and ask the stall owner.

4. Inspect Physical QR Codes for Tampering

Look for stickers pasted over the original code, mismatched printing, or codes on loose paper rather than laminated signage. Merchants should periodically inspect their own SGQR displays.

5. Use Your Bank's Official App for Payments

DBS PayLah!, OCBC Digital, UOB TMRW, and other local apps have built-in QR scanners that validate against the SGQR registry. They are far safer than a generic camera scan.

6. Enable Money Lock and Transaction Limits

Most Singapore banks now offer a "money lock" feature that ring-fences part of your savings so it cannot be transferred digitally. Combine this with low daily transfer limits for extra protection.

7. Keep Your Phone's Operating System Updated

Many QR-triggered exploits rely on unpatched browser or OS vulnerabilities. Install iOS and Android updates promptly.

8. Understand Link Shorteners and Use Trusted Ones

Not every short link is malicious — shorteners are used legitimately by businesses, government agencies, and content creators every day. The key is knowing whether the shortener is reputable and whether the destination is verifiable. Trusted platforms such as Lunyb provide link previews, click analytics, and abuse monitoring, which help both link creators and recipients confirm where a URL actually leads. If you frequently share links yourself, choosing a transparent shortener matters — see our 2026 buyer's guide to URL shorteners for a full comparison.

9. Report Suspicious Codes Immediately

If you spot a suspicious QR sticker in public, report it to the venue owner and to the Singapore Police Force via the ScamShield app or the 1799 anti-scam helpline. If you have already scanned and entered details, contact your bank's 24-hour hotline right away to freeze accounts.

10. Educate Family Members, Especially Seniors

Elderly relatives are frequent targets because they may be less familiar with URL structures and phishing patterns. Walk them through what SingPass and bank login pages look like, and remind them that no legitimate agency asks for OTPs.

Quick Comparison: Safe vs. Suspicious QR Scenarios

ScenarioLikely SafeLikely Suspicious
Source of codeLaminated, official signage at a known merchantLoose sticker, printed flyer, unsolicited letter
Landing pageOfficial domain (e.g. dbs.com.sg, singpass.gov.sg)Lookalike domain (dbs-sg-verify.com, singpass.info)
Information requestedConfirm payment amount and recipient nameSingPass password, OTP, full card number, CVV
UrgencyNone — you decide when to pay"Act within 30 minutes or account frozen"
App behaviourOpens your bank's real appPrompts you to install an APK or sideload

What to Do If You Have Been Scammed

  1. Call your bank immediately using the number on the back of your card or in their official app. Request an emergency freeze on all accounts and cards.
  2. Change your SingPass password and revoke any unknown devices linked to your account.
  3. Enable Money Lock on remaining funds if available.
  4. Lodge a police report at any Neighbourhood Police Centre or online via the SPF e-Services portal.
  5. Report to ScamShield so the URL and phone numbers involved can be added to national blocklists.
  6. Notify CSA through the SingCERT incident reporting form if the scam involved a spoofed government or corporate identity.
  7. Monitor your credit via the Credit Bureau Singapore for any unauthorised loans or applications in your name.

Advice for Singapore Businesses and Merchants

Small businesses are both victims and unwitting distribution points for QR fraud. If you operate a hawker stall, retail shop, or F&B outlet:

  • Inspect your SGQR display daily for tampering.
  • Laminate and secure QR codes behind a rigid, tamper-evident cover.
  • Train staff to verify payment notifications on the bank app before releasing goods.
  • Use dynamic QR codes generated per transaction where possible — many POS systems support this.
  • If you distribute marketing links via QR, use a reputable shortener with analytics and abuse controls so you can detect if your codes are being cloned or misused.

The Bigger Picture: Building Long-Term Digital Hygiene

QR code scams are just one facet of a broader phishing ecosystem. The same defensive habits — verifying domains, refusing to share OTPs, using official apps, and keeping devices patched — protect you against SMS scams, email phishing, and social media impersonation. Treat every unsolicited link, whether tapped or scanned, with the same scepticism.

For readers who want to go deeper into link safety and how modern shorteners handle abuse, our honest review of Lunyb and our Rebrandly review for 2026 explain what to look for in a trustworthy link platform.

Frequently Asked Questions

Can simply scanning a QR code hack my phone?

In almost all cases, scanning a QR code only opens a URL — it does not automatically install malware. The danger comes from what you do next: entering credentials, downloading an app from outside the official stores, or approving a payment. Keep your OS updated and never sideload apps from links you scanned.

Is it safe to pay via PayNow QR at hawker centres?

Yes, PayNow and SGQR are safe protocols when used correctly. The risk is not the technology but tampered stickers. Always confirm the recipient name displayed in your banking app matches the stall or business before pressing pay.

How do I report a suspicious QR code in Singapore?

Call the ScamShield Helpline at 1799, use the ScamShield mobile app to report the URL, or lodge a report with the Singapore Police Force. If a spoofed government or corporate identity is involved, also report to SingCERT under the Cyber Security Agency of Singapore.

Will my bank refund me if I was tricked by a QR code scam?

Under Singapore's Shared Responsibility Framework, banks and telcos may bear part of the loss if they failed in specific duties (such as sending real-time alerts). However, if you voluntarily entered your OTP or password on a phishing page, recovery is not guaranteed. Report as quickly as possible to maximise the chance of freezing funds before they leave the country.

Are dynamic QR codes safer than static ones?

Generally yes, for merchants. Dynamic codes are generated per transaction and often include the exact amount, making tampering harder and reconciliation easier. For consumers, the safety difference is smaller — you still need to verify the recipient name and landing page before paying.

Final Thoughts

QR codes are not going away — they are woven into how Singapore pays, boards, orders, and verifies. The good news is that staying safe does not require abandoning them. It requires a small set of durable habits: preview every link, never share OTPs, verify recipients, use official apps, and report anything suspicious. Share this guide with parents, grandparents, and colleagues. In a city as digitally connected as Singapore, collective awareness is the strongest firewall we have.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles