facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes have quietly become part of daily life in Singapore. From ordering kopi at a hawker centre to paying with PayNow, scanning a small black-and-white square feels routine. Unfortunately, scammers know this too. In the past two years, the Singapore Police Force and the Cyber Security Agency (CSA) have flagged a sharp rise in QR code scams, also known as quishing (QR + phishing), targeting shoppers, diners, and even bubble tea lovers.

This guide breaks down how QR code scams in Singapore work, the real-world cases that have cost victims tens of thousands of dollars, and the practical steps you can take to stay safe.

What Are QR Code Scams?

A QR code scam is a form of phishing where criminals use a malicious QR code to redirect victims to fake websites, trigger unauthorised payments, or install malware on their devices. Because a QR code is just a visual link, you cannot tell where it leads until you scan it — and by then, the damage may already be underway.

In Singapore, these scams typically fall into four categories:

  1. Fake payment QR codes pasted over legitimate ones at hawker stalls, food courts, or retail shops.
  2. Survey and reward scams where a QR sticker on a shop window or drink promises a free item in exchange for a "quick survey".
  3. Phishing QR codes in emails, letters, or SMS pretending to be from banks, IRAS, Singpost, or ICA.
  4. Malicious QR codes that trigger app downloads (usually Android APK files) leading to banking trojans.

Why Singapore Is a Prime Target

Singapore's high smartphone penetration, widespread PayNow and SGQR adoption, and trust in digital services make it fertile ground for QR-based fraud. According to police statistics, scam-related losses in Singapore crossed S$1 billion in 2024, with phishing and e-commerce scams — many now involving QR codes — among the fastest-growing categories.

Three factors amplify the risk locally:

  • SGQR ubiquity: The unified SGQR label is everywhere, so a fake sticker rarely raises eyebrows.
  • Bilingual and multilingual scams: Scammers craft convincing messages in English, Mandarin, Malay, and Tamil.
  • Trust in government branding: Fake QR codes often mimic HDB, LTA, IRAS, or SPF letterheads.

Real QR Code Scam Cases in Singapore

The Bubble Tea Survey Scam

One of the most publicised cases involved a 60-year-old woman who scanned a QR code on the glass door of a bubble tea shop in Chinatown, promising a free cup for completing a survey. The QR led to a malicious Android app that harvested her banking credentials. She lost S$20,000 from her savings account overnight.

Fake Parking Fine Notices

Scammers have distributed fake parking notices on cars in HDB estates, complete with an official-looking QR code for "instant payment". The QR redirects to a cloned LTA or HDB page requesting card details and OTPs.

Overlaid Hawker Payment Stickers

Enforcement officers have found scammers pasting their own PayNow QR stickers over legitimate stall QR codes. Diners scan and pay, but the money goes to a mule account instead of the stall owner.

Quishing Emails Impersonating Banks

DBS, OCBC, and UOB have all issued advisories about phishing emails that embed QR codes instead of clickable links. The QR bypasses corporate email filters and, when scanned on a personal phone, opens a convincing fake login page.

How Quishing Actually Works: A Step-by-Step Breakdown

  1. Bait placement: The scammer creates a QR code linking to a phishing site or malicious file, then places it in a physical or digital location where victims will encounter it.
  2. Trust trigger: The QR is disguised as a payment code, government notice, promotion, or courier update to lower the victim's guard.
  3. Redirect: Upon scanning, the victim is taken to a spoofed website (e.g. a fake DBS login page) or prompted to download an app.
  4. Data or money capture: The victim enters credentials, OTPs, or card details — or grants the malicious app Accessibility permissions that let it read SMS and control the screen.
  5. Cash-out: Scammers drain accounts through PayNow transfers, credit card charges, or by adding the stolen card to a mobile wallet on another device.

Warning Signs of a Fake QR Code

Physical Red Flags

  • A sticker that looks freshly applied, peeling at the edges, or slightly misaligned with the original signage.
  • A QR code covering another QR code underneath (feel for a bump or double layer).
  • Handwritten or printed-at-home posters offering "too good to be true" freebies.
  • Payment QR codes at hawker stalls where the merchant name shown after scanning does not match the stall.

Digital Red Flags

  • The scanned URL uses an unusual domain (e.g. dbs-sg-verify.com instead of dbs.com.sg).
  • The link uses a URL shortener you don't recognise or a random string of characters.
  • You're prompted to download an APK file directly instead of going through the Google Play Store.
  • The page asks for full card details, CVV, and OTP on a single screen.
  • Urgency language: "Your account will be suspended in 24 hours."

Safe vs Unsafe QR Code Scenarios

Scenario Likely Safe Likely a Scam
Payment at a hawker stall SGQR label is laminated, undamaged, and the merchant name matches the stall A sticker pasted over the original, or a mismatched merchant name
Bank communication Login via the official app you downloaded from the App Store or Play Store QR code in an email or letter asking you to "verify" your account
Government notice Letter with Singpass login instructions to singpass.gov.sg QR sticker on your car or letterbox demanding immediate payment
Promotions QR at official brand pop-ups redirecting to the brand's known domain Random QR on a lamp post promising cash vouchers or free drinks
Parcel delivery Tracking via the courier's official app SMS with QR to "reschedule delivery" from an unknown number

How to Stay Safe: 10 Practical Rules

  1. Preview the URL before opening. Both iOS Camera and Google Lens show the destination URL before you tap. Read it carefully.
  2. Check the merchant name after scanning a payment QR. PayNow and SGQR display the recipient's registered name — if it doesn't match the shop, cancel immediately.
  3. Never download apps from a QR code. Only install apps via the official App Store or Google Play Store.
  4. Turn off "Install from unknown sources" on Android. This single setting blocks most quishing malware.
  5. Don't enter OTPs on pages reached from a QR. Legitimate banks never ask for OTPs on a webpage triggered by a QR scan.
  6. Look for a physical layer. Run your fingernail over suspicious QR stickers to check if one is pasted over another.
  7. Use ScamShield. The SPF/NCPC ScamShield app blocks known scam URLs and numbers in Singapore.
  8. Enable transaction alerts. Set your bank to notify you of every transaction, no matter how small.
  9. Lock your PayNow limits. Reduce daily transfer limits to what you actually need day-to-day.
  10. When in doubt, don't scan. Type the URL manually or use the official app instead.

Verifying Shortened Links Before You Click

Many QR codes contain shortened URLs to save space. That's normal — but it also hides the destination. Before trusting a shortened link revealed by a QR scan, use a link preview tool or a shortener that offers transparent, previewable destinations.

Reputable shorteners like Lunyb allow the owner to publish safe-preview pages and analytics without hiding the destination domain, which is exactly what legitimate merchants and government agencies should be using. If you're evaluating link tools for your own business, our 2026 buyer's guide to URL shorteners compares the safest options, and our honest Lunyb review walks through how link-preview features protect end users.

What to Do If You've Been Scammed

  1. Disconnect immediately. Turn off mobile data and Wi-Fi to stop any active malware from communicating.
  2. Call your bank's 24-hour hotline. Freeze accounts and cards. DBS: 1800-339-6963. OCBC: 1800-363-3333. UOB: 1800-222-2121.
  3. Report to the police. Lodge a report at any Neighbourhood Police Centre or online via eservices.police.gov.sg.
  4. Call the Anti-Scam Helpline: 1800-722-6688 (24/7).
  5. Factory reset your phone. If you downloaded a suspicious APK, back up photos to cloud storage and perform a full reset.
  6. Change all passwords from a different, clean device — especially banking, email, and Singpass.
  7. Report the QR code location. Notify the shop owner, town council, or building management so the physical sticker can be removed.

Protecting Businesses from QR Code Fraud

If you run an F&B outlet, retail shop, or delivery business in Singapore, quishing hurts your customers and your reputation. A few practical safeguards:

  • Laminate and tamper-proof your SGQR labels. Check them daily.
  • Display your registered PayNow name next to the QR so customers can verify after scanning.
  • Use branded short links for marketing QR campaigns so customers recognise your domain. Trusted link platforms (see our Rebrandly review for enterprise-grade options) let you use your own domain, making spoofing much harder.
  • Train staff to spot pasted-over stickers during opening and closing checks.
  • Enable CCTV coverage of areas where QR codes are displayed publicly.

The Role of Encrypted DNS and Private Browsers

Beyond scanning habits, your device settings matter. Enabling encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) on your phone helps block known malicious domains at the network level, even before a phishing page loads. Both iOS and Android support this natively, and services like Cloudflare's 1.1.1.1 or Quad9 offer free, privacy-respecting options.

Pair this with a privacy-focused browser (Brave, Firefox Focus, or Safari with strict tracking prevention) and you add a second layer of protection: even if you scan a bad QR, the malicious domain may be blocked before the page renders.

Frequently Asked Questions

Are QR code scams really common in Singapore?

Yes. Singapore Police Force advisories in 2023 and 2024 flagged quishing as one of the fastest-growing scam vectors, with individual victims losing anywhere from a few hundred dollars to over S$100,000. High-profile cases involving bubble tea shops, fake parking notices, and spoofed bank emails have all been reported in mainstream media.

Is it safe to scan SGQR codes at hawker centres?

Generally yes, but always verify the recipient name shown by your banking app matches the stall before confirming payment. Check the physical sticker for signs of tampering — a QR pasted over another QR is the clearest warning sign.

Can scanning a QR code hack my phone instantly?

Scanning alone does not compromise your device. The danger comes from what happens next: entering credentials on a phishing page, downloading a malicious APK, or granting Accessibility permissions to a fake app. If you scan, preview the URL, and close the tab, you're almost always safe.

What should I do if I already entered my bank details after scanning a suspicious QR?

Call your bank's 24-hour fraud hotline immediately, freeze your cards and PayNow, then call the Anti-Scam Helpline at 1800-722-6688. Change your passwords from a clean device and file a police report. Time is critical — funds are often moved within minutes.

How can I tell if a QR code in an email is legitimate?

Be extremely cautious. Legitimate Singapore banks, IRAS, ICA, and Singpass never ask you to scan a QR code in an email to "verify" your account. When in doubt, ignore the QR and log in via the official mobile app or by typing the known URL into your browser directly.

Final Thoughts

QR codes are convenient — that's exactly why scammers love them. The good news is that quishing relies almost entirely on human trust, not sophisticated hacking. If you slow down, preview URLs, verify merchant names, and never install apps from a QR scan, you eliminate the vast majority of the risk.

Stay alert at hawker centres, treat unsolicited QR codes on letters and cars with deep suspicion, and share this guide with older family members — they are the most frequently targeted group in Singapore. A five-second pause before you scan can save you thousands of dollars and hours of stress.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles