QR Code Scams in Singapore: How to Stay Safe in 2026
Singapore has one of the highest rates of QR code adoption in the world. From hawker stalls in Chinatown to MRT posters, parking meters in HDB estates, and PayNow transfers at retail counters, the humble black-and-white square has become part of daily life. Unfortunately, that same convenience has made Singaporeans a prime target for a fast-growing category of fraud: QR code scams, often called "quishing" (QR phishing).
The Singapore Police Force and the Cyber Security Agency (CSA) have issued repeated advisories about scams involving tampered QR stickers, fake payment codes, and phishing links hidden inside QR images sent via WhatsApp, Telegram and email. This guide explains how these scams work in the Singapore context, highlights real cases, and gives you a practical checklist to stay safe.
What Are QR Code Scams?
A QR code scam is any fraud in which a criminal uses a QR code to trick a victim into visiting a malicious website, installing malware, or authorising an unwanted payment. Because a QR code is just a visual encoding of a URL or payload, users cannot read it with their eyes, they must trust whatever their phone camera decodes.
Scammers exploit this trust in three main ways in Singapore:
- Physical tampering: Sticking a fake QR code over a legitimate one at a hawker stall, bubble tea kiosk, or parking meter.
- Digital delivery: Sending QR images via WhatsApp, Telegram, email, or fake government letters that lead to phishing sites.
- Fake payment requests: Impersonating sellers on Carousell, Facebook Marketplace, or Telegram groups and sending QR codes that request money instead of sending it.
Why Singapore Is a High-Risk Target
Singapore's near-universal use of PayNow, PayLah!, GrabPay and SGQR has created a rich environment for QR-based fraud. A few factors make local users especially vulnerable:
- High trust in institutions: Singaporeans are used to seeing official QR codes from IRAS, HDB, LTA, and SingPost, so a scam disguised as a government notice feels credible.
- Speed of contactless payments: People scan and pay in seconds without checking merchant names carefully.
- Multilingual scams: Scammers use English, Mandarin, Malay and Tamil to reach every demographic.
- Cross-border payment apps: Tourists and residents scan foreign QR codes (Alipay, WeChat Pay) without knowing what a legitimate one should look like.
According to the Singapore Police Force's mid-year scam brief, e-commerce and phishing scams — many involving QR codes — continue to rank among the top five scam types by victim count, with losses running into the hundreds of millions of Singapore dollars annually.
Common Types of QR Code Scams in Singapore
1. Bubble Tea and F&B Survey Scams
One of the most publicised local cases involved an elderly woman who lost around S$20,000 after scanning a QR code stuck outside a bubble tea shop, supposedly for a free cup in exchange for a survey. The code installed a malicious Android app that gave scammers remote access to her banking app.
2. Hawker and Coffeeshop Payment Stickers
Scammers paste fake PayNow or SGQR stickers over the real ones at hawker centres and coffeeshops. Customers pay, the stall owner never receives the money, and the customer only realises when the vendor asks for payment again.
3. Parking Coupon and LTA Impersonation
Fake QR codes placed on car windscreens or parking meters claim to be from the Land Transport Authority or HDB parking. Scanning them leads to a cloned payment page that harvests card details.
4. Fake Government Letters
Physical letters or emails claiming to be from IRAS, MOM, ICA or CPF Board include a QR code directing users to a phishing site that mimics Singpass. Once credentials are entered, scammers hijack the Singpass account.
5. Carousell and Marketplace Refund Scams
A fake buyer or seller sends a QR code claiming it will "receive" a refund or deposit. In reality, scanning it initiates a PayNow transfer out of the victim's account.
6. Delivery and Parcel Scams
Fake missed-delivery notices claiming to be from SingPost, Ninja Van or J&T include a QR code for "re-delivery scheduling." The link asks for card details to pay a small redelivery fee — and then drains the account.
How Quishing Actually Works: The Attack Chain
Understanding the flow helps you spot the red flags before you scan.
- Bait: The scammer places a QR code somewhere trusted — a sticker, a poster, a WhatsApp message, an email.
- Scan: You point your phone camera at it. Your default browser opens a URL.
- Lookalike page: The page mimics DBS, OCBC, UOB, Singpass, PayLah! or a courier company. Fonts, colours and logos are almost perfect.
- Credential or app install: You are asked to log in, enter OTPs, or download an APK file (Android sideloading).
- Account takeover: With your credentials or a malicious accessibility-enabled app, the scammer transfers funds, often at 3–5am when you are asleep.
The MAS-mandated Money Lock feature and the Shared Responsibility Framework have reduced some losses, but they do not eliminate the risk — especially if you approve transactions yourself under social engineering pressure.
Red Flags: How to Spot a Suspicious QR Code
| Red Flag | What It Means |
|---|---|
| Sticker placed over another sticker | Physical tampering — peel and check underneath |
| QR code in an unsolicited email or SMS | Almost always phishing |
| URL preview shows unusual domain (.xyz, .top, .icu) | Not a legitimate Singapore business or agency |
| Page asks you to download an APK | Malware — legitimate SG banks never do this |
| Site requests Singpass login outside singpass.gov.sg | Phishing — Singpass only lives on the official domain |
| QR code offers a "free" gift or lucky draw | Classic bait, especially at F&B outlets |
| Merchant name in PayNow prompt doesn't match the stall | Do not confirm the transfer |
10 Practical Steps to Stay Safe
- Always preview the URL before opening. iOS and modern Android cameras show the destination link — read it carefully.
- Check the merchant name on PayNow. Before you tap "Transfer," confirm the recipient name matches the business.
- Never sideload APK files. Only install apps from Google Play or the Apple App Store. If a page tells you to enable "Install Unknown Apps," close it immediately.
- Turn on ScamShield. The ScamShield app by Open Government Products filters known scam numbers and links.
- Enable Money Lock on your bank account. DBS, OCBC and UOB all offer this — locked funds cannot be transferred out digitally.
- Use bank apps directly. Never log in to internet banking through a link from a QR code, SMS or email.
- Peel and inspect stickers at hawker centres, especially if the sticker looks newer than the surroundings.
- Keep your phone OS updated. Both Apple and Google patch QR-related vulnerabilities regularly.
- Educate elderly family members. They are the most-targeted group in Singapore scam statistics.
- Report suspicious codes to the ScamShield hotline (1799) or the SPF anti-scam website.
Safer Link Handling for Businesses and Content Creators
If you run a business, a school CCA, a religious organisation, or a marketing campaign in Singapore, the QR codes you issue are also a target. Scammers can replace them or clone your branded materials. A few good practices:
- Use a link management platform that lets you monitor clicks and swap destinations if a code is compromised.
- Print QR codes with your brand or logo embedded so tampered stickers are visually obvious.
- Use HTTPS-only destination URLs on a domain you fully control.
- Rotate promotional links after a campaign ends so old printed materials cannot be exploited later.
Tools like Lunyb allow you to generate short, trackable links that sit behind your QR codes, so if a code is misused or tampered with, you can disable or redirect the underlying URL without reprinting anything. If you want to compare options first, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
Comparing Safe vs Unsafe QR Code Scenarios
| Scenario | Safe Signal | Unsafe Signal |
|---|---|---|
| Paying at a hawker stall | SGQR sticker matches stall name, uncovered, printed under laminate | Fresh sticker layered on top, mismatched name in PayNow prompt |
| Government notice | Letter matches records in Singpass app inbox | Urgent tone, QR code goes to non-.gov.sg domain |
| Marketing poster in MRT | Reputable brand, URL preview matches company domain | Sticker over official ad, generic short link with typos |
| Carousell transaction | Payment through in-app Carouprotect | Seller sends external QR via WhatsApp asking you to scan |
| Restaurant menu | QR under table glass or on printed menu | Loose sticker on the table edge that peels off |
What to Do If You've Already Scanned a Scam QR Code
- Disconnect immediately. Turn on airplane mode to stop any ongoing data transfer.
- Do not enter any credentials. Close the browser tab.
- If you installed an APK: Boot your phone into Safe Mode and uninstall the app. Consider a factory reset if in doubt.
- Call your bank's 24/7 anti-scam hotline — DBS: 1800-339-6963, OCBC: 1800-363-3333, UOB: 1800-222-2121. Ask them to freeze your account.
- Change your Singpass and iBanking passwords from a clean device.
- File a police report at police.gov.sg/iwitness and call the Anti-Scam Helpline at 1799.
- Report to ScamShield so the malicious link can be blocklisted for others.
The Regulatory Picture in Singapore
Several agencies are actively pushing back against QR-based fraud:
- MAS requires banks to implement kill switches, Money Lock, and default 12-hour cooling-off periods on high-risk activities.
- IMDA works with telcos to block scam SMS senders and filter phishing URLs at network level.
- CSA publishes advisories through SingCERT and the annual Singapore Cyber Landscape report.
- SPF's Anti-Scam Command (ASCom) coordinates rapid fund recovery with banks — the first 24 hours after a scam are critical.
The Shared Responsibility Framework (SRF), effective from late 2024, distributes losses between banks, telcos and consumers depending on who failed which duty. But the fastest way to stay whole is still not to fall for the scam in the first place.
Frequently Asked Questions
Are QR codes themselves dangerous?
No. A QR code is just an image that encodes text — usually a URL. The danger comes from what the URL leads to. Treat every unfamiliar QR code the same way you would treat an unfamiliar link in an email: preview it, verify the domain, and never enter credentials unless you are certain of the site.
Can scanning a QR code hack my phone by itself?
Simply scanning a code cannot install malware on an up-to-date iPhone or Android device. However, if you follow the link, download an APK, and grant it accessibility permissions — which is what many Singapore scam pages instruct — then your device can be fully compromised. Keep your OS updated and never sideload apps.
Is PayNow safe to use with QR codes?
PayNow itself is secure and regulated by MAS. The weakness is human: users often ignore the recipient name shown on the confirmation screen. Always read the merchant name before tapping confirm. If it says something unrelated to the stall, cancel the transaction.
How can I tell if a Singpass login page is real?
The only legitimate Singpass domain is singpass.gov.sg. Any other domain — even ones with "singpass" in the middle of a longer URL — is a phishing attempt. The safest option is to open the Singpass app directly rather than logging in through a browser link.
Where do I report a QR code scam in Singapore?
Call the Anti-Scam Helpline at 1799, file an online report at police.gov.sg/iwitness, and forward suspicious SMS or URLs to ScamShield. If money has already left your account, call your bank's 24/7 fraud hotline first — every minute matters for fund recovery.
Final Thoughts
QR codes are here to stay in Singapore. They power our payments, our parking, our government services, and our shopping. The good news is that staying safe does not require avoiding them — it just requires a two-second habit: preview the link, check the merchant name, and never install anything a QR code tells you to install.
Share this guide with parents, grandparents and colleagues. In Singapore, the strongest anti-scam tool is not technology — it is a well-informed community that pauses for one extra second before tapping "confirm."
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Zero Trust Security Model Explained Simply: A Complete Guide
Zero Trust flips traditional security on its head with a simple rule: never trust, always verify. This guide breaks down the model in plain English, explains its core principles, and shows how to start implementing it—whether you're securing an enterprise or your personal digital life.
Email Security Best Practices for 2026: The Complete Guide
Email remains the top attack vector in 2026, supercharged by AI-generated phishing and token theft. This guide covers the essential email security best practices — from DMARC and passkeys to BEC defense and encryption — that individuals and organizations need to stay protected.
How Hackers Use Shortened URLs to Spread Malware: A 2026 Security Guide
Hackers increasingly use shortened URLs to hide malware, phishing pages, and ransomware payloads behind trusted-looking links. This guide explains the tactics attackers use, how to detect malicious short links, and the practical steps that protect you and your organization.
Password Manager vs Browser Passwords: Which Is Safer in 2026?
Should you rely on Chrome and Safari to save your passwords, or invest in a dedicated password manager? We compare security architecture, features, and real-world risks so you can pick the safest option for 2026.