facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

Singapore has one of the highest rates of QR code adoption in the world. From hawker stalls in Chinatown to MRT posters, parking meters in HDB estates, and PayNow transfers at retail counters, the humble black-and-white square has become part of daily life. Unfortunately, that same convenience has made Singaporeans a prime target for a fast-growing category of fraud: QR code scams, often called "quishing" (QR phishing).

The Singapore Police Force and the Cyber Security Agency (CSA) have issued repeated advisories about scams involving tampered QR stickers, fake payment codes, and phishing links hidden inside QR images sent via WhatsApp, Telegram and email. This guide explains how these scams work in the Singapore context, highlights real cases, and gives you a practical checklist to stay safe.

What Are QR Code Scams?

A QR code scam is any fraud in which a criminal uses a QR code to trick a victim into visiting a malicious website, installing malware, or authorising an unwanted payment. Because a QR code is just a visual encoding of a URL or payload, users cannot read it with their eyes, they must trust whatever their phone camera decodes.

Scammers exploit this trust in three main ways in Singapore:

  1. Physical tampering: Sticking a fake QR code over a legitimate one at a hawker stall, bubble tea kiosk, or parking meter.
  2. Digital delivery: Sending QR images via WhatsApp, Telegram, email, or fake government letters that lead to phishing sites.
  3. Fake payment requests: Impersonating sellers on Carousell, Facebook Marketplace, or Telegram groups and sending QR codes that request money instead of sending it.

Why Singapore Is a High-Risk Target

Singapore's near-universal use of PayNow, PayLah!, GrabPay and SGQR has created a rich environment for QR-based fraud. A few factors make local users especially vulnerable:

  • High trust in institutions: Singaporeans are used to seeing official QR codes from IRAS, HDB, LTA, and SingPost, so a scam disguised as a government notice feels credible.
  • Speed of contactless payments: People scan and pay in seconds without checking merchant names carefully.
  • Multilingual scams: Scammers use English, Mandarin, Malay and Tamil to reach every demographic.
  • Cross-border payment apps: Tourists and residents scan foreign QR codes (Alipay, WeChat Pay) without knowing what a legitimate one should look like.

According to the Singapore Police Force's mid-year scam brief, e-commerce and phishing scams — many involving QR codes — continue to rank among the top five scam types by victim count, with losses running into the hundreds of millions of Singapore dollars annually.

Common Types of QR Code Scams in Singapore

1. Bubble Tea and F&B Survey Scams

One of the most publicised local cases involved an elderly woman who lost around S$20,000 after scanning a QR code stuck outside a bubble tea shop, supposedly for a free cup in exchange for a survey. The code installed a malicious Android app that gave scammers remote access to her banking app.

2. Hawker and Coffeeshop Payment Stickers

Scammers paste fake PayNow or SGQR stickers over the real ones at hawker centres and coffeeshops. Customers pay, the stall owner never receives the money, and the customer only realises when the vendor asks for payment again.

3. Parking Coupon and LTA Impersonation

Fake QR codes placed on car windscreens or parking meters claim to be from the Land Transport Authority or HDB parking. Scanning them leads to a cloned payment page that harvests card details.

4. Fake Government Letters

Physical letters or emails claiming to be from IRAS, MOM, ICA or CPF Board include a QR code directing users to a phishing site that mimics Singpass. Once credentials are entered, scammers hijack the Singpass account.

5. Carousell and Marketplace Refund Scams

A fake buyer or seller sends a QR code claiming it will "receive" a refund or deposit. In reality, scanning it initiates a PayNow transfer out of the victim's account.

6. Delivery and Parcel Scams

Fake missed-delivery notices claiming to be from SingPost, Ninja Van or J&T include a QR code for "re-delivery scheduling." The link asks for card details to pay a small redelivery fee — and then drains the account.

How Quishing Actually Works: The Attack Chain

Understanding the flow helps you spot the red flags before you scan.

  1. Bait: The scammer places a QR code somewhere trusted — a sticker, a poster, a WhatsApp message, an email.
  2. Scan: You point your phone camera at it. Your default browser opens a URL.
  3. Lookalike page: The page mimics DBS, OCBC, UOB, Singpass, PayLah! or a courier company. Fonts, colours and logos are almost perfect.
  4. Credential or app install: You are asked to log in, enter OTPs, or download an APK file (Android sideloading).
  5. Account takeover: With your credentials or a malicious accessibility-enabled app, the scammer transfers funds, often at 3–5am when you are asleep.

The MAS-mandated Money Lock feature and the Shared Responsibility Framework have reduced some losses, but they do not eliminate the risk — especially if you approve transactions yourself under social engineering pressure.

Red Flags: How to Spot a Suspicious QR Code

Red FlagWhat It Means
Sticker placed over another stickerPhysical tampering — peel and check underneath
QR code in an unsolicited email or SMSAlmost always phishing
URL preview shows unusual domain (.xyz, .top, .icu)Not a legitimate Singapore business or agency
Page asks you to download an APKMalware — legitimate SG banks never do this
Site requests Singpass login outside singpass.gov.sgPhishing — Singpass only lives on the official domain
QR code offers a "free" gift or lucky drawClassic bait, especially at F&B outlets
Merchant name in PayNow prompt doesn't match the stallDo not confirm the transfer

10 Practical Steps to Stay Safe

  1. Always preview the URL before opening. iOS and modern Android cameras show the destination link — read it carefully.
  2. Check the merchant name on PayNow. Before you tap "Transfer," confirm the recipient name matches the business.
  3. Never sideload APK files. Only install apps from Google Play or the Apple App Store. If a page tells you to enable "Install Unknown Apps," close it immediately.
  4. Turn on ScamShield. The ScamShield app by Open Government Products filters known scam numbers and links.
  5. Enable Money Lock on your bank account. DBS, OCBC and UOB all offer this — locked funds cannot be transferred out digitally.
  6. Use bank apps directly. Never log in to internet banking through a link from a QR code, SMS or email.
  7. Peel and inspect stickers at hawker centres, especially if the sticker looks newer than the surroundings.
  8. Keep your phone OS updated. Both Apple and Google patch QR-related vulnerabilities regularly.
  9. Educate elderly family members. They are the most-targeted group in Singapore scam statistics.
  10. Report suspicious codes to the ScamShield hotline (1799) or the SPF anti-scam website.

Safer Link Handling for Businesses and Content Creators

If you run a business, a school CCA, a religious organisation, or a marketing campaign in Singapore, the QR codes you issue are also a target. Scammers can replace them or clone your branded materials. A few good practices:

  • Use a link management platform that lets you monitor clicks and swap destinations if a code is compromised.
  • Print QR codes with your brand or logo embedded so tampered stickers are visually obvious.
  • Use HTTPS-only destination URLs on a domain you fully control.
  • Rotate promotional links after a campaign ends so old printed materials cannot be exploited later.

Tools like Lunyb allow you to generate short, trackable links that sit behind your QR codes, so if a code is misused or tampered with, you can disable or redirect the underlying URL without reprinting anything. If you want to compare options first, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.

Comparing Safe vs Unsafe QR Code Scenarios

ScenarioSafe SignalUnsafe Signal
Paying at a hawker stallSGQR sticker matches stall name, uncovered, printed under laminateFresh sticker layered on top, mismatched name in PayNow prompt
Government noticeLetter matches records in Singpass app inboxUrgent tone, QR code goes to non-.gov.sg domain
Marketing poster in MRTReputable brand, URL preview matches company domainSticker over official ad, generic short link with typos
Carousell transactionPayment through in-app CarouprotectSeller sends external QR via WhatsApp asking you to scan
Restaurant menuQR under table glass or on printed menuLoose sticker on the table edge that peels off

What to Do If You've Already Scanned a Scam QR Code

  1. Disconnect immediately. Turn on airplane mode to stop any ongoing data transfer.
  2. Do not enter any credentials. Close the browser tab.
  3. If you installed an APK: Boot your phone into Safe Mode and uninstall the app. Consider a factory reset if in doubt.
  4. Call your bank's 24/7 anti-scam hotline — DBS: 1800-339-6963, OCBC: 1800-363-3333, UOB: 1800-222-2121. Ask them to freeze your account.
  5. Change your Singpass and iBanking passwords from a clean device.
  6. File a police report at police.gov.sg/iwitness and call the Anti-Scam Helpline at 1799.
  7. Report to ScamShield so the malicious link can be blocklisted for others.

The Regulatory Picture in Singapore

Several agencies are actively pushing back against QR-based fraud:

  • MAS requires banks to implement kill switches, Money Lock, and default 12-hour cooling-off periods on high-risk activities.
  • IMDA works with telcos to block scam SMS senders and filter phishing URLs at network level.
  • CSA publishes advisories through SingCERT and the annual Singapore Cyber Landscape report.
  • SPF's Anti-Scam Command (ASCom) coordinates rapid fund recovery with banks — the first 24 hours after a scam are critical.

The Shared Responsibility Framework (SRF), effective from late 2024, distributes losses between banks, telcos and consumers depending on who failed which duty. But the fastest way to stay whole is still not to fall for the scam in the first place.

Frequently Asked Questions

Are QR codes themselves dangerous?

No. A QR code is just an image that encodes text — usually a URL. The danger comes from what the URL leads to. Treat every unfamiliar QR code the same way you would treat an unfamiliar link in an email: preview it, verify the domain, and never enter credentials unless you are certain of the site.

Can scanning a QR code hack my phone by itself?

Simply scanning a code cannot install malware on an up-to-date iPhone or Android device. However, if you follow the link, download an APK, and grant it accessibility permissions — which is what many Singapore scam pages instruct — then your device can be fully compromised. Keep your OS updated and never sideload apps.

Is PayNow safe to use with QR codes?

PayNow itself is secure and regulated by MAS. The weakness is human: users often ignore the recipient name shown on the confirmation screen. Always read the merchant name before tapping confirm. If it says something unrelated to the stall, cancel the transaction.

How can I tell if a Singpass login page is real?

The only legitimate Singpass domain is singpass.gov.sg. Any other domain — even ones with "singpass" in the middle of a longer URL — is a phishing attempt. The safest option is to open the Singpass app directly rather than logging in through a browser link.

Where do I report a QR code scam in Singapore?

Call the Anti-Scam Helpline at 1799, file an online report at police.gov.sg/iwitness, and forward suspicious SMS or URLs to ScamShield. If money has already left your account, call your bank's 24/7 fraud hotline first — every minute matters for fund recovery.

Final Thoughts

QR codes are here to stay in Singapore. They power our payments, our parking, our government services, and our shopping. The good news is that staying safe does not require avoiding them — it just requires a two-second habit: preview the link, check the merchant name, and never install anything a QR code tells you to install.

Share this guide with parents, grandparents and colleagues. In Singapore, the strongest anti-scam tool is not technology — it is a well-informed community that pauses for one extra second before tapping "confirm."

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles