facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··9 min read

QR code scams have become one of the fastest-growing digital threats in Singapore. What began as a convenient way to pay for kopi at a hawker centre or check in during the pandemic has been quietly weaponised by scam syndicates. In 2024 alone, the Singapore Police Force reported losses in the tens of millions of dollars to phishing scams involving fraudulent QR codes, with victims ranging from bubble tea customers in Bukit Timah to elderly residents scanning stickers on parking meters.

This guide breaks down how QR code scams work in Singapore, the specific tactics local scammers use, and the practical steps you can take to protect yourself, your family, and your business.

What Are QR Code Scams?

A QR code scam is a form of phishing (often called "quishing") in which criminals trick victims into scanning a malicious QR code that redirects them to a fake website, downloads malware onto their device, or authorises fraudulent transactions. Because QR codes are essentially unreadable to the human eye, victims have no way of knowing where the code leads until it is too late.

In Singapore, where QR-based payments through PayNow, SGQR, NETS, and GrabPay are woven into daily life, scammers exploit the public's high trust in QR technology. A single sticker placed over a legitimate merchant code can funnel payments straight into a scammer's mule account.

Why Singapore Is a Prime Target

  • High QR adoption: SGQR unified payment codes are displayed at nearly every hawker stall, retail outlet, and taxi.
  • Digital-first population: Over 90% of Singaporeans use mobile banking apps.
  • Trusted brands: Scammers impersonate DBS, OCBC, UOB, SingPass, IRAS, and government agencies.
  • Multilingual society: Fake messages can be tailored in English, Mandarin, Malay, or Tamil to widen the net.

Common Types of QR Code Scams in Singapore

Scammers have refined several playbooks specifically targeting Singaporean consumers and businesses. Understanding each one helps you spot red flags before you scan.

1. The Bubble Tea and F&B Survey Scam

This scam made national headlines when a 60-year-old woman lost S$20,000 after scanning a QR code sticker offering a free cup of milk tea in exchange for completing a survey. The code prompted her to download a third-party Android app that granted scammers remote access to her phone. They then drained her bank account overnight while she slept.

Variants include free durian promotions, bak kwa vouchers, and "lucky draw" stickers pasted on shopfronts in Chinatown, Geylang, and heartland malls.

2. Fake Parking and ERP Fines

Scammers place counterfeit notices on windscreens in HDB carparks or near URA-managed lots claiming an unpaid parking fine. The QR code leads to a spoofed LTA or HDB website requesting SingPass login and credit card details.

3. Merchant Payment Overlay Scam

Fraudsters walk into a busy hawker centre and paste their own SGQR sticker directly on top of a stall's legitimate code. Customers pay via PayNow, but the money flows to a scammer-controlled mule account. The hawker only realises at the end of the day when takings are missing.

4. Fake Banking or SingPass Alerts

Victims receive an SMS or email urging them to "verify their account" or "reactivate SingPass" by scanning a QR code. The code leads to a pixel-perfect clone of the DBS digibank, OCBC, or SingPass login page. Once credentials are entered, scammers empty the account within minutes.

5. Phishing via Shortened or Disguised Links

Some QR codes hide behind link shorteners or long redirect chains to disguise the true destination. Legitimate businesses in Singapore increasingly use trusted, transparent shorteners like Lunyb that let users preview the destination URL before clicking, but scammers deliberately use obscure services with no preview feature to hide malicious domains.

6. Delivery Scam QR Codes

Fake SingPost, Ninja Van, or Qxpress "missed delivery" cards are slipped into letterboxes across Singapore. Scanning the QR code leads to a page requesting a small "redelivery fee" and full card details.

How to Identify a Malicious QR Code

Follow this quick checklist every time you are about to scan a QR code in public or from a message.

  1. Inspect the physical surface. Look for a sticker pasted over another code, peeling edges, or mismatched printing quality.
  2. Preview the URL before opening. Modern iPhone and Android cameras display the destination link before you tap. Read it carefully.
  3. Check the domain. Legitimate Singapore government sites end in .gov.sg. Banks use official domains like dbs.com.sg or ocbc.com, not dbs-verify.xyz or ocbc-login.top.
  4. Watch for urgency. "Your account will be frozen in 24 hours" is a classic scam trigger.
  5. Never download apps from a QR code. Only install apps from the official Apple App Store or Google Play Store.
  6. Confirm with the merchant. If you are paying at a hawker stall, ask the owner to confirm the PayNow name that appears on your screen matches their business.

QR Code Scam Red Flags: At a Glance

Red FlagLegitimate BehaviourLikely Scam
Payee name on PayNowMatches business name (e.g. "ABC HAWKER PTE LTD")Personal name or unrelated company
URL after scanningOfficial domain ending in .sg, .com.sg, .gov.sgRandom subdomains, .xyz, .top, misspellings
App download requestRedirects to App Store / Play StoreDownloads an APK or unknown installer
Sticker conditionPrinted as part of signage, laminated cleanlyLoose sticker over another code, uneven edges
Request for SingPassOnly through the official Singpass appWebsite form asking for NRIC + password

What to Do If You Have Scanned a Malicious QR Code

Speed is critical. Scammers often act within minutes of obtaining credentials or installing malware.

  1. Disconnect immediately. Turn on flight mode to cut off internet and mobile data.
  2. Do not enter any credentials. Close the browser tab or app.
  3. Contact your bank. Call the 24/7 anti-scam hotlines: DBS (1800 339 6963), OCBC (1800 363 3333), UOB (1800 222 2121). Freeze cards and accounts.
  4. Reset your SingPass password at singpass.gov.sg from a trusted device.
  5. Run a mobile security scan. Use Google Play Protect or a reputable mobile anti-malware app.
  6. Uninstall any suspicious apps installed in the past 24 hours. Factory-reset the phone if remote-access malware is suspected.
  7. Report to the authorities. Call the ScamShield Helpline at 1799 or file a police report at police.gov.sg/iwitness.
  8. Report to ScamShield. Forward suspicious messages to 9-SPF-SPF-9 (9773 7739) via SMS.

How to Protect Yourself Long-Term

Enable the ScamShield App

Developed by the National Crime Prevention Council and Open Government Products, ScamShield blocks scam calls and filters known phishing SMS. Every Singapore resident should install it.

Use the Money Lock Feature

DBS, OCBC, UOB, and Standard Chartered now offer a "Money Lock" feature that ring-fences a portion of your savings so it cannot be transferred out digitally, even if scammers gain full access to your banking app.

Turn On Anti-Malware Protections

Since 2024, all major Singapore banks require the Google Play Protect security check to be enabled before their apps will run. Do not disable it. On iOS, keep Lockdown Mode as an option if you are a high-risk user.

Verify Shortened Links Before Scanning

QR codes often encode shortened URLs. If you run a business and need to publish QR codes on menus, receipts, or marketing materials, choose a shortener that provides link previews, HTTPS by default, and transparent analytics. Our guide to the best URL shorteners in 2026 compares the safest options, and readers curious about specific platforms can also read our honest review of Lunyb or our Rebrandly review.

Educate Vulnerable Family Members

Elderly parents and grandparents are disproportionately targeted. Walk them through the basics: never scan a code that arrives by SMS, never download an APK, and always call you before making a transfer above S$500.

Advice for Singapore Businesses and Hawkers

If you accept SGQR or PayNow payments, you are also a target. Scammers who paste fake codes over yours can quietly siphon a day's takings.

  • Laminate and mount your SGQR code behind a rigid, tamper-evident cover.
  • Inspect your QR code at the start and end of each shift.
  • Ask customers to show you the payee name before confirming payment.
  • Enable transaction notifications so you know instantly when a payment lands.
  • Report tampering to the police and to your bank's merchant support line.

The Regulatory Response in Singapore

The Monetary Authority of Singapore (MAS), the Infocomm Media Development Authority (IMDA), and the Singapore Police Force have rolled out several initiatives:

  • Shared Responsibility Framework (SRF) — banks and telcos may share liability for scam losses if they fail their duties.
  • Anti-Scam Command (ASCom) — a dedicated police unit that has recovered hundreds of millions in scam proceeds.
  • SMS Sender ID Registry — blocks unregistered alphanumeric SMS senders that impersonate banks.
  • Kill Switches — most banks now allow customers to instantly lock their accounts via app or hotline.

Frequently Asked Questions

Are QR code scams really that common in Singapore?

Yes. The Singapore Police Force has flagged QR-code-related phishing as a top-five scam category in recent years, with high-profile cases involving bubble tea surveys, fake parking fines, and cloned bank pages. Losses per victim frequently exceed S$10,000.

Is it safe to scan QR codes at hawker centres and coffee shops?

Generally yes, but always confirm that the payee name on the PayNow or SGQR screen matches the stall's registered business name before hitting confirm. If the payee is an individual's personal name at a well-known chain, stop and alert the stall owner.

Can scanning a QR code install malware on my iPhone or Android?

Simply scanning a QR code does not install malware on its own. The danger arises if the code sends you to a website that then prompts you to download an app (especially an APK on Android) or enter credentials. Never install apps from outside the App Store or Play Store.

What should I do if I paid a scammer via PayNow?

Call your bank's anti-scam hotline immediately, ideally within 30 minutes. Provide the transaction reference so the bank can attempt to freeze the receiving mule account. Then file a police report at police.gov.sg/iwitness and call the ScamShield Helpline at 1799.

Does ScamShield block malicious QR codes?

ScamShield primarily blocks scam calls and SMS. It does not scan physical QR codes, but it can flag suspicious links you paste into your browser and warn you about known phishing domains. Combine it with cautious scanning habits for the best protection.

Final Thoughts

QR codes are not going away — they are too deeply embedded in Singapore's payment, transport, and government services. The good news is that avoiding QR code scams comes down to a handful of habits: preview every link, verify every payee, never download apps from a code, and never share SingPass or banking credentials on a page you reached via a scan. Stay skeptical, stay slow, and when in doubt, don't scan.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles