QR Code Scams in Singapore: How to Stay Safe in 2026
Singapore is one of the most digitally connected societies in the world, and QR codes have become woven into daily life — from hawker centre payments and PayNow transfers to LTA parking, MRT posters, and restaurant menus. Unfortunately, that same convenience has opened the door to a fast-growing category of fraud: QR code scams, also known as "quishing" (QR phishing). The Singapore Police Force and the Cyber Security Agency of Singapore (CSA) have repeatedly warned the public about victims losing tens of thousands of dollars after simply scanning the wrong square of black-and-white dots.
This guide breaks down exactly how QR code scams work in Singapore, the most common local variations you should know about, and practical steps you can take to stay safe — whether you're paying at a bubble tea stall in Orchard, topping up parking at a HDB carpark, or scanning a poster at Changi Airport.
What Are QR Code Scams?
A QR code scam is a form of fraud where criminals use a malicious QR code to trick victims into visiting a phishing website, downloading malware, or authorising a payment to the scammer instead of the legitimate merchant. Because QR codes are unreadable to the human eye, victims cannot tell a legitimate code from a fraudulent one without scanning it first — and by then, it may be too late.
In Singapore, quishing has become particularly dangerous because so many trusted services — PayNow, NETS, SGQR, LTA, government agencies, and banks like DBS, OCBC, and UOB — rely on QR codes. Scammers exploit that trust by mimicking the visual style of these familiar systems.
Why Singapore Is a Prime Target
- High smartphone penetration: Over 90% of Singaporeans own a smartphone with a built-in QR scanner.
- SGQR ubiquity: The unified SGQR standard means people scan codes multiple times a day without thinking twice.
- Tourist and expat density: Visitors unfamiliar with local systems are easier to deceive.
- Fast digital payments: Transfers via PayNow are near-instant and often irreversible.
Common QR Code Scams in Singapore
Local law enforcement and CSA have flagged several recurring scam patterns. Understanding them is the first step to spotting one in the wild.
1. Sticker Overlay Scams at F&B and Retail Outlets
Scammers physically paste a fake QR code sticker over a legitimate SGQR sticker at hawker stalls, cafes, or small shops. When a customer scans it, the payment goes to the fraudster's account instead of the merchant's. Bubble tea shops, wet markets, and hawker centres have all been targeted.
2. "Free Milk Tea" and Survey Scams
One of the most publicised Singapore cases involved a woman who lost S$20,000 after scanning a QR code on a bubble tea shop's door offering a free cup for filling in a survey. The code led to a malicious Android app that gave scammers remote access to her banking app.
3. Fake Parking and Traffic Fine Notices
Fraudsters distribute fake parking summonses or LTA notices with QR codes pointing to phishing sites that impersonate the Singapore Police Force, LTA, or IRAS. Victims are prompted to "pay the fine" via a fake payment gateway.
4. Delivery and Package Scams
With the rise of e-commerce, fake SingPost, Ninja Van, or Shopee "missed delivery" cards are dropped into letterboxes. The QR code leads to a spoofed tracking page requesting credit card details or CDC/SingPass login.
5. Charity and Donation QR Codes
Scammers pose as volunteers from established Singaporean charities, presenting a QR code for donations. The code routes funds to a personal PayNow number rather than the actual charity.
6. Fake E-Commerce and Facebook Marketplace Listings
Sellers on Carousell or Facebook Marketplace send buyers a QR code claiming it's needed to "verify" or "receive" payment. Scanning it actually authorises an outgoing transfer from the victim's account.
How Quishing Actually Works
Understanding the technical flow helps you spot the warning signs earlier.
- Bait placement: The scammer places a malicious QR code somewhere plausible — a shopfront, a printed flyer, an email, or a social media ad.
- Scan and redirect: When scanned, the code opens a URL. Because most phone cameras just show a shortened or unfamiliar link, victims tap through without inspecting it.
- Impersonation site: The link leads to a page that looks nearly identical to DBS, OCBC, Singpass, or a delivery service.
- Data or app harvesting: The victim either enters credentials, installs a sideloaded APK, or grants Accessibility permissions to a rogue app.
- Account takeover: With login details or remote control, scammers drain bank accounts, sometimes waiting until the victim is asleep to bypass 2FA notifications.
Red Flags to Watch Out For
Before you scan any QR code in Singapore, run through this mental checklist:
- The QR sticker looks freshly pasted, misaligned, or covers another sticker underneath.
- The merchant name shown after scanning does not match the shop you're at.
- You're asked to download an APK file or an app from outside the Google Play Store or Apple App Store.
- The URL uses odd domains like .xyz, .top, .click, or misspellings such as "dbs-sg-secure.com".
- The page requests your Singpass login, banking OTP, or full NRIC on a non-official domain.
- You're pressured with urgency ("pay within 30 minutes or face a fine").
- A stranger hands you a printed QR code, especially in tourist areas.
How to Verify a QR Code Safely
Not every unfamiliar QR code is malicious, but every unfamiliar one deserves a two-second sanity check.
1. Preview the URL Before Opening
Both iOS and Android show a URL preview at the top of the screen when you scan. Read it carefully. If it doesn't match the merchant or service, don't tap.
2. Check the Merchant Name in Your Payment App
When paying via PayNow, DBS PayLah!, OCBC Digital, or GrabPay, always confirm the displayed merchant or recipient name before hitting confirm. If a hawker stall's payment shows a random personal name, walk away.
3. Use a URL Expander for Shortened Links
If a QR code resolves to a shortened link, you can paste it into a URL expander to see the true destination before visiting. Reputable link platforms like Lunyb also give businesses cleaner, branded short links with analytics — which makes it easier for consumers to recognise legitimate URLs versus suspicious ones. For more on choosing trustworthy link services, see our 2026 buyer's guide to URL shorteners.
4. Never Sideload Apps from a QR Code
No legitimate Singapore bank, government agency, or delivery firm will ever ask you to install an APK file from a QR code. Full stop.
5. Check for HTTPS and Domain Authenticity
Genuine Singapore government sites end in .gov.sg. Banks use their own well-known domains (dbs.com.sg, ocbc.com, uob.com.sg). Anything else purporting to be official is a scam.
Comparison: Legitimate vs. Malicious QR Code Scenarios
| Signal | Legitimate QR Code | Malicious QR Code |
|---|---|---|
| Placement | Printed on menu, laminated signage, or official receipt | Sticker pasted over existing signage, loose flyer, unsolicited email |
| Merchant Name on App | Matches the shop or service exactly | Personal name, random UEN, or mismatched business |
| Destination URL | Ends in .sg, .gov.sg, or a well-known brand domain | Odd TLDs, misspellings, IP addresses, or long random strings |
| App Installation | Never required, or directs to Play Store/App Store | Prompts APK download or "enable unknown sources" |
| Data Requested | Payment amount only | Singpass, OTP, NRIC, full card details |
| Urgency | None | Threats of fines, arrest, account closure |
What to Do If You've Been Scammed
Speed is critical. If you suspect you've scanned a malicious QR code or made a payment to a scammer:
- Freeze your bank account immediately. DBS, OCBC, UOB, and other Singapore banks offer a "kill switch" or emergency freeze in their apps. Use it before contacting anyone else.
- Uninstall any suspicious apps. If you sideloaded an APK, boot into Safe Mode and remove it. Consider a full factory reset if you granted Accessibility permissions.
- Change all critical passwords from a different, trusted device — starting with Singpass, banking, and email.
- Report to the Singapore Police Force via the ScamShield hotline at 1799 or file a report at police.gov.sg.
- Report the scam on the ScamShield app, which helps CSA track and block malicious numbers and links.
- Notify friends and family if the scammer may now have access to your messaging apps.
Protecting Businesses from QR Code Fraud
If you run a Singapore-based business — from a hawker stall to an SME — your customers can also be targeted by scammers hijacking your storefront. Protect your brand:
- Laminate SGQR stickers and inspect them daily for tampering or overlays.
- Place QR codes behind the counter where customers can see staff verify them.
- Train staff to spot unusual payment amounts or recipient names during checkout.
- Use branded short links for any marketing QR codes so customers see a domain they recognise rather than a random shortener. Read our honest review of Lunyb or our Rebrandly review for 2026 to see how branded links compare.
- Register with the Singapore Business Federation's anti-scam initiatives and stay updated on CSA advisories.
Broader Security Habits That Reduce QR Code Risk
QR code scams rarely succeed in isolation — they usually rely on weak account security to complete the theft. Strengthening your general digital hygiene makes quishing far less profitable for criminals.
Enable Money Lock and Transaction Limits
DBS, OCBC, and UOB all offer "Money Lock" features that ring-fence a portion of your savings so it cannot be transferred out digitally. Set your daily PayNow and overseas transfer limits to the lowest amount you realistically need.
Use App Store Downloads Only
Enable Google Play Protect on Android and never disable the "Install unknown apps" restriction. On iOS, only install apps from the official App Store.
Turn On Two-Factor Authentication Everywhere
Singpass, banking apps, and email accounts should all use 2FA — ideally with an authenticator app rather than SMS, which is vulnerable to SIM-swap attacks.
Keep Your Phone Updated
Many malicious APKs exploit known Android vulnerabilities patched months ago. Install operating system updates as soon as they're offered.
Use Encrypted DNS and a Trusted Browser
Configure your phone to use encrypted DNS (like Cloudflare 1.1.1.1 or Google 8.8.8.8 with DNS-over-HTTPS) so that even if you tap a phishing link, some malicious domains are blocked at the network level.
The Bigger Picture: Singapore's Anti-Scam Response
Singapore has been aggressive in fighting QR-related fraud. The Anti-Scam Command (ASCom), ScamShield app, mandatory bank kill switches, and shared fraud liability frameworks between banks and telcos all aim to reduce victim losses. Still, no framework replaces personal vigilance — the two-second pause before you scan is your most powerful defence.
Frequently Asked Questions
Are all QR codes at hawker centres safe to scan?
Most are, but not all. Always verify that the merchant name shown in your payment app matches the stall you're paying. If the recipient is a personal name or an unrelated business, cancel the transaction and alert stall staff.
Can simply scanning a QR code hack my phone?
Scanning alone rarely compromises your phone. The danger begins when you tap the link, enter credentials, or install an app. However, a malicious link could exploit an unpatched browser vulnerability, so keeping your OS and browser updated is essential.
What is the fastest way to report a QR code scam in Singapore?
Call the ScamShield helpline at 1799 or file an online report at police.gov.sg/iwitness. If money has already left your account, freeze the account immediately via your bank's app before making the report.
Do iPhones offer better protection against QR scams than Android phones?
iPhones are somewhat safer because iOS does not allow sideloading APK files, which is the delivery method for most banking-trojan quishing attacks in Singapore. However, phishing sites that steal Singpass or banking credentials work equally well on both platforms — so behaviour matters more than device.
Are branded short links safer than random QR code links?
Generally yes. Branded short links show a recognisable domain (like a company's own short domain), making it easier for consumers to verify legitimacy at a glance. Businesses using branded link platforms such as Lunyb or Rebrandly give their customers a clearer trust signal than anonymous shorteners.
Final Thoughts
QR code scams in Singapore are evolving quickly, but the defences are simple and consistent: pause before you scan, verify the merchant name, inspect the URL, never sideload apps, and lock down your bank account with the tools your bank already provides. Combined with national resources like ScamShield and CSA advisories, these habits will keep you — and your money — safely out of scammers' reach.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Password Manager vs Browser Passwords: Which Is Safer in 2026?
Browser password managers are convenient, but dedicated password managers offer stronger security, cross-platform support, and advanced features. This guide compares both options in detail so you can choose the safest way to protect your accounts in 2026.
Zero Trust Security Model Explained Simply: A Complete Guide
Zero Trust security replaces outdated perimeter defenses with a 'never trust, always verify' approach. Learn the core principles, benefits, and a step-by-step implementation roadmap in plain English.
Two-Factor Authentication: Why You Need It in 2026
Passwords alone can't protect your accounts in 2026. Learn how two-factor authentication works, which methods are safest, and how to enable 2FA on every account that matters in just a few minutes.
Data Breaches 2026: What You Need to Know
Data breaches in 2026 are faster, costlier, and increasingly AI-powered. This guide covers the latest statistics, major attack vectors, regulatory changes, and the practical steps individuals and businesses must take right now to stay protected.