facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

Singapore is one of the most digitally connected societies in the world, and QR codes have become woven into daily life — from hawker centre payments and PayNow transfers to LTA parking, MRT posters, and restaurant menus. Unfortunately, that same convenience has opened the door to a fast-growing category of fraud: QR code scams, also known as "quishing" (QR phishing). The Singapore Police Force and the Cyber Security Agency of Singapore (CSA) have repeatedly warned the public about victims losing tens of thousands of dollars after simply scanning the wrong square of black-and-white dots.

This guide breaks down exactly how QR code scams work in Singapore, the most common local variations you should know about, and practical steps you can take to stay safe — whether you're paying at a bubble tea stall in Orchard, topping up parking at a HDB carpark, or scanning a poster at Changi Airport.

What Are QR Code Scams?

A QR code scam is a form of fraud where criminals use a malicious QR code to trick victims into visiting a phishing website, downloading malware, or authorising a payment to the scammer instead of the legitimate merchant. Because QR codes are unreadable to the human eye, victims cannot tell a legitimate code from a fraudulent one without scanning it first — and by then, it may be too late.

In Singapore, quishing has become particularly dangerous because so many trusted services — PayNow, NETS, SGQR, LTA, government agencies, and banks like DBS, OCBC, and UOB — rely on QR codes. Scammers exploit that trust by mimicking the visual style of these familiar systems.

Why Singapore Is a Prime Target

  • High smartphone penetration: Over 90% of Singaporeans own a smartphone with a built-in QR scanner.
  • SGQR ubiquity: The unified SGQR standard means people scan codes multiple times a day without thinking twice.
  • Tourist and expat density: Visitors unfamiliar with local systems are easier to deceive.
  • Fast digital payments: Transfers via PayNow are near-instant and often irreversible.

Common QR Code Scams in Singapore

Local law enforcement and CSA have flagged several recurring scam patterns. Understanding them is the first step to spotting one in the wild.

1. Sticker Overlay Scams at F&B and Retail Outlets

Scammers physically paste a fake QR code sticker over a legitimate SGQR sticker at hawker stalls, cafes, or small shops. When a customer scans it, the payment goes to the fraudster's account instead of the merchant's. Bubble tea shops, wet markets, and hawker centres have all been targeted.

2. "Free Milk Tea" and Survey Scams

One of the most publicised Singapore cases involved a woman who lost S$20,000 after scanning a QR code on a bubble tea shop's door offering a free cup for filling in a survey. The code led to a malicious Android app that gave scammers remote access to her banking app.

3. Fake Parking and Traffic Fine Notices

Fraudsters distribute fake parking summonses or LTA notices with QR codes pointing to phishing sites that impersonate the Singapore Police Force, LTA, or IRAS. Victims are prompted to "pay the fine" via a fake payment gateway.

4. Delivery and Package Scams

With the rise of e-commerce, fake SingPost, Ninja Van, or Shopee "missed delivery" cards are dropped into letterboxes. The QR code leads to a spoofed tracking page requesting credit card details or CDC/SingPass login.

5. Charity and Donation QR Codes

Scammers pose as volunteers from established Singaporean charities, presenting a QR code for donations. The code routes funds to a personal PayNow number rather than the actual charity.

6. Fake E-Commerce and Facebook Marketplace Listings

Sellers on Carousell or Facebook Marketplace send buyers a QR code claiming it's needed to "verify" or "receive" payment. Scanning it actually authorises an outgoing transfer from the victim's account.

How Quishing Actually Works

Understanding the technical flow helps you spot the warning signs earlier.

  1. Bait placement: The scammer places a malicious QR code somewhere plausible — a shopfront, a printed flyer, an email, or a social media ad.
  2. Scan and redirect: When scanned, the code opens a URL. Because most phone cameras just show a shortened or unfamiliar link, victims tap through without inspecting it.
  3. Impersonation site: The link leads to a page that looks nearly identical to DBS, OCBC, Singpass, or a delivery service.
  4. Data or app harvesting: The victim either enters credentials, installs a sideloaded APK, or grants Accessibility permissions to a rogue app.
  5. Account takeover: With login details or remote control, scammers drain bank accounts, sometimes waiting until the victim is asleep to bypass 2FA notifications.

Red Flags to Watch Out For

Before you scan any QR code in Singapore, run through this mental checklist:

  • The QR sticker looks freshly pasted, misaligned, or covers another sticker underneath.
  • The merchant name shown after scanning does not match the shop you're at.
  • You're asked to download an APK file or an app from outside the Google Play Store or Apple App Store.
  • The URL uses odd domains like .xyz, .top, .click, or misspellings such as "dbs-sg-secure.com".
  • The page requests your Singpass login, banking OTP, or full NRIC on a non-official domain.
  • You're pressured with urgency ("pay within 30 minutes or face a fine").
  • A stranger hands you a printed QR code, especially in tourist areas.

How to Verify a QR Code Safely

Not every unfamiliar QR code is malicious, but every unfamiliar one deserves a two-second sanity check.

1. Preview the URL Before Opening

Both iOS and Android show a URL preview at the top of the screen when you scan. Read it carefully. If it doesn't match the merchant or service, don't tap.

2. Check the Merchant Name in Your Payment App

When paying via PayNow, DBS PayLah!, OCBC Digital, or GrabPay, always confirm the displayed merchant or recipient name before hitting confirm. If a hawker stall's payment shows a random personal name, walk away.

3. Use a URL Expander for Shortened Links

If a QR code resolves to a shortened link, you can paste it into a URL expander to see the true destination before visiting. Reputable link platforms like Lunyb also give businesses cleaner, branded short links with analytics — which makes it easier for consumers to recognise legitimate URLs versus suspicious ones. For more on choosing trustworthy link services, see our 2026 buyer's guide to URL shorteners.

4. Never Sideload Apps from a QR Code

No legitimate Singapore bank, government agency, or delivery firm will ever ask you to install an APK file from a QR code. Full stop.

5. Check for HTTPS and Domain Authenticity

Genuine Singapore government sites end in .gov.sg. Banks use their own well-known domains (dbs.com.sg, ocbc.com, uob.com.sg). Anything else purporting to be official is a scam.

Comparison: Legitimate vs. Malicious QR Code Scenarios

SignalLegitimate QR CodeMalicious QR Code
PlacementPrinted on menu, laminated signage, or official receiptSticker pasted over existing signage, loose flyer, unsolicited email
Merchant Name on AppMatches the shop or service exactlyPersonal name, random UEN, or mismatched business
Destination URLEnds in .sg, .gov.sg, or a well-known brand domainOdd TLDs, misspellings, IP addresses, or long random strings
App InstallationNever required, or directs to Play Store/App StorePrompts APK download or "enable unknown sources"
Data RequestedPayment amount onlySingpass, OTP, NRIC, full card details
UrgencyNoneThreats of fines, arrest, account closure

What to Do If You've Been Scammed

Speed is critical. If you suspect you've scanned a malicious QR code or made a payment to a scammer:

  1. Freeze your bank account immediately. DBS, OCBC, UOB, and other Singapore banks offer a "kill switch" or emergency freeze in their apps. Use it before contacting anyone else.
  2. Uninstall any suspicious apps. If you sideloaded an APK, boot into Safe Mode and remove it. Consider a full factory reset if you granted Accessibility permissions.
  3. Change all critical passwords from a different, trusted device — starting with Singpass, banking, and email.
  4. Report to the Singapore Police Force via the ScamShield hotline at 1799 or file a report at police.gov.sg.
  5. Report the scam on the ScamShield app, which helps CSA track and block malicious numbers and links.
  6. Notify friends and family if the scammer may now have access to your messaging apps.

Protecting Businesses from QR Code Fraud

If you run a Singapore-based business — from a hawker stall to an SME — your customers can also be targeted by scammers hijacking your storefront. Protect your brand:

  • Laminate SGQR stickers and inspect them daily for tampering or overlays.
  • Place QR codes behind the counter where customers can see staff verify them.
  • Train staff to spot unusual payment amounts or recipient names during checkout.
  • Use branded short links for any marketing QR codes so customers see a domain they recognise rather than a random shortener. Read our honest review of Lunyb or our Rebrandly review for 2026 to see how branded links compare.
  • Register with the Singapore Business Federation's anti-scam initiatives and stay updated on CSA advisories.

Broader Security Habits That Reduce QR Code Risk

QR code scams rarely succeed in isolation — they usually rely on weak account security to complete the theft. Strengthening your general digital hygiene makes quishing far less profitable for criminals.

Enable Money Lock and Transaction Limits

DBS, OCBC, and UOB all offer "Money Lock" features that ring-fence a portion of your savings so it cannot be transferred out digitally. Set your daily PayNow and overseas transfer limits to the lowest amount you realistically need.

Use App Store Downloads Only

Enable Google Play Protect on Android and never disable the "Install unknown apps" restriction. On iOS, only install apps from the official App Store.

Turn On Two-Factor Authentication Everywhere

Singpass, banking apps, and email accounts should all use 2FA — ideally with an authenticator app rather than SMS, which is vulnerable to SIM-swap attacks.

Keep Your Phone Updated

Many malicious APKs exploit known Android vulnerabilities patched months ago. Install operating system updates as soon as they're offered.

Use Encrypted DNS and a Trusted Browser

Configure your phone to use encrypted DNS (like Cloudflare 1.1.1.1 or Google 8.8.8.8 with DNS-over-HTTPS) so that even if you tap a phishing link, some malicious domains are blocked at the network level.

The Bigger Picture: Singapore's Anti-Scam Response

Singapore has been aggressive in fighting QR-related fraud. The Anti-Scam Command (ASCom), ScamShield app, mandatory bank kill switches, and shared fraud liability frameworks between banks and telcos all aim to reduce victim losses. Still, no framework replaces personal vigilance — the two-second pause before you scan is your most powerful defence.

Frequently Asked Questions

Are all QR codes at hawker centres safe to scan?

Most are, but not all. Always verify that the merchant name shown in your payment app matches the stall you're paying. If the recipient is a personal name or an unrelated business, cancel the transaction and alert stall staff.

Can simply scanning a QR code hack my phone?

Scanning alone rarely compromises your phone. The danger begins when you tap the link, enter credentials, or install an app. However, a malicious link could exploit an unpatched browser vulnerability, so keeping your OS and browser updated is essential.

What is the fastest way to report a QR code scam in Singapore?

Call the ScamShield helpline at 1799 or file an online report at police.gov.sg/iwitness. If money has already left your account, freeze the account immediately via your bank's app before making the report.

Do iPhones offer better protection against QR scams than Android phones?

iPhones are somewhat safer because iOS does not allow sideloading APK files, which is the delivery method for most banking-trojan quishing attacks in Singapore. However, phishing sites that steal Singpass or banking credentials work equally well on both platforms — so behaviour matters more than device.

Are branded short links safer than random QR code links?

Generally yes. Branded short links show a recognisable domain (like a company's own short domain), making it easier for consumers to verify legitimacy at a glance. Businesses using branded link platforms such as Lunyb or Rebrandly give their customers a clearer trust signal than anonymous shorteners.

Final Thoughts

QR code scams in Singapore are evolving quickly, but the defences are simple and consistent: pause before you scan, verify the merchant name, inspect the URL, never sideload apps, and lock down your bank account with the tools your bank already provides. Combined with national resources like ScamShield and CSA advisories, these habits will keep you — and your money — safely out of scammers' reach.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles