QR Code Scams in Singapore: How to Stay Safe in 2026
Singapore is one of the most digitally connected societies in the world, and QR codes have become woven into daily life — from hawker centre payments and PayNow transfers to LTA parking, MRT posters, and restaurant menus. Unfortunately, that same convenience has opened the door to a fast-growing category of fraud: QR code scams, also known as "quishing" (QR phishing). The Singapore Police Force and the Cyber Security Agency of Singapore (CSA) have repeatedly warned the public about victims losing tens of thousands of dollars after simply scanning the wrong square of black-and-white dots.
This guide breaks down exactly how QR code scams work in Singapore, the most common local variations you should know about, and practical steps you can take to stay safe — whether you're paying at a bubble tea stall in Orchard, topping up parking at a HDB carpark, or scanning a poster at Changi Airport.
What Are QR Code Scams?
A QR code scam is a form of fraud where criminals use a malicious QR code to trick victims into visiting a phishing website, downloading malware, or authorising a payment to the scammer instead of the legitimate merchant. Because QR codes are unreadable to the human eye, victims cannot tell a legitimate code from a fraudulent one without scanning it first — and by then, it may be too late.
In Singapore, quishing has become particularly dangerous because so many trusted services — PayNow, NETS, SGQR, LTA, government agencies, and banks like DBS, OCBC, and UOB — rely on QR codes. Scammers exploit that trust by mimicking the visual style of these familiar systems.
Why Singapore Is a Prime Target
- High smartphone penetration: Over 90% of Singaporeans own a smartphone with a built-in QR scanner.
- SGQR ubiquity: The unified SGQR standard means people scan codes multiple times a day without thinking twice.
- Tourist and expat density: Visitors unfamiliar with local systems are easier to deceive.
- Fast digital payments: Transfers via PayNow are near-instant and often irreversible.
Common QR Code Scams in Singapore
Local law enforcement and CSA have flagged several recurring scam patterns. Understanding them is the first step to spotting one in the wild.
1. Sticker Overlay Scams at F&B and Retail Outlets
Scammers physically paste a fake QR code sticker over a legitimate SGQR sticker at hawker stalls, cafes, or small shops. When a customer scans it, the payment goes to the fraudster's account instead of the merchant's. Bubble tea shops, wet markets, and hawker centres have all been targeted.
2. "Free Milk Tea" and Survey Scams
One of the most publicised Singapore cases involved a woman who lost S$20,000 after scanning a QR code on a bubble tea shop's door offering a free cup for filling in a survey. The code led to a malicious Android app that gave scammers remote access to her banking app.
3. Fake Parking and Traffic Fine Notices
Fraudsters distribute fake parking summonses or LTA notices with QR codes pointing to phishing sites that impersonate the Singapore Police Force, LTA, or IRAS. Victims are prompted to "pay the fine" via a fake payment gateway.
4. Delivery and Package Scams
With the rise of e-commerce, fake SingPost, Ninja Van, or Shopee "missed delivery" cards are dropped into letterboxes. The QR code leads to a spoofed tracking page requesting credit card details or CDC/SingPass login.
5. Charity and Donation QR Codes
Scammers pose as volunteers from established Singaporean charities, presenting a QR code for donations. The code routes funds to a personal PayNow number rather than the actual charity.
6. Fake E-Commerce and Facebook Marketplace Listings
Sellers on Carousell or Facebook Marketplace send buyers a QR code claiming it's needed to "verify" or "receive" payment. Scanning it actually authorises an outgoing transfer from the victim's account.
How Quishing Actually Works
Understanding the technical flow helps you spot the warning signs earlier.
- Bait placement: The scammer places a malicious QR code somewhere plausible — a shopfront, a printed flyer, an email, or a social media ad.
- Scan and redirect: When scanned, the code opens a URL. Because most phone cameras just show a shortened or unfamiliar link, victims tap through without inspecting it.
- Impersonation site: The link leads to a page that looks nearly identical to DBS, OCBC, Singpass, or a delivery service.
- Data or app harvesting: The victim either enters credentials, installs a sideloaded APK, or grants Accessibility permissions to a rogue app.
- Account takeover: With login details or remote control, scammers drain bank accounts, sometimes waiting until the victim is asleep to bypass 2FA notifications.
Red Flags to Watch Out For
Before you scan any QR code in Singapore, run through this mental checklist:
- The QR sticker looks freshly pasted, misaligned, or covers another sticker underneath.
- The merchant name shown after scanning does not match the shop you're at.
- You're asked to download an APK file or an app from outside the Google Play Store or Apple App Store.
- The URL uses odd domains like .xyz, .top, .click, or misspellings such as "dbs-sg-secure.com".
- The page requests your Singpass login, banking OTP, or full NRIC on a non-official domain.
- You're pressured with urgency ("pay within 30 minutes or face a fine").
- A stranger hands you a printed QR code, especially in tourist areas.
How to Verify a QR Code Safely
Not every unfamiliar QR code is malicious, but every unfamiliar one deserves a two-second sanity check.
1. Preview the URL Before Opening
Both iOS and Android show a URL preview at the top of the screen when you scan. Read it carefully. If it doesn't match the merchant or service, don't tap.
2. Check the Merchant Name in Your Payment App
When paying via PayNow, DBS PayLah!, OCBC Digital, or GrabPay, always confirm the displayed merchant or recipient name before hitting confirm. If a hawker stall's payment shows a random personal name, walk away.
3. Use a URL Expander for Shortened Links
If a QR code resolves to a shortened link, you can paste it into a URL expander to see the true destination before visiting. Reputable link platforms like Lunyb also give businesses cleaner, branded short links with analytics — which makes it easier for consumers to recognise legitimate URLs versus suspicious ones. For more on choosing trustworthy link services, see our 2026 buyer's guide to URL shorteners.
4. Never Sideload Apps from a QR Code
No legitimate Singapore bank, government agency, or delivery firm will ever ask you to install an APK file from a QR code. Full stop.
5. Check for HTTPS and Domain Authenticity
Genuine Singapore government sites end in .gov.sg. Banks use their own well-known domains (dbs.com.sg, ocbc.com, uob.com.sg). Anything else purporting to be official is a scam.
Comparison: Legitimate vs. Malicious QR Code Scenarios
| Signal | Legitimate QR Code | Malicious QR Code |
|---|---|---|
| Placement | Printed on menu, laminated signage, or official receipt | Sticker pasted over existing signage, loose flyer, unsolicited email |
| Merchant Name on App | Matches the shop or service exactly | Personal name, random UEN, or mismatched business |
| Destination URL | Ends in .sg, .gov.sg, or a well-known brand domain | Odd TLDs, misspellings, IP addresses, or long random strings |
| App Installation | Never required, or directs to Play Store/App Store | Prompts APK download or "enable unknown sources" |
| Data Requested | Payment amount only | Singpass, OTP, NRIC, full card details |
| Urgency | None | Threats of fines, arrest, account closure |
What to Do If You've Been Scammed
Speed is critical. If you suspect you've scanned a malicious QR code or made a payment to a scammer:
- Freeze your bank account immediately. DBS, OCBC, UOB, and other Singapore banks offer a "kill switch" or emergency freeze in their apps. Use it before contacting anyone else.
- Uninstall any suspicious apps. If you sideloaded an APK, boot into Safe Mode and remove it. Consider a full factory reset if you granted Accessibility permissions.
- Change all critical passwords from a different, trusted device — starting with Singpass, banking, and email.
- Report to the Singapore Police Force via the ScamShield hotline at 1799 or file a report at police.gov.sg.
- Report the scam on the ScamShield app, which helps CSA track and block malicious numbers and links.
- Notify friends and family if the scammer may now have access to your messaging apps.
Protecting Businesses from QR Code Fraud
If you run a Singapore-based business — from a hawker stall to an SME — your customers can also be targeted by scammers hijacking your storefront. Protect your brand:
- Laminate SGQR stickers and inspect them daily for tampering or overlays.
- Place QR codes behind the counter where customers can see staff verify them.
- Train staff to spot unusual payment amounts or recipient names during checkout.
- Use branded short links for any marketing QR codes so customers see a domain they recognise rather than a random shortener. Read our honest review of Lunyb or our Rebrandly review for 2026 to see how branded links compare.
- Register with the Singapore Business Federation's anti-scam initiatives and stay updated on CSA advisories.
Broader Security Habits That Reduce QR Code Risk
QR code scams rarely succeed in isolation — they usually rely on weak account security to complete the theft. Strengthening your general digital hygiene makes quishing far less profitable for criminals.
Enable Money Lock and Transaction Limits
DBS, OCBC, and UOB all offer "Money Lock" features that ring-fence a portion of your savings so it cannot be transferred out digitally. Set your daily PayNow and overseas transfer limits to the lowest amount you realistically need.
Use App Store Downloads Only
Enable Google Play Protect on Android and never disable the "Install unknown apps" restriction. On iOS, only install apps from the official App Store.
Turn On Two-Factor Authentication Everywhere
Singpass, banking apps, and email accounts should all use 2FA — ideally with an authenticator app rather than SMS, which is vulnerable to SIM-swap attacks.
Keep Your Phone Updated
Many malicious APKs exploit known Android vulnerabilities patched months ago. Install operating system updates as soon as they're offered.
Use Encrypted DNS and a Trusted Browser
Configure your phone to use encrypted DNS (like Cloudflare 1.1.1.1 or Google 8.8.8.8 with DNS-over-HTTPS) so that even if you tap a phishing link, some malicious domains are blocked at the network level.
The Bigger Picture: Singapore's Anti-Scam Response
Singapore has been aggressive in fighting QR-related fraud. The Anti-Scam Command (ASCom), ScamShield app, mandatory bank kill switches, and shared fraud liability frameworks between banks and telcos all aim to reduce victim losses. Still, no framework replaces personal vigilance — the two-second pause before you scan is your most powerful defence.
Frequently Asked Questions
Are all QR codes at hawker centres safe to scan?
Most are, but not all. Always verify that the merchant name shown in your payment app matches the stall you're paying. If the recipient is a personal name or an unrelated business, cancel the transaction and alert stall staff.
Can simply scanning a QR code hack my phone?
Scanning alone rarely compromises your phone. The danger begins when you tap the link, enter credentials, or install an app. However, a malicious link could exploit an unpatched browser vulnerability, so keeping your OS and browser updated is essential.
What is the fastest way to report a QR code scam in Singapore?
Call the ScamShield helpline at 1799 or file an online report at police.gov.sg/iwitness. If money has already left your account, freeze the account immediately via your bank's app before making the report.
Do iPhones offer better protection against QR scams than Android phones?
iPhones are somewhat safer because iOS does not allow sideloading APK files, which is the delivery method for most banking-trojan quishing attacks in Singapore. However, phishing sites that steal Singpass or banking credentials work equally well on both platforms — so behaviour matters more than device.
Are branded short links safer than random QR code links?
Generally yes. Branded short links show a recognisable domain (like a company's own short domain), making it easier for consumers to verify legitimacy at a glance. Businesses using branded link platforms such as Lunyb or Rebrandly give their customers a clearer trust signal than anonymous shorteners.
Final Thoughts
QR code scams in Singapore are evolving quickly, but the defences are simple and consistent: pause before you scan, verify the merchant name, inspect the URL, never sideload apps, and lock down your bank account with the tools your bank already provides. Combined with national resources like ScamShield and CSA advisories, these habits will keep you — and your money — safely out of scammers' reach.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Irish Data Breaches 2026: What You Need to Know
Irish data breaches in 2026 are rising in volume and sophistication, driven by AI-powered phishing, ransomware, and supply-chain attacks. This guide covers the latest DPC enforcement trends, the 72-hour notification rules, top causes by sector, and practical steps Irish businesses and citizens should take right now.
Is Public WiFi Safe? The Truth in 2026
Is public WiFi safe in 2026? Universal HTTPS and encrypted DNS have made casual browsing much safer, but new threats like evil twin hotspots and captive portal phishing have taken their place. Here's what you actually need to worry about — and how to stay protected.
Social Engineering Attacks: A Complete Guide for 2026
Social engineering attacks exploit human psychology rather than technology, making them one of the most effective threats in cybersecurity today. This complete guide explains the most common attack types, real-world examples, and proven defenses for individuals and organizations.
Zero Trust Security Model Explained Simply: A 2026 Guide
Zero Trust security replaces the outdated 'trust everything inside the network' model with continuous verification of every user, device, and request. This guide explains the core principles, how it works, and how to implement it step by step — for both enterprises and small teams.