QR Code Scams in Singapore: How to Stay Safe in 2026
Singapore has one of the highest smartphone penetration rates in the world, and QR codes are woven into daily life — from paying at hawker centres with PayNow and SGQR to logging in at co-working spaces, ordering food, and topping up EZ-Link cards. Unfortunately, scammers know this too. In 2024 and 2025, the Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) issued repeated warnings about a surge in "quishing" — phishing attacks that hide behind QR codes.
This guide explains how QR code scams in Singapore work, the most common tactics used against locals and tourists, and the concrete steps you can take to stay safe.
What Are QR Code Scams?
A QR code scam is any fraud where a malicious QR code is used to trick you into visiting a fake website, downloading malware, authorising a payment, or handing over personal information. Because a QR code is just a machine-readable link, you cannot tell by looking whether it is safe — and that is exactly what scammers exploit.
In Singapore, these scams have appeared on parking meters, restaurant tables, bubble tea stalls, survey flyers, delivery notices, and even fake SingPost or IRAS letters. The Singapore Police Force reported that victims of phishing scams (including QR-based ones) lost tens of millions of dollars in recent years, with individual losses ranging from a few hundred to over S$100,000.
How QR Code Scams Work in Singapore
Most quishing attacks in Singapore follow a predictable pattern. Understanding the steps helps you spot them earlier.
- Placement or delivery. The scammer places a fake QR code sticker over a legitimate one, hands out a flyer, or sends a code via WhatsApp, SMS, or email.
- Enticement. The message promises a reward — free bubble tea, a supermarket voucher, a customer feedback prize, or a small cash incentive.
- Redirect to a fake site. Scanning the code opens a page that mimics DBS, OCBC, UOB, Singpass, or a well-known retailer.
- Credential or OTP harvest. You are asked to log in, enter your NRIC, or approve a transaction, sometimes through a fake app you're urged to install.
- Account takeover. With your credentials, the scammer drains your bank account, often using a malicious Android app that intercepts SMS OTPs.
The Bubble Tea Survey Scam
One of the most publicised cases involved a woman who lost S$20,000 after scanning a QR code on a flyer offering free bubble tea in exchange for a short survey. The code led to a malicious Android app that gave scammers remote access to her phone. This case became a national warning about QR-based malware in Singapore.
Parking and E-Payment Scams
Scammers have been caught pasting fake QR stickers over legitimate parking payment codes, particularly in tourist-heavy areas. Victims believe they are paying for parking through the Parking.sg equivalent or a Nets link, but the money is routed to a scammer-controlled wallet.
Common Types of QR Code Scams in Singapore
1. Quishing (QR Phishing)
The QR code leads to a lookalike login page for DBS, POSB, OCBC, UOB, Singpass, or SingPost. Once you enter your credentials and OTP, scammers log in on the real site and transfer funds.
2. Malicious App Downloads
Especially on Android, scanning may prompt a download of an .apk file outside the Play Store. These apps request accessibility permissions, allowing scammers to see your screen, keystrokes, and SMS codes.
3. Fake Payment QR Codes
At hawker stalls, cafés, or roadside vendors, a scammer replaces the merchant's SGQR or PayNow code with their own. Customers pay, the vendor doesn't receive the money, and the dispute is often only discovered later.
4. Delivery and Parcel Scams
A "missed delivery" notice from SingPost, Ninja Van, or a courier includes a QR code to "reschedule" or "pay a redelivery fee." The link leads to a card-harvesting page.
5. Government Impersonation
Fake IRAS tax refund letters, MOM work-pass notices, or ICA immigration reminders include QR codes leading to fraudulent Singpass login pages.
6. Charity and Donation Scams
During festive periods or after disasters, scammers distribute QR codes claiming to support local charities. The funds go to private wallets rather than registered Institutions of a Public Character (IPCs).
Red Flags: How to Spot a Suspicious QR Code
Before you scan any QR code in Singapore, run through this quick mental checklist:
- Is it a sticker on top of another code? Peel test: legitimate QR codes are usually printed directly on menus, signage, or receipts.
- Does the URL preview look right? Modern iPhones and Android phones show a URL preview before opening. Look for ".sg" domains, correct spelling, and no strange subdomains like
dbs.secure-login-sg.xyz. - Are you being rushed? "Scan within 5 minutes to claim your prize" is a classic pressure tactic.
- Are you asked to install an app outside the App Store or Play Store? Never sideload apps from a QR code.
- Does the page ask for OTPs, NRIC, or Singpass credentials? Legitimate promotions never need these.
- Is the offer too good? Free vouchers, cash rebates, or lucky draws from unknown brands are almost always scams.
What to Do Before You Scan Any QR Code
- Inspect the physical code. Check for stickers layered on top of the original.
- Use your phone's built-in camera. It shows the destination URL before opening — safer than third-party scanner apps that may auto-redirect.
- Read the URL carefully. Look for the correct domain (e.g.,
dbs.com.sg, notdbs-sg.top). - Expand shortened links when possible. If the code hides behind a link shortener you don't recognise, use a link-expander tool or paste the URL into a URL-preview service.
- Pause before entering anything sensitive. Ask yourself: would this brand really ask me this here?
How to Verify Short Links Safely
Many QR codes wrap their destination in a shortened URL to save space. That's normal, but it also gives scammers cover. Reputable short-link platforms publish transparent policies, scan destinations for malware, and let recipients preview links before opening.
If you frequently create QR codes for your own business, use a shortener with strong abuse controls, HTTPS, and analytics so you can spot suspicious redirects quickly. Services like Lunyb are built with security-conscious defaults and are reviewed in our 2026 buyer's guide to URL shorteners. For businesses that need branded links on collateral, our Rebrandly review also covers enterprise-grade options.
Protecting Your Phone and Accounts
Enable Money Lock and Banking App Protections
Most Singapore banks — DBS, OCBC, UOB, and Standard Chartered — now offer a "Money Lock" feature that ring-fences a portion of your savings so it cannot be transferred digitally. Turn it on for the majority of your balance.
Turn On Anti-Scam Tools Built Into Your Phone
Both iOS and Android now block sideloaded apps by default and warn about suspicious links. On Android, keep Google Play Protect enabled. On iOS, keep Lockdown Mode as an option for high-risk periods.
Use ScamShield
The ScamShield app, developed by the National Crime Prevention Council and Open Government Products, blocks known scam calls and SMS messages. It's free and specifically built for Singapore.
Enable Multi-Factor Authentication Everywhere
Use app-based authenticators (Google Authenticator, Microsoft Authenticator) instead of SMS OTPs where possible. SMS codes can be intercepted by malicious apps.
Keep Singpass Face Verification Active
Face verification adds a strong layer against unauthorised Singpass logins, which are a common target of QR phishing.
What to Do If You've Scanned a Suspicious QR Code
- Do not enter any details on the page that opened. Close the browser tab immediately.
- Disconnect from the internet if you downloaded anything. Turn on Airplane Mode.
- Uninstall any app installed as a result of the scan. On Android, boot into Safe Mode if the app resists removal.
- Change your passwords for banking, email, and Singpass from a different, trusted device.
- Call your bank's 24/7 anti-scam hotline immediately if you entered banking details. DBS: 1800-339-6963. OCBC: 1800-363-3333. UOB: 1800-222-2121.
- Report to the police via the ScamShield app or the Anti-Scam Hotline at 1800-722-6688.
- Lodge a report on the SPF's website at police.gov.sg/iwitness.
- Factory reset your phone if malware is suspected, after backing up photos and contacts to a trusted cloud account.
Advice for Businesses Using QR Codes in Singapore
If you run an F&B outlet, retail store, or event and use QR codes for menus, payments, or check-ins, you have a responsibility to protect customers too.
- Laminate or emboss your codes so stickers can't easily be pasted over them.
- Check your codes daily during opening — a quick self-scan takes 5 seconds.
- Use branded short links so customers recognise your domain in the URL preview.
- Display your PayNow UEN or business name clearly on payment signage so customers can verify recipient details before confirming.
- Train staff to explain to customers what a legitimate code looks like.
Advice for Tourists Visiting Singapore
Tourists are a favourite target because they don't know local brands, banks, or normal payment flows. If you're visiting Singapore:
- Use credit cards or contactless payments at hawker stalls when possible — most now accept them.
- Only scan payment QR codes at counters, not those handed to you loose or on flyers.
- Verify the recipient name shown in your banking app before approving any PayNow transfer.
- Avoid downloading any Singapore "discount" or "tourist reward" apps from QR codes.
The Bigger Picture: Why Quishing Is Growing
QR code scams work because they exploit trust. In Singapore, QR codes symbolise convenience and modernity — SGQR, PayNow, Singpass QR login, and SafeEntry (during the pandemic) all trained people to scan quickly and act quickly. Scammers piggyback on that trained behaviour.
Email filters and SMS blockers now catch most traditional phishing text, but a QR code sails right past them — it's just an image. It also bypasses corporate URL scanners because the click happens on a personal phone, not a work laptop. That's why quishing is the fastest-growing category of phishing globally, and Singapore is no exception.
The good news is that awareness works. Every red flag you learn to recognise is one fewer attack that can succeed. Slowing down for two seconds before you scan — checking the sticker, checking the URL, checking the request — is the single most effective habit you can build.
Frequently Asked Questions
Are QR code scams common in Singapore?
Yes. The Singapore Police Force and CSA have flagged QR code phishing (quishing) as one of the fastest-growing scam categories, with victims losing millions of dollars combined in recent years. Cases involving fake bubble tea surveys, parking meters, and delivery notices are frequently reported.
Is it safe to scan QR codes at hawker centres and restaurants?
Generally yes, but always inspect the code for tampering (stickers layered on top), check that the URL preview matches the restaurant or a known payments provider, and verify the recipient name in your banking app before confirming any PayNow transfer.
What should I do if I already scanned a scam QR code?
Close the page immediately, do not enter any credentials, uninstall any app you downloaded, disconnect from the internet, change your banking and Singpass passwords from a different device, and call your bank's anti-scam hotline plus the Anti-Scam Hotline at 1800-722-6688.
Do iPhones or Android phones handle malicious QR codes better?
Both platforms show a URL preview before opening, which is the key defence. iPhones are generally harder to compromise because sideloading apps is restricted. Android is safer when Google Play Protect is enabled and installing apps from unknown sources is disabled — never approve an .apk download from a QR code.
How can I check where a shortened QR code link goes without opening it?
Use your phone's built-in camera to reveal the URL preview, then either read it carefully or paste it into a link-expander/URL-preview website on a desktop browser. Reputable link shorteners also allow safe redirection with malware scanning built in.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Irish Data Breaches 2026: What You Need to Know
Irish data breaches are hitting record highs in 2026, driven by ransomware, AI phishing and third-party attacks. This guide covers the biggest incidents, DPC enforcement trends, your legal obligations, and practical steps to protect your organisation and personal data.
Is Public WiFi Safe? The Truth in 2026
Is public WiFi safe in 2026? The honest answer is more nuanced than either the alarmist warnings or the reassuring "HTTPS fixes everything" narrative suggests. This guide breaks down what has actually changed, which threats remain real, and exactly how to protect yourself.
What Data Does Google Have on You? The Complete 2026 Breakdown
Google has assembled one of the most detailed personal datasets ever created about ordinary internet users. This 2026 guide breaks down exactly what Google collects, how it uses it, and the practical steps you can take to reduce your data footprint.
Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore now target every mobile user through fake bank SMS, SingPost alerts, and Singpass scams. Learn how to recognise the warning signs, verify suspicious messages, and protect your accounts before it's too late.