facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes are everywhere in Singapore — from hawker stalls and NETS terminals to PayNow transfers, SimplyGo top-ups, and government e-services. Unfortunately, this convenience has made QR codes one of the fastest-growing tools used by scammers. In 2023, the Singapore Police Force flagged a surge in "quishing" (QR phishing) cases, and by 2025 the Monetary Authority of Singapore (MAS) and the Cyber Security Agency (CSA) had issued multiple public advisories warning that QR-based fraud continues to evolve.

This guide explains how QR code scams work in Singapore, the most common tactics scammers use locally, and how you can protect yourself, your family, and your business. It is written for everyday users, not just tech specialists.

What Is a QR Code Scam?

A QR code scam is a form of phishing where a fraudster tricks a victim into scanning a malicious QR code that leads to a fake website, malware download, or unauthorised payment. Because QR codes are visually indistinguishable from one another, victims rarely realise the destination is dangerous until money or credentials are already gone.

In Singapore, these scams often exploit trust in familiar brands such as DBS, OCBC, UOB, PayNow, SingPost, Shopee, IRAS, and even NEA or LTA. Scammers know that Singaporeans regularly scan codes for parking, dining vouchers, MRT services, and government transactions — so a fake sticker or email attachment can easily slip through.

Why QR Code Scams Are Rising in Singapore

Singapore has one of the highest smartphone penetration rates in the world and one of the most cashless economies in Asia. According to police statistics, scam losses in Singapore exceeded S$1.1 billion in 2024, with phishing-related scams — including quishing — forming a significant portion.

Several factors make Singapore a prime target:

  • High PayNow and PayLah! adoption: Fast payments mean money can be gone in seconds.
  • Widespread QR usage: Every F&B outlet, retail shop, and government agency uses QR codes for payments, feedback, or authentication.
  • Trust in institutions: Singaporeans generally trust official-looking notices, which scammers exploit.
  • Multilingual population: Scam messages can be tailored in English, Mandarin, Malay, or Tamil to widen the target base.

Common QR Code Scams in Singapore

1. Fake Bubble Tea and F&B Survey Scams

One of the most publicised cases involved a woman losing over S$20,000 after scanning a QR code on a bubble tea shop's door offering a "free cup for feedback." The QR led to a malicious Android app that granted the scammer remote access to her banking app. This tactic is now used across cafes, restaurants, and even massage parlours in heartland areas.

2. Parking Coupon and LTA Impersonation Scams

Fake notices are stuck on car windshields claiming an outstanding parking fine or an LTA violation. The QR code leads to a spoofed URA or LTA page requesting Singpass login or credit card details.

3. PayNow and Bank "Verification" Emails

Victims receive emails or SMS from what appears to be DBS, OCBC, or UOB asking them to "verify" their account by scanning a QR code. The scanned link opens a phishing site that mirrors the real ibanking login page.

4. Fake Hawker and Merchant PayNow Stickers

Scammers physically paste their own PayNow QR stickers over legitimate ones at hawker stalls. Customers unknowingly transfer payment to the scammer's account instead of the merchant.

5. E-Commerce and Delivery Scams

QR codes appear in fake delivery failure notices claiming to be from SingPost, Ninja Van, or Qxpress. Scanning leads to malware or a form requesting card details for a "redelivery fee."

6. Investment and Crypto Scams

QR codes in Telegram groups or Facebook ads promising high returns on crypto or forex trading redirect victims to fraudulent trading platforms that eventually block withdrawals.

7. Charity and Donation Scams

During festive seasons (Chinese New Year, Hari Raya, Deepavali), fake charity flyers with QR codes appear in HDB lift lobbies or community centres, redirecting donations to scammer-controlled accounts.

How to Identify a Suspicious QR Code

Before scanning any QR code, run through this quick checklist:

  1. Check the physical placement. Is the QR code a sticker pasted over another code? Peel gently — many scam QRs are placed on top of legitimate ones.
  2. Preview the URL. Both iOS and Android show the destination URL before opening. Read it carefully.
  3. Look for spelling anomalies. "dbs-sg-verify.com" or "paynow-secure.net" are not official domains. Real Singapore bank domains typically end in .com.sg or the bank's official global domain.
  4. Beware of shortened links from unknown sources. While reputable shorteners are safe, scammers sometimes use free shorteners to hide malicious URLs. If you use shortened links for business, use a reputable service like Lunyb that offers link previews and analytics.
  5. Never scan codes that ask you to install an APK file. Legitimate Singapore apps are always distributed via Google Play or the Apple App Store.
  6. Watch for urgency. "Your account will be suspended in 24 hours" is a classic scam trigger.

What Happens When You Scan a Malicious QR Code

Understanding the mechanics helps you spot attacks earlier. A malicious QR code can trigger one or more of the following:

Attack TypeWhat It DoesTypical Outcome
Phishing websiteOpens a fake login page mimicking a bank, Singpass, or e-commerce siteCredentials stolen; money transferred out
Malware downloadPrompts an APK or configuration profile installRemote access to phone, SMS interception, banking trojan
Payment redirectionAuto-fills a PayNow or PayLah! transfer to a scammer's accountImmediate financial loss
Wi-Fi hijackConnects device to a rogue networkTraffic interception, session hijacking
Contact / calendar injectionAdds spam events or contactsPersistent phishing prompts

How to Stay Safe: Practical Steps for Singaporeans

For Everyday Consumers

  1. Enable Money Lock on DBS, OCBC, UOB, or Standard Chartered apps. This ring-fences a portion of your savings from digital transfers, even if scammers gain access.
  2. Turn on ScamShield. The ScamShield app by NCPC and Open Government Products blocks known scam SMS and calls.
  3. Use biometric login and transaction signing for banking apps.
  4. Set low daily transfer limits. Reduce PayNow and FAST transfer limits to what you actually need.
  5. Never enter Singpass credentials after scanning a QR code from an untrusted source. Real Singpass logins should always be initiated from the official app or singpass.gov.sg.
  6. Verify merchant QR codes by checking that the receiving name matches the shop when making PayNow payments.
  7. Update your phone's operating system regularly to patch known vulnerabilities.

For Business Owners and Merchants

  1. Inspect your QR code stickers daily. Hawker stalls and retail shops should visually check for tampering each morning.
  2. Laminate or tamper-seal QR codes so scammers cannot easily paste over them.
  3. Use a branded, trackable link platform for any marketing QR codes so you can monitor scan analytics and detect anomalies.
  4. Train staff to recognise suspicious behaviour, such as customers pointing out unexpected receiving names.
  5. Register your business PayNow correctly under your UEN so customers see your legal entity name during payment.

For Marketing and Communications Teams

If your organisation uses QR codes in campaigns, posters, or emails, treat every code as a piece of security-sensitive infrastructure. Use a reputable link management platform that provides HTTPS, click analytics, and the ability to disable links quickly if compromised. Services like the best URL shorteners of 2026 allow you to update the destination without reprinting your collateral — critical if you discover a security issue after distribution.

What to Do If You've Scanned a Malicious QR Code

Speed matters. If you suspect you've been scammed, follow this order of actions:

  1. Disconnect the phone from the internet (turn on airplane mode) to stop malware from communicating.
  2. Call your bank's 24/7 fraud hotline immediately:
    • DBS/POSB: 1800-339-6963
    • OCBC: 1800-363-3333
    • UOB: 1800-222-2121
    • Standard Chartered: 1800-747-7000
  3. Freeze your accounts using the "Safety Switch" or "Kill Switch" feature in your banking app.
  4. Report the incident to the ScamShield Helpline at 1799 or file a police report at spf.gov.sg.
  5. Uninstall any suspicious apps and consider a factory reset if malware is confirmed.
  6. Change all critical passwords from a separate, trusted device — starting with Singpass, banking, and email.
  7. Enable 2FA on all remaining accounts if not already active.

How Singapore Authorities Are Fighting Back

The Singapore government has rolled out multiple initiatives to combat QR-based fraud:

  • Shared Responsibility Framework (SRF): Launched by MAS and IMDA in December 2024, this framework outlines when banks and telcos must compensate scam victims.
  • Anti-Scam Command (ASCom): A dedicated police unit that has recovered hundreds of millions in scam proceeds since 2022.
  • SMS Sender ID Registry (SSIR): Blocks unregistered senders from impersonating banks or government agencies.
  • ScamShield app: Now integrated with Singpass and telco networks for real-time protection.
  • Money Lock and Kill Switch: Available across all major banks.

Despite these measures, no system can fully replace personal vigilance. Scammers adapt quickly, and the human factor remains the weakest link.

QR Code Safety Habits to Build

Cybersecurity is a daily habit, not a one-off action. Adopt these routines:

  • Pause before scanning any code in public.
  • Verify URLs on the preview screen every single time.
  • Never scan QR codes received via unsolicited SMS, WhatsApp, or email.
  • Educate elderly family members — they are disproportionately targeted.
  • Discuss scam trends at family dinners or team meetings.
  • Report suspicious codes and messages so others can be warned.

Frequently Asked Questions

Are all QR codes in Singapore dangerous?

No. The vast majority of QR codes — including SGQR at hawker centres, PayNow codes, and government service codes — are safe. The danger lies in codes placed by unknown parties, sent via unsolicited messages, or that ask you to install apps outside official app stores.

Can scanning a QR code alone install malware on my phone?Scanning itself only opens a URL. Malware installation requires an additional step, such as downloading and installing an APK file on Android or approving a configuration profile on iOS. Never approve installations from unknown sources, and keep "Install unknown apps" disabled in your Android settings.

Will my bank refund me if I fall victim to a QR code scam in Singapore?

Under the Shared Responsibility Framework, banks and telcos may share liability if they failed to meet specific anti-scam duties. However, if the loss resulted from you willingly entering credentials or approving transfers, refunds are not guaranteed. Report the incident immediately to improve your chances of recovery.

How can I check if a shortened URL is safe before opening it?

Use a URL expander or preview tool, and check whether the destination uses HTTPS with a valid certificate. Reputable link shorteners provide preview features and use trusted domains. You can read more about safe link services in our 2026 URL shortener buyer's guide.

What should I teach elderly parents about QR code scams?

Focus on three simple rules: (1) never scan QR codes from strangers, flyers, or unexpected messages; (2) never install any app outside the Play Store or App Store; (3) always call a family member before transferring money after scanning any code. Enrol them in ScamShield and set low banking transfer limits on their behalf.

Final Thoughts

QR codes are not going away — they're becoming even more embedded in Singapore's digital lifestyle, from HealthHub to MRT gantries to hawker payments. The goal isn't to fear QR codes but to use them with awareness. A five-second pause to verify a URL, check a sticker for tampering, or confirm a merchant name can save you tens of thousands of dollars and months of stress.

Stay informed, share this knowledge with your family and colleagues, and treat every unexpected QR code with the same caution you'd give an unknown email attachment. In an era where a single scan can drain a bank account, healthy skepticism is your strongest defence.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles