QR Code Scams in Singapore: How to Stay Safe in 2026
QR codes are everywhere in Singapore — on hawker stall payment stickers, MRT posters, restaurant menus, parking meters, and even utility bills. That convenience has a dark side: scammers are exploiting our trust in the little black-and-white squares to steal money, credentials, and identities. In 2024 and 2025, the Singapore Police Force and the Monetary Authority of Singapore (MAS) issued multiple advisories about "quishing" — QR code phishing — after victims lost thousands of dollars in single transactions.
This guide explains how QR code scams in Singapore actually work, walks through real local cases, and gives you a practical checklist to stay safe whether you're paying for bubble tea, topping up your EZ-Link, or receiving a bank notification.
What Are QR Code Scams?
A QR code scam is a form of phishing where criminals use a Quick Response (QR) code to redirect victims to a malicious website, trigger a fraudulent payment, or install malware on a mobile device. Because QR codes are unreadable to the human eye, victims cannot tell a legitimate code from a fake one until it is too late.
Security researchers call this technique "quishing" (QR + phishing). It has become popular with fraudsters for three reasons:
- QR codes bypass most email and SMS link-scanning filters because the URL is embedded in an image.
- Mobile browsers show less of a URL than desktop browsers, making spoofed domains harder to spot.
- Singaporeans are conditioned to scan codes quickly at hawker centres, retail counters, and events.
Why Singapore Is a Prime Target
Singapore's rapid adoption of PayNow, SGQR, and unified payment rails has made QR-based transactions a daily habit. According to industry data, over 90% of merchants across the island accept some form of QR payment. That density of legitimate codes gives scammers cover — a fake sticker on a bubble tea shop counter or a printed menu at a coffee shop can easily go unnoticed for days.
The Singapore Police Force reported that scam losses hit record highs in recent years, with phishing-related scams — including QR code variants — accounting for a significant share. Older Singaporeans and busy professionals are both frequent targets: the former because they may be less familiar with URL red flags, the latter because they scan and pay in a hurry.
Common Types of QR Code Scams in Singapore
1. Sticker Overlay Scams at F&B Outlets
Scammers physically paste a fake QR sticker over the merchant's real SGQR code. Customers scan the fake code, are directed to a spoofed banking or payment page, and unknowingly transfer money to the scammer's account or hand over their internet banking credentials. The infamous 2023 bubble tea case — where a 60-year-old woman lost S$20,000 after scanning a fake survey QR code at a Maxwell area outlet — remains a cautionary reference point.
2. Fake "Free Gift" or Survey Codes
Flyers, posters, or shopfront stickers promise a free drink, voucher, or lucky draw if you scan a QR code and complete a short survey. The survey link installs a malicious Android APK that gives attackers remote access to the phone, including SMS OTPs and banking apps.
3. Parking and Traffic Fine Scams
Fake notices on car windshields or lamp posts claim you have an outstanding parking fee. The QR code leads to a spoofed HDB, URA, or LTA payment portal. Real Singapore government agencies do not collect parking fees via random QR stickers on the street.
4. Email and PDF Quishing (Corporate Targets)
Employees receive emails claiming to be from Microsoft 365, DBS IDEAL, or HR, asking them to scan a QR code to "reauthenticate" or view a document. Because the code opens on a personal phone (outside corporate security controls), credential theft succeeds where a direct link would have been blocked.
5. Delivery and Package Scams
A missed-delivery card is left in your letterbox with a QR code to "reschedule" delivery. It mimics SingPost, Ninja Van, or J&T, and asks for a small redelivery fee — capturing card details in the process.
6. Cryptocurrency Wallet Address Swaps
When sending crypto, users often scan a QR code for a wallet address. Malware or a compromised website silently swaps the displayed address for the attacker's. Because wallet addresses are long strings, the swap is nearly impossible to spot manually.
How to Recognise a Malicious QR Code
You cannot read a QR code by looking at it, but you can spot warning signs around it:
| Red Flag | Why It Matters |
|---|---|
| Sticker is peeling or pasted over another code | Classic overlay attack — the original SGQR may be underneath |
| QR code is on an unbranded flyer or lamp post | Legitimate agencies rarely distribute payment codes this way |
| URL preview shows a shortened link you don't recognise | Legitimate merchants usually route to sgqr.org or a bank domain |
| Scanning prompts you to download an APK file | Never install apps from a QR code — use Google Play or App Store |
| Page asks for full internet banking password | Banks never ask for full passwords or OTPs on payment confirmation pages |
| Urgency ("pay within 24 hours to avoid fine") | Pressure tactics are a hallmark of scams |
Step-by-Step: How to Scan QR Codes Safely
- Inspect the physical code first. Look for tampering, layered stickers, or codes that seem out of place. At hawker stalls, confirm the stall name printed on the SGQR label matches the stall.
- Use your phone's built-in camera instead of a third-party scanner app. iOS and Android both preview the URL before opening it.
- Read the URL carefully. Look for the real domain — for example,
dbs.com.sg, notdbs-sg-secure.com. Watch out for lookalike characters (0 vs O, rn vs m). - Never enter banking credentials on a page opened from a QR code. Instead, open your bank's official app manually.
- Verify payments in the app. When paying via PayNow or SGQR, always confirm the recipient's name shown in your banking app matches the merchant before approving.
- Enable Money Lock and transaction limits offered by DBS, OCBC, UOB, and other local banks. These delay large transfers and add friction that saves victims.
- Refuse app downloads triggered by a scan. If a QR code tries to install software, close the page immediately.
Tools and Habits That Reduce Your Risk
Use Reputable Link Expanders
If you are unsure about a link, expand and preview it before visiting. A trusted link management platform like Lunyb lets you paste suspicious URLs to see where they truly redirect, and offers safer sharing when you need to distribute links yourself. For a broader look at how shortener platforms handle safety, see our 2026 buyer's guide to URL shorteners, and if you're curious about Lunyb specifically, our honest Lunyb review covers the details.
Enable Encrypted DNS on Your Phone
Encrypted DNS providers (such as Cloudflare 1.1.1.1 or Quad9) can block known phishing domains before your browser even loads them. On iOS, this is set under Settings > General > DNS. On Android, use Private DNS with a provider hostname like 1dot1dot1dot1.cloudflare-dns.com.
Keep Your Phone OS and Banking Apps Updated
Many quishing attacks rely on outdated WebView components or unpatched Android versions. Update your device monthly and delete apps you no longer use.
Turn On ScamShield
The ScamShield app, developed by the National Crime Prevention Council and Open Government Products, blocks scam calls and SMS messages and provides a channel to report suspicious content, including QR-linked phishing sites.
Use Separate Cards for Small Payments
Consider using a low-limit debit card or a prepaid card (such as YouTrip or Revolut) for QR payments to small merchants. If the account is compromised, your exposure is limited.
What to Do If You've Been Scammed
- Freeze your accounts immediately. Use the kill-switch feature in your DBS, OCBC, UOB, or Standard Chartered app, or call the bank's 24-hour hotline.
- Call the Anti-Scam Helpline at 1800-722-6688 or file a report at police.gov.sg/iwitness.
- Report the scam to ScamShield so the malicious number, URL, or QR content can be added to nationwide block lists.
- Change passwords and revoke sessions for any account you may have logged into from the malicious page. Enable two-factor authentication using an authenticator app.
- Factory reset your phone if you installed an APK from the QR code. Back up photos to iCloud or Google Photos first, but do not restore apps blindly.
- Notify your employer if the incident involved a work account — corporate credentials may need to be rotated across systems.
Advice for Businesses and Merchants
If you run a hawker stall, café, or retail outlet, protect your customers (and your reputation) by:
- Laminating and mounting SGQR codes rigidly, not as loose stickers that can be replaced.
- Inspecting your payment codes at the start and end of each shift.
- Displaying your registered business name near the code so customers can cross-check the payee in their banking app.
- Training staff to recognise complaints about "strange payment pages" and act immediately.
- Using verified branded short links for marketing campaigns rather than raw or unknown shorteners — this builds customer trust and reduces spoofing risk. Platforms like Lunyb or alternatives reviewed in our Rebrandly review can help.
The Regulatory Landscape in Singapore
The Shared Responsibility Framework (SRF), which took effect in 2024, allocates losses from phishing scams among financial institutions, telcos, and consumers based on whether each party met defined duties. While the SRF has strengthened bank-side defences (such as kill switches, cooling-off periods for new payees, and 12-hour delays on high-risk activation of digital tokens), consumers who fail to exercise basic vigilance may still bear part of the loss.
MAS has also mandated that major retail banks phase out clickable links in SMS and email communications with customers. This shifts more responsibility onto users to open banking apps directly — which is exactly the discipline that defeats QR quishing too.
Frequently Asked Questions
Can just scanning a QR code hack my phone?
Scanning alone typically only reveals a URL. The danger comes from what happens next — visiting a malicious website, entering credentials, or downloading an app. Modern iPhones and Android devices with up-to-date browsers are generally safe from "drive-by" infections, but you should still preview the URL before tapping it.
Is PayNow safe to use for QR payments?
Yes, PayNow itself is secure — the risk is in the QR code you scan, not the network. Always verify the recipient's name shown in your banking app before confirming the transfer. If the name doesn't match the merchant, cancel the payment.
How do I check if a shortened URL from a QR code is safe?
Use a URL expander or preview tool to see the final destination before visiting. Many reputable shortener platforms — including Lunyb — provide preview features. You can also long-press the link on your phone to see the full URL in a preview pop-up.
Are QR codes on hawker centre stalls verified by anyone?
SGQR codes are issued by participating payment schemes and banks, but there is no daily physical audit of stickers. Scammers exploit this by overlaying fake codes. Always confirm the payee name in your banking app matches the stall.
What should I do if I already entered my banking password on a suspicious page?
Act within minutes. Use your bank's kill switch to freeze accounts, change your internet banking password from within the official app, revoke all active sessions and digital tokens, then call the bank's anti-scam hotline. File a police report and enable ScamShield to help protect others.
Final Thoughts
QR codes are not going away — they are woven into how Singapore pays, orders, and communicates. The good news is that defending yourself doesn't require technical expertise. A three-second pause to check the sticker, preview the URL, and verify the payee in your banking app defeats the vast majority of quishing attacks. Combine that habit with encrypted DNS, ScamShield, transaction limits, and a healthy scepticism of "free" offers, and you'll navigate Singapore's cashless economy safely.
Stay alert, and when in doubt — don't scan.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Irish Data Breaches 2026: What You Need to Know
Irish data breaches are surging in 2026, driven by AI-powered phishing, ransomware, and expanding regulatory scrutiny. This guide covers the current threat landscape, DPC enforcement trends, GDPR notification obligations, and practical steps every Irish organisation should take to reduce risk.
Is Public WiFi Safe? The Truth in 2026
Public WiFi in 2026 is safer than it used to be thanks to HTTPS and encrypted DNS — but it's not risk-free. Learn which threats still matter, which are overblown, and the practical steps that keep you safe on open networks.
Zero Trust Security Model Explained Simply: A 2026 Guide
Zero Trust flips traditional security on its head with a simple rule: never trust, always verify. This guide explains what Zero Trust is, how it works, and how to start implementing it — in plain English, without the jargon.
How to Know if Your Phone Is Hacked: 10 Warning Signs
Wondering if your smartphone has been compromised? Learn the 10 clearest warning signs your phone is hacked — from battery drain and data spikes to strange messages and unfamiliar apps — plus exactly what to do if you spot them.