QR Code Scams in Singapore: How to Stay Safe in 2026
Quick Response (QR) codes have become part of daily life in Singapore. You scan them to pay at hawker stalls, top up EZ-Link cards, order at restaurants, log in to services, and even check into buildings. But this convenience has a dark side: QR code scams in Singapore are now one of the fastest-growing forms of cybercrime, with the Singapore Police Force and the Cyber Security Agency (CSA) issuing repeated warnings throughout 2024 and 2025.
This guide explains how QR code scams work in the Singapore context, the most common tactics fraudsters use locally, and the practical steps you can take to protect your money, your identity, and your devices.
What Are QR Code Scams?
A QR code scam is a form of phishing where criminals use a malicious QR code to trick victims into visiting fake websites, downloading harmful apps, or authorising fraudulent payments. The technique is often called "quishing" — a blend of "QR" and "phishing".
Because a QR code is just a machine-readable image, you cannot tell by looking at it whether it leads to a legitimate site or a scam. Your phone reads the encoded URL and opens it, often in a browser or app, before you have a chance to think. That split second is what scammers rely on.
Why Singapore Is a Prime Target
Singapore has one of the highest QR code adoption rates in the world thanks to PayNow, SGQR, NETS QR, and app-based ordering systems. When almost every merchant displays a QR sticker, it becomes very easy for a fraudster to slip a fake one into the mix without anyone noticing.
The Most Common QR Code Scams in Singapore
1. The Bubble Tea and F&B Survey Scam
This was one of the most widely reported quishing cases in Singapore. Victims found QR code stickers on the exterior of shops — including bubble tea outlets — offering a free drink in exchange for completing a "customer survey". Scanning the code led to a fake page prompting them to download a third-party Android app. The app then requested accessibility permissions, silently recording banking credentials and taking over the device. Losses in individual cases reached tens of thousands of dollars.
2. Fake Parking Fine QR Codes
Fraudsters have placed fake notices resembling HDB, URA, or LTA parking summonses on windshields. The notice includes a QR code to "pay the fine online". The link leads to a spoofed government payment page that harvests credit card details or SingPass credentials.
3. Hawker and Coffee Shop PayNow Swaps
Scammers physically paste their own PayNow QR sticker over the merchant's genuine one. Customers scan and transfer funds directly to the scammer's account. Because SGQR stickers look uniform, the swap can go unnoticed for days.
4. Fake Delivery and Parcel Notifications
You receive an SMS or a note claiming a SingPost, Ninja Van, or J&T parcel could not be delivered. A QR code invites you to "reschedule delivery" or "pay a small customs fee". The destination is a phishing page mimicking a delivery service.
5. Job Offer and Part-Time Task Scams
Attractive part-time job ads on Telegram, WhatsApp, or Carousell include a QR code to "register". Scanning it opens a chat with a scammer who eventually asks for bank details, ID documents, or an upfront "deposit".
6. Charity and Donation Scams
Around festive periods and disaster relief campaigns, fake charity flyers with QR codes appear in public areas. Well-meaning donors send funds to personal accounts disguised as registered charities.
7. Event and Ticketing QR Scams
Fake resale listings for concerts, football matches, or F1 tickets include QR codes that either lead to phishing pages or transfer money without producing a real ticket.
How Quishing Actually Works: A Step-by-Step Breakdown
- The bait is placed. The scammer prints a sticker, sends a message, or posts a flyer with a QR code in a location where victims expect it to be legitimate.
- The victim scans. The phone's camera decodes the URL and prompts the user to open it. Many people tap "Open" without reading the domain.
- The landing page loads. It mimics a familiar brand — a bank, government agency, e-commerce site, or delivery firm.
- Credentials or downloads are requested. The page asks for login details, OTPs, credit card numbers, or prompts you to "install our app" (usually a sideloaded APK on Android).
- The device or account is compromised. Malicious apps abuse accessibility services to read screens, capture keystrokes, and approve transactions in the background.
- Funds are drained. Money is often moved through mule accounts within minutes, making recovery extremely difficult.
Red Flags: How to Spot a Suspicious QR Code
- A QR code sticker that looks freshly pasted over another sticker.
- Codes placed in unusual locations — on lamp posts, toilet doors, or shop windows facing outside.
- Offers that sound too good to be true: free drinks, cash rebates, or "limited-time" gifts.
- Unsolicited SMS, WhatsApp, or Telegram messages containing QR codes.
- Landing pages asking you to install an app from outside the Play Store or App Store.
- URLs with misspellings (e.g., "dbs-sg-login.com", "singpost-delivery.net").
- Pages that request your SingPass password, full NRIC, or full bank credentials — legitimate services never do this via a scanned link.
- Payment QR codes where the recipient name shown in PayNow does not match the shop or organisation.
Comparing Safe vs. Risky QR Code Behaviour
| Situation | Safe Behaviour | Risky Behaviour |
|---|---|---|
| Paying at a hawker stall | Confirm recipient name in PayNow matches the stall before pressing send | Scanning and paying immediately without reading the recipient |
| Receiving a "parking fine" note | Verify via the OneMotoring or HDB website directly | Scanning the QR on the notice |
| Delivery notification SMS | Open the courier's official app to track | Tapping the QR or link in the SMS |
| Free gift promotion | Ignore or verify with the brand's official channels | Scanning outdoor stickers offering rewards |
| Prompt to install an app | Search the app in Google Play or App Store directly | Sideloading an APK from a scanned link |
Practical Steps to Stay Safe
1. Preview the URL Before Opening It
Most modern iPhone and Android cameras display the decoded URL before opening it. Read the full domain carefully. If it looks unfamiliar, contains random characters, or does not match the brand, do not open it.
2. Use Only Official Apps for Payments
Open your bank's app (DBS PayLah!, OCBC Digital, UOB TMRW) and use its built-in scanner. These apps include additional fraud checks and will flag known scam accounts.
3. Never Sideload Apps
Android users should keep "Install unknown apps" disabled. Almost every quishing attack in Singapore that led to full bank account takeover involved a sideloaded APK. Major local banks have now rolled out anti-malware protections that block transactions when sideloaded apps are detected — do not try to disable them.
4. Enable Money Lock and Transfer Limits
DBS, OCBC, and UOB all offer a "Money Lock" feature that ring-fences funds from digital transfers. Combine this with low daily transfer limits so that even if credentials are stolen, losses are capped.
5. Verify PayNow Recipient Names
Before confirming any payment, check that the registered UEN or recipient name matches the merchant. A hawker called "Ah Seng Chicken Rice" should not be receiving your money as "John Tan".
6. Use a Secure DNS or Anti-Phishing Browser
Enable encrypted DNS (like Cloudflare's 1.1.1.1 for Families or Quad9) on your phone to block known phishing domains at the network level. Browsers such as Brave and Firefox Focus also help by blocking trackers and warning about suspicious sites.
7. Inspect Shortened Links Before Visiting
If a QR code resolves to a shortened URL, use a link expander or a trustworthy shortener platform that shows you the destination first. Reputable shorteners such as Lunyb allow both link creators and recipients to see safe previews and analytics, making it easier to identify suspicious redirects. If you use short links for your own business, choosing a reputable provider matters — see our 2026 buyer's guide to URL shorteners for comparisons.
8. Keep Your Phone Updated
Install iOS and Android security patches promptly. Many malware families used in Singapore quishing attacks exploit older Android versions and outdated WebView components.
What to Do If You Have Been Scammed
- Freeze your accounts immediately. Every major Singapore bank offers a "Kill Switch" through their app or 24-hour hotline. Use it before doing anything else.
- Disconnect the device. Turn on airplane mode to stop malware from communicating with the attacker.
- Call the Anti-Scam Helpline at 1800-722-6688 or use the ScamShield app to report the incident.
- File a police report at any Neighbourhood Police Centre or via the online e-Services portal.
- Factory reset the device after backing up essential data, and change all passwords from a clean device.
- Alert your contacts in case the scammer uses your accounts to spread the scam further.
- Notify SingPass if you suspect your government login was compromised, and reset your 2FA settings.
How Businesses and Merchants Can Help
Merchants have a role to play too. Simple habits protect both the business and its customers:
- Laminate SGQR and PayNow stickers, and inspect them daily for tampering.
- Use QR stickers with tamper-evident seals so any overlay is obvious.
- Display the registered PayNow name clearly next to the QR code.
- Train staff to recognise phishing attempts targeting merchant accounts.
- For marketing campaigns, use branded short links from a reputable provider so customers can recognise your domain. Our honest review of Lunyb and Rebrandly 2026 review can help you pick the right one.
The Bigger Picture: Singapore's Anti-Scam Ecosystem
Singapore has built one of the region's most active anti-scam ecosystems. The Anti-Scam Command (ASCom), the ScamShield app, GovTech's real-time transaction monitoring, and the Shared Responsibility Framework between banks and telcos all work together to reduce losses. However, technology alone cannot beat social engineering — the last line of defence is always the person holding the phone.
Being sceptical of every unsolicited QR code, verifying recipients before pressing send, and refusing to install unknown apps are habits that will protect you far better than any single tool.
Frequently Asked Questions
Are QR code scams really that common in Singapore?
Yes. The Singapore Police Force has reported millions of dollars in losses to quishing and related malware-enabled scams. Cases involving fake surveys, PayNow sticker swaps, and phishing SMSes with QR codes have all been documented publicly in 2024 and 2025 advisories from the SPF and CSA.
Is it safe to scan QR codes at hawker centres and restaurants?
Generally yes, but you should always confirm the recipient name displayed in your banking app before pressing send. If the name looks like a personal account rather than the shop's business name, cancel the transaction and pay by another method.
Can scanning a QR code alone hack my phone?
Simply scanning a QR code does not automatically install malware. The danger comes from what happens next — visiting a phishing site, entering credentials, or being convinced to install an app from an unofficial source. If you never open the link or install anything, the risk is minimal.
How do I check if a shortened URL from a QR code is safe?
Use a URL expander service or a browser extension that previews the final destination. Reputable link shorteners often provide a preview page. When creating your own campaigns, choose a trusted platform and always show your custom branded domain so recipients recognise it.
What should I do first if I already scanned a scam QR code and entered my details?
Immediately activate your bank's Kill Switch or call the 24-hour fraud hotline to freeze your accounts. Then turn on airplane mode, call the Anti-Scam Helpline at 1800-722-6688, and file a police report. Speed is critical — funds are often transferred out within minutes.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Two-Factor Authentication: Why You Need It in 2026
Two-factor authentication blocks over 99.9% of automated account attacks, yet most people still rely on passwords alone. Learn how 2FA works, which methods are strongest, and how to protect your most important accounts step by step.
End-to-End Encryption Explained: How It Works and Why It Matters
End-to-end encryption keeps your messages readable only to you and your recipient — not even the service provider can peek. This guide explains how E2EE works step by step, why it matters in 2026, and where its limits lie.
Phishing Attacks in Singapore: How to Recognize and Avoid Them
Phishing attacks in Singapore are more targeted than ever, from fake DBS SMSes to SingPass clone sites. This guide shows you how to recognise the red flags, verify suspicious messages, and take immediate action if you've been compromised.
How Hackers Use Shortened URLs to Spread Malware (2026 Guide)
Shortened URLs make link-sharing cleaner — but they also hide destinations from users and scanners alike, making them a favorite tool of cybercriminals. Learn the exact techniques hackers use to spread malware through short links, and the practical defenses that stop them.