facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··11 min read

QR codes are everywhere in Singapore, from hawker centre payment stalls and MRT posters to parking coupons and restaurant menus. Their convenience has also made them a favourite tool for scammers. In recent years, the Singapore Police Force and the Cyber Security Agency of Singapore (CSA) have warned repeatedly about a fast-growing threat known as quishing, or QR code phishing.

This guide explains how QR code scams in Singapore actually work, walks through real cases reported locally, and gives you a practical checklist to stay safe whether you are paying for bubble tea, topping up ERP, or scanning a flyer at a bus stop.

What Are QR Code Scams?

A QR code scam is a fraud technique where criminals use a malicious QR code to redirect victims to fake websites, trigger unauthorised payments, or install harmful apps on their phones. Because a QR code is just a visual link, you cannot tell by looking at it whether the destination is safe.

The industry term is quishing, a combination of "QR" and "phishing". Instead of a suspicious email link, the bait is a small black-and-white square that looks perfectly ordinary. Once scanned, it can send you to a spoofed DBS, OCBC, UOB, Singpass, or IRAS login page, or prompt you to download a sideloaded Android APK that steals your banking credentials.

Why Singapore Is a Prime Target

Singapore has one of the highest smartphone penetration rates in the world and is largely cashless. PayNow, PayLah!, GrabPay, and SGQR are used daily by millions. That means the average Singaporean is trained to scan first and think later, which is exactly the behaviour scammers exploit.

How QR Code Scams Work in Singapore

Most QR code scams follow a predictable pattern. Understanding the flow makes it easier to spot the red flags before you lose money.

  1. Placement: The scammer places a malicious QR code somewhere trusted, such as on a hawker stall counter, a parking meter, a bubble tea shop survey flyer, or inside a fake email or SMS.
  2. Scan: The victim scans the code, often while distracted or in a hurry.
  3. Redirect: The code opens a page that mimics a Singapore bank, Singpass, IRAS, or a delivery service like SingPost or Ninja Van.
  4. Harvest: The victim enters login credentials, OTPs, or NRIC details, or is asked to install an APK file outside the Play Store.
  5. Drain: Within minutes, funds are transferred out through PayNow or overseas card transactions, sometimes wiping entire savings accounts.

Common Scam Scenarios Seen Locally

  • Bubble tea and food survey scams: Victims are approached outside malls in Bugis, Jurong, or Orchard and asked to scan a QR code for a "free drink" survey. The link installs a malicious app that hijacks the phone.
  • Fake parking coupon QR codes: Stickers pasted on top of legitimate signs at HDB carparks redirecting to fake payment pages.
  • Hawker stall payment fraud: Scammers stick their own SGQR code over the stall owner's real one, redirecting payments to a mule account.
  • Fake bank letters: Physical letters claiming to be from DBS or UOB asking recipients to scan a QR code to "reactivate" their account.
  • Delivery notification scams: SMS or emails supposedly from SingPost or a courier, with a QR code linking to a fake tracking page that harvests card details.

Real Examples of QR Code Scams in Singapore

The Singapore Police Force has issued multiple advisories over the past two years. In one widely reported case, a 60-year-old woman lost around S$20,000 after scanning a QR code on a survey flyer outside a bubble tea shop. The linked app gave scammers remote access to her banking app.

In another wave of incidents, tourists and residents at popular hawker centres discovered that scammers had physically pasted fake SGQR stickers over legitimate ones. Stall owners only realised something was wrong when customers insisted they had paid, but no funds arrived.

The Cyber Security Agency of Singapore has also flagged quishing campaigns targeting corporate employees, where QR codes embedded in emails bypass traditional email security filters because the malicious URL is hidden inside an image.

Types of QR Code Scams to Watch For

1. Payment Redirection Scams

A fraudulent SGQR or PayNow QR code replaces or overlays a real one. Your money goes to a mule account instead of the merchant. Always verify the recipient name shown in your banking app before confirming payment.

2. Credential Phishing (Quishing)

The QR code leads to a page that looks identical to Singpass, DBS iBanking, or CPF. Any credentials or 2FA codes you enter are captured in real time and used to log in to your actual account.

3. Malicious App Installation

Common on Android. The QR code prompts you to download an APK outside the Google Play Store. Once installed, the app requests accessibility permissions and takes over your device, reading OTPs and controlling banking apps.

4. Wi-Fi and Device Hijacking

Some QR codes automatically connect your phone to a rogue Wi-Fi network, where all your traffic can be intercepted. This is common in tourist areas and coworking spaces.

5. Fake Charity and Donation Codes

During Ramadan, Deepavali, Christmas, and after disasters, scammers create fake donation QR codes shared on WhatsApp and Telegram, often impersonating real Singapore charities.

How to Spot a Malicious QR Code

Before scanning, take five seconds to run through this checklist.

Warning Sign What It Means
Sticker pasted over another sticker Someone may have overlaid a fake QR on a legitimate one
QR code in an unsolicited email or SMS Classic quishing attempt, especially if urgency is used
Prompt to download an APK or unknown app Almost always malware on Android devices
Shortened or unfamiliar domain after scan Legitimate Singapore services use recognisable .sg or .com.sg domains
Requests for NRIC, Singpass, or full card details No genuine merchant needs these to accept a payment
Recipient name does not match the merchant Payment is being redirected to a mule account

How to Stay Safe from QR Code Scams in Singapore

Staying safe does not mean avoiding QR codes altogether. It means adopting a few consistent habits.

1. Preview the URL Before Opening

Both iOS Camera and Google Lens show a preview of the URL before you tap it. Read the domain carefully. dbs.com.sg is legitimate; dbs-secure-login.xyz is not. If a link uses a URL shortener, expand it first using a link checker before visiting.

2. Verify the Payee in Your Banking App

Before you tap "Pay" on PayNow or PayLah!, confirm the recipient name matches the stall or merchant. If a hawker stall named "Ah Hock Chicken Rice" shows a payee like "JOHN TAN XX", stop immediately and inform the stall owner.

3. Never Install Apps from a QR Code

Legitimate Singapore banks, government agencies, and major retailers will never ask you to install an APK file outside the Google Play Store or Apple App Store. This is the single biggest red flag in local scams.

4. Use Money Lock and Transaction Limits

DBS, OCBC, UOB, and Standard Chartered all offer Money Lock features that ring-fence funds from digital transfers. Set daily transaction limits low, and only raise them when needed.

5. Keep Your Phone Updated

Android and iOS security patches close vulnerabilities that malware exploits after a bad QR scan. Enable automatic updates and keep Google Play Protect turned on.

6. Be Careful With Shortened Links

Not all short links are dangerous, but you should always know where one leads before opening it. Reputable URL shorteners such as Lunyb provide link previews, malware scanning, and analytics so both senders and recipients can trust the destination. If you regularly share links for your business or community group in Singapore, using a trustworthy shortener is far safer than a random free tool. You can read more in our honest Lunyb review or compare options in our 2026 buyer's guide to URL shorteners.

7. Report Suspicious QR Codes

If you spot a suspicious QR sticker at a hawker centre, MRT station, or carpark, report it to the merchant, the venue operator, and the Singapore Police Force via the ScamShield helpline (1799) or the ScamShield app. You can also forward suspicious SMS messages to 9068.

What to Do If You Have Been Scammed

Speed is everything. Every minute matters once your credentials or device are compromised.

  1. Turn on airplane mode to cut the scammer's remote access to your phone.
  2. Call your bank immediately using the anti-scam hotlines: DBS 1800-339-6963, OCBC 1800-363-3333, UOB 1800-222-2121.
  3. Freeze your accounts using the kill switch inside your banking app if available.
  4. File a police report at any Neighbourhood Police Centre or online via eservices.police.gov.sg.
  5. Reset your Singpass credentials at singpass.gov.sg if you entered them on a suspicious site.
  6. Uninstall any suspicious apps, then perform a full factory reset if you installed an APK.
  7. Change passwords for banking, email, and any account that reused the compromised password.

Business Owners: Protecting Your Customers

If you run a hawker stall, cafe, retail shop, or clinic in Singapore, you also have a responsibility to protect customers from QR tampering.

  • Laminate your SGQR code and place it inside a clear acrylic holder that is hard to overlay with a sticker.
  • Check your QR code visually at the start and end of every day for suspicious stickers.
  • Display your business name clearly next to the QR code so customers can verify the payee name.
  • Encourage customers to show you the payment confirmation screen before leaving.
  • Train staff to recognise fake QR overlays and the signs of a compromised payment terminal.

The Role of Regulators and Banks in Singapore

The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) have rolled out several anti-scam measures, including the Shared Responsibility Framework, kill switches, and default lower transfer limits for new payees. The Singapore Police Force's Anti-Scam Command works around the clock with banks to freeze mule accounts, sometimes within minutes of a report.

However, technology alone cannot stop quishing. The final line of defence is always the person holding the phone. A moment of caution before scanning is worth far more than any after-the-fact intervention.

Frequently Asked Questions

Are all QR codes in Singapore dangerous?

No. The vast majority of QR codes at legitimate merchants, government agencies, and SGQR payment terminals are safe. The risk comes from unverified codes on flyers, unsolicited messages, stickers placed over legitimate ones, and codes distributed by unknown parties. Treat QR codes like links: only scan those from trusted sources.

How do I know if a QR code has been tampered with at a hawker centre?

Look for signs of a sticker placed over another, uneven edges, mismatched printing, or a QR code that seems newer than the surrounding menu. Before paying, always verify that the payee name shown in your banking app matches the stall's business name. If in doubt, ask the stall owner to confirm the name on their PayNow.

Can scanning a QR code alone hack my phone?

Simply scanning a QR code does not usually install malware. The danger begins when you tap the link, enter information, or install an app it directs you to. Modern iOS and Android show a URL preview before opening, giving you a chance to cancel. However, if you are on an outdated device with unpatched vulnerabilities, even opening a malicious page can be risky.

Is it safe to use PayNow QR codes?

PayNow itself is secure and regulated by MAS. The risks come from fraudulent QR codes designed to look like PayNow requests but that route funds to mule accounts. Always confirm the recipient name and, for larger amounts, verify with the merchant directly before pressing send.

Where can I report a QR code scam in Singapore?

Call the ScamShield Helpline at 1799, use the ScamShield app, or file a report at any Neighbourhood Police Centre or online at the Singapore Police Force e-Services portal. If money has already been transferred, contact your bank's 24-hour anti-scam hotline first so they can attempt to freeze the receiving account.

Final Thoughts

QR code scams in Singapore are evolving quickly, but the defence is straightforward: slow down, verify the destination, and never trust urgency. Whether you are paying for a plate of chicken rice in Chinatown or tapping a link in an email, treat every QR code as an unknown door until you have checked what is behind it.

A five-second pause before scanning could save you thousands of dollars and hours of stress dealing with fraud reports. Share this guide with family members, especially older relatives, and encourage the businesses you frequent to protect their payment codes. Staying safe online in Singapore is a community effort.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles