facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes have become part of daily life in Singapore. You scan them to pay at hawker centres, order kopi at cafes, top up EZ-Link cards, access government e-services, and even join Wi-Fi networks. Unfortunately, that same convenience has made QR codes one of the fastest-growing tools used by scammers targeting Singaporeans. In 2023 and 2024, the Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) issued multiple advisories after victims lost hundreds of thousands of dollars to QR code phishing, also known as "quishing."

This guide explains exactly how QR code scams in Singapore work, walks through real local cases, and gives you a practical checklist to stay safe whether you are paying at a bubble tea shop, filling in a survey, or accessing your bank account.

What Are QR Code Scams?

A QR code scam is a form of phishing where criminals use a malicious Quick Response (QR) code to redirect victims to fraudulent websites, trigger unauthorised payments, or trick them into installing malware. Because a QR code is just a machine-readable shortcut to a URL or payment string, users cannot see where it leads until after they scan it — and by then, the damage may already be done.

In Singapore, scammers commonly exploit the country's high adoption of PayNow, SGQR, and mobile banking apps. A single tap on a fake link can lead to credential theft, drained bank accounts, or Android malware that intercepts SMS-based one-time passwords (OTPs).

Why Singapore Is a Prime Target

  • High digital payment adoption: SGQR is nationally standardised, so users are trained to scan without hesitation.
  • Trust in QR-based government services: SingPass, HealthHub, and LTA services regularly use QR codes.
  • Dense F&B environments: Hawker centres, coffee shops, and food courts rely on printed QR menus and payment stickers that are easy to swap or overlay.
  • Multilingual population: Scammers craft phishing pages in English, Mandarin, Malay, and Tamil to widen their net.

How QR Code Scams Work in Singapore

Most quishing attacks in Singapore follow a predictable pattern. Understanding the mechanics helps you recognise red flags before you scan.

  1. The bait: The scammer creates a fake sticker, poster, email, letter, or social media ad containing a malicious QR code.
  2. The placement: They stick it over a legitimate QR code (e.g., on a bubble tea shop payment terminal or a parking meter) or send it directly to victims via WhatsApp, Telegram, or email.
  3. The redirect: When scanned, the code opens a spoofed website that mimics a bank, DBS PayLah!, Singpass, IRAS, or a delivery service like SingPost.
  4. The harvest: Victims enter their login credentials, NRIC, credit card details, or OTPs. Some pages prompt users to download an Android APK disguised as an update, which installs remote-access malware.
  5. The drain: Attackers use the harvested credentials to transfer funds via PayNow, add themselves as payees, or take over Singpass accounts.

Real QR Code Scam Cases in Singapore

These are not hypothetical threats — Singaporean authorities have documented multiple high-profile incidents.

The Bubble Tea Survey Scam

In 2023, a 60-year-old woman in Singapore lost S$20,000 after scanning a QR code sticker on the glass door of a bubble tea shop in Jalan Besar. The sticker offered a free cup in exchange for completing a survey. Scanning it prompted her to download a third-party Android app, which then hijacked her banking session and drained her account overnight.

Fake Parking.sg Notices

Fraudsters have been spotted placing counterfeit parking summons and Parking.sg reminder slips on windshields, complete with a QR code that leads to a fake payment page. Victims who entered card details had funds siphoned within hours.

Overlay Stickers at Hawker Stalls

The National Environment Agency (NEA) and SPF have warned hawkers that scammers physically paste fake PayNow QR stickers over legitimate stall codes, redirecting payments to money mule accounts. The stall owner never receives the payment, and the customer's money is gone.

Phishing Emails Impersonating Banks

DBS, OCBC, and UOB customers have received emails with QR codes claiming they need to "reverify" their account. The QR bypasses email filters that would normally flag suspicious links, funnelling victims to fake login portals.

Types of QR Code Scams to Watch For

1. Payment Redirection Scams

Fake SGQR or PayNow stickers overlay real ones. You think you are paying a merchant; you are actually paying a scammer's mule account.

2. Quishing (QR Phishing)

The QR code leads to a spoofed login page for Singpass, a bank, IRAS, or CPF. Any credentials you enter go straight to the attacker.

3. Malware Delivery

Especially dangerous on Android. The QR leads to an APK download disguised as a food ordering, delivery tracking, or bank update app. Once installed, it can read SMS OTPs and control the device.

4. Fake Contest and Survey Scams

"Scan to win" posters on MRT platforms, bus stops, or shopfronts promise vouchers or lucky draws in exchange for personal details or a small "delivery fee."

5. Fake Parking, Traffic, or Utility Notices

Scammers mimic HDB, SP Group, LTA, or Parking.sg branding on physical or digital notices demanding urgent payment via a QR code.

6. Cryptocurrency and Investment Scams

Telegram groups and Facebook ads promoting "guaranteed returns" often use QR codes leading to fake crypto wallets or investment platforms.

How to Spot a Malicious QR Code

Since you cannot read a QR code with your eyes, the trick is to inspect the context and the destination URL before acting.

Red FlagWhy It Matters
Sticker looks pasted over another stickerClassic overlay scam at hawker stalls and shops
URL uses unfamiliar or misspelled domains (e.g., dbs-secure-sg.com)Legitimate banks use dbs.com.sg, ocbc.com, uob.com.sg
Prompt to download an APK or third-party appLegitimate SG apps are on Google Play or App Store — never sideloaded
Urgency language: "Pay within 24 hours or face penalty"Government agencies do not demand instant QR payments
QR code in an unsolicited email or SMSBanks and Singpass never send QR codes for login
Merchant name on PayNow prompt does not match the shopPayment is being redirected to a mule account

10 Steps to Stay Safe from QR Code Scams in Singapore

  1. Preview the URL before opening. Both iOS and Android show the destination link when you scan. Read it carefully before tapping.
  2. Verify the merchant name on PayNow. Before confirming any transfer, check that the recipient name matches the business. If it shows an unrelated individual's name, cancel.
  3. Never download apps from a QR code. Install banking, government, and delivery apps only from the official Google Play Store or Apple App Store.
  4. Enable Google Play Protect and Scam Shield. Singapore's ScamShield app (by NCPC and Open Government Products) blocks known scam URLs and calls.
  5. Look for physical tampering. At payment terminals, check whether a QR sticker is peeling, pasted crookedly, or covering another sticker. Ask the stall owner to confirm.
  6. Use bank apps, not QR-linked web pages, for logins. Never log in to DBS, OCBC, UOB, or Singpass through a link opened from a QR code.
  7. Turn on transaction alerts. Get instant SMS or push notifications for every card and PayNow transaction so you can spot fraud fast.
  8. Set low daily transfer limits. Most banks in Singapore allow you to cap daily PayNow and FAST transfers. Keep them low and raise them only when needed.
  9. Use encrypted DNS or a private browser. Services like Cloudflare 1.1.1.1 or Firefox Focus can block many known phishing domains at the network level.
  10. Report suspicious QR codes. Call the ScamShield Helpline at 1799, report to the Singapore Police at police.gov.sg/iwitness, or submit to scamshield.gov.sg.

What Businesses in Singapore Should Do

If you run a hawker stall, F&B outlet, retail shop, or any business that accepts SGQR or PayNow, you have a duty of care to your customers.

  • Laminate and secure your QR codes. Use tamper-evident stickers or place codes behind a clear acrylic cover.
  • Inspect payment stickers daily. Train staff to check for overlays every morning and after each shift change.
  • Display your registered business name clearly. Customers should be able to cross-check the PayNow recipient name against your signage.
  • Use dynamic QR codes where possible. Dynamic codes tied to your POS system are harder to spoof than static printed stickers.
  • Avoid unknown link shorteners in marketing QR codes. If you must shorten URLs for menus, promotions, or feedback forms, use a reputable service like Lunyb that provides link previews and analytics so customers can trust where the code leads. You can read our honest review of Lunyb or compare it against alternatives in our 2026 URL shortener buyer's guide.

What to Do If You Have Been Scammed

Speed matters. The faster you act, the higher your chance of recovering funds.

  1. Call your bank immediately. Every major Singapore bank has a 24/7 anti-scam hotline. Freeze your account and cards.
  2. Activate the "kill switch" if your bank offers one (DBS, OCBC, UOB, Standard Chartered all do). This locks all digital access instantly.
  3. File a police report at any Neighbourhood Police Centre or via police.gov.sg/iwitness.
  4. Call the Anti-Scam Helpline at 1800-722-6688.
  5. Report the scam to ScamShield at scamshield.gov.sg so the malicious URL is added to the national blocklist.
  6. Change all affected passwords from a clean device, and enable two-factor authentication using an authenticator app (not SMS) where possible.
  7. Uninstall any suspicious apps and consider a factory reset if you sideloaded an APK.

The Role of MAS, IMDA, and SPF in Fighting QR Scams

Singapore has some of the strongest anti-scam infrastructure in Asia. The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) rolled out the Shared Responsibility Framework in late 2024, which sets out when banks and telcos must reimburse phishing scam victims. The Infocomm Media Development Authority (IMDA) has mandated SMS Sender ID registration to block spoofed messages from impersonating banks and government agencies.

The Anti-Scam Command (ASCom) under SPF works with banks to freeze mule accounts within hours of a report, and the ScamShield app now blocks millions of scam messages and URLs each month. Still, these safeguards work best when combined with personal vigilance.

Frequently Asked Questions

Are QR code scams common in Singapore?

Yes. The Singapore Police Force has reported a sharp rise in quishing cases since 2022, with victims losing millions of dollars collectively. Common vectors include fake bubble tea surveys, overlaid PayNow stickers at hawker stalls, and phishing emails containing QR codes.

Is it safe to scan QR codes at hawker centres?

Generally yes, but always check that the sticker is not pasted over another, verify that the PayNow recipient name matches the stall, and confirm the amount before authorising. If anything looks off, pay by cash or ask the stallholder to send you their PayNow QR directly.

Can iPhones get malware from QR codes?

iPhones are much harder to infect because iOS does not allow app sideloading through Safari. However, iPhone users are still fully exposed to phishing sites that steal Singpass, bank, or credit card credentials. The threat is credential theft, not device malware.

Will my bank refund me if I lose money to a QR scam?

Under Singapore's Shared Responsibility Framework, banks and telcos may share liability if they failed in their anti-scam duties. However, if you willingly entered your credentials or approved the transfer, recovery is not guaranteed. Always act within minutes and file a police report to maximise your chances.

How do I report a suspicious QR code in Singapore?

Report it to ScamShield at scamshield.gov.sg, call the Anti-Scam Helpline at 1800-722-6688, or file a report at police.gov.sg/iwitness. If it is a physical sticker in a public place, also notify the venue owner and, if applicable, the town council or NEA.

Final Thoughts

QR codes are not going away — they are woven into how Singapore pays, orders, and accesses government services. The good news is that a few seconds of caution before every scan is enough to stop the vast majority of quishing attacks. Preview the URL, verify the merchant name, refuse APK downloads, and use tools like ScamShield to add a safety net. Share this guide with your parents, grandparents, and friends who may not yet recognise the signs — because in the fight against scams, awareness is the strongest firewall we have.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles