facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes have become part of daily life in Singapore. From ordering kopi at a hawker centre to paying with PayNow, scanning a black-and-white square is second nature. Unfortunately, scammers know this too. In the past two years, the Singapore Police Force (SPF) and Cyber Security Agency (CSA) have issued multiple advisories about the rapid rise of QR code scams, also known as "quishing" (QR phishing), with losses running into the millions of Singapore dollars.

This guide explains exactly how QR code scams in Singapore work, the most common tactics being used in 2026, and the practical steps you can take to protect your money, personal data, and devices.

What Are QR Code Scams?

A QR code scam is a form of phishing where criminals use a Quick Response (QR) code to trick victims into visiting a malicious website, downloading malware, or authorising fraudulent payments. Because the destination of a QR code is hidden until you scan it, users often trust codes without verifying where they lead.

In Singapore, scammers exploit the country's high adoption of cashless payments (PayNow, PayLah!, SGQR) and the general public trust in QR-based systems used by banks, government agencies, and F&B outlets.

Why Singapore Is a Prime Target

  • High digital payment penetration: Over 90% of Singaporeans use mobile payment apps regularly.
  • SGQR ubiquity: A unified national QR standard means people scan codes without a second thought.
  • Tourist-heavy environment: Visitors unfamiliar with local systems are easier targets.
  • Trust in institutions: Scammers impersonate MAS, IRAS, SPF, and major banks like DBS, OCBC, and UOB.

How QR Code Scams Work in Singapore

Most QR scams follow a predictable pattern. Understanding the steps helps you spot them before it's too late.

  1. Bait placement: The scammer places a fake QR code sticker over a legitimate one, or sends it via SMS, WhatsApp, email, or social media.
  2. Trigger: The message creates urgency — a parcel delivery issue, an IRAS tax refund, a bubble tea survey, or a food-review reward.
  3. Scan and redirect: The victim scans the code, which opens a website that looks identical to a legitimate bank or government portal.
  4. Credential harvest or app install: The site either asks for Singpass, SingPass Face Verification, banking credentials, and OTPs — or prompts you to install a third-party APK file.
  5. Account takeover: Once malware is installed or credentials are stolen, criminals drain bank accounts, sometimes within minutes.

The Most Common QR Code Scams in Singapore (2026)

1. The Bubble Tea and F&B Survey Scam

This is one of the most publicised scams in Singapore. Victims — often elderly women — were approached at bubble tea shops or received flyers with a QR code offering a free drink in exchange for completing a "survey." Scanning the code led to a fake app installation that stole banking credentials. In one widely reported case, a victim lost S$20,000 overnight.

2. Fake Parcel Delivery Notices (SingPost, Ninja Van, J&T)

SMS or WhatsApp messages claim a parcel is stuck at customs or requires a small redelivery fee. The QR code leads to a spoofed payment page harvesting card details.

3. IRAS and Government Impersonation

Fraudsters send messages about tax refunds, GST vouchers, or CDC vouchers with QR codes leading to fake Singpass login pages. Real government agencies never ask you to log in via a QR code in an unsolicited message.

4. Overwritten Hawker and Retail SGQR Codes

Scammers physically paste their own QR code sticker on top of a merchant's SGQR label. Payments intended for the stall owner are redirected to the scammer's PayNow account. Some victims only discover this when the stall owner points out that no payment was received.

5. Fake Charity and Donation Drives

Especially around festive seasons (CNY, Hari Raya, Deepavali, Christmas), scammers set up fake donation posters with QR codes claiming to support well-known charities.

6. Parking Coupon and ERP-Related Scams

Fake notices placed on windscreens claim you have unpaid parking fines or ERP charges. Scanning the QR code opens a phishing page mimicking OneMotoring or HDB.

Red Flags: How to Spot a Malicious QR Code

Before you scan, look for these warning signs.

Red FlagWhat It MeansWhat to Do
Sticker pasted over existing codeLikely tampered SGQRAsk the merchant to confirm the code
URL preview shows an unfamiliar domainPossible phishing siteDo not proceed; close the preview
Prompts you to download an APKAlmost certainly malwareNever sideload apps from links
Asks for Singpass or bank OTPCredential harvestingExit immediately
Urgency language ("Act now," "Last chance")Classic social engineeringVerify via official channels
Shortened link with no contextHidden destinationUse a link expander first

How to Stay Safe: 10 Practical Steps

  1. Preview the URL before opening. Both iOS and Android show the destination URL when you scan a QR code. Read it carefully before tapping.
  2. Look for HTTPS and the correct domain. Real DBS uses dbs.com.sg, not dbs-sg-secure.com. Real Singpass uses singpass.gov.sg.
  3. Never install apps from QR codes. Only download from the App Store or Google Play. If a QR asks you to install an APK, it's a scam.
  4. Enable ScamShield. The ScamShield app by the Singapore Police Force and Open Government Products blocks known scam SMS and calls.
  5. Use in-app QR scanners for payments. Scan through PayLah!, PayNow, or your bank's app — not a random third-party scanner.
  6. Check physical stickers carefully. If an SGQR code looks pasted on, peeling, or misaligned, don't scan it. Pay in cash or ask the merchant.
  7. Turn on transaction alerts and lower limits. Set daily transfer limits low by default and raise them only when needed. Enable Money Lock on your bank account for funds you never intend to move digitally.
  8. Verify unsolicited messages independently. If IRAS, MOM, or your bank supposedly contacts you, log in through the official app or website — never through the link provided.
  9. Use a URL expander for shortened links. If you receive a shortened link, expand it first to see the real destination. Reputable shorteners like Lunyb provide transparent link previews and safety checks, which is part of why they're trusted by marketers — but any link from a stranger should still be treated with caution. Read our honest review of Lunyb to understand how legitimate shorteners work.
  10. Keep your device updated. Both Android and iOS patch security vulnerabilities monthly. An outdated phone is a soft target.

What to Do If You've Been Scammed

If you suspect you've fallen victim to a QR code scam in Singapore, act within minutes — not hours.

  1. Call your bank's 24/7 fraud hotline immediately.
    • DBS/POSB: 1800-339-6963
    • OCBC: 1800-363-3333
    • UOB: 1800-222-2121
    • Standard Chartered: 1800-747-7000
  2. Freeze your accounts using the kill-switch feature in your banking app.
  3. Uninstall any suspicious apps and consider a factory reset if you installed an APK.
  4. Change your Singpass password and enable Singpass Face Verification lock.
  5. Report to the police. File a report at any Neighbourhood Police Centre or online at eservices.police.gov.sg.
  6. Report the scam to ScamShield so others can be warned.
  7. Call the Anti-Scam Helpline: 1800-722-6688.

QR Safety for Businesses and Merchants

Merchants in Singapore have a responsibility to protect their customers from tampered SGQR codes.

Best Practices for Hawkers, F&B, and Retail

  • Laminate or frame your SGQR code so tampering is visible.
  • Check your code daily before opening for business.
  • Confirm each payment — don't rely on customers to show you a screen.
  • Display your business name clearly next to the QR so customers can verify the recipient matches.
  • Train staff to recognise the physical characteristics of the official code.

For Marketers Using QR Codes

If your business runs campaigns with QR codes, using a trustworthy shortening and tracking platform matters. Customers are increasingly skeptical of unknown short links. Our 2026 buyer's guide to URL shorteners compares platforms on transparency, analytics, and security features — key criteria for building trust with Singaporean audiences who are on high alert for scams.

The Role of Government and Banks

Singapore has been proactive in fighting QR scams. Key initiatives include:

  • Shared Responsibility Framework (SRF): Effective since December 2024, requires banks and telcos to share losses with victims under specific conditions.
  • Money Lock: Offered by DBS, OCBC, UOB, and others — lets you ring-fence funds that cannot be transferred digitally.
  • ScamShield app: Government-built tool to block scam calls and SMS.
  • SMS Sender ID Registry (SSIR): All legitimate organisations must register their SMS sender IDs; unregistered ones display as "Likely-SCAM."
  • Anti-Scam Centre (ASC): Works with banks to freeze fraudulent transactions in real time.

Emerging QR Scam Trends to Watch in 2026

AI-Generated Fake Merchant Pages

Scammers now use generative AI to create pixel-perfect replicas of bank and government portals within minutes. Visual inspection alone is no longer enough — always verify the URL.

QR Codes in Physical Mail

Fake letters styled after IRAS, HDB, or CPF notices are being posted to residential addresses. The QR code inside leads to a phishing site. Physical mail feels more trustworthy, which is exactly why scammers use it.

Deepfake Video + QR Combos

Videos on TikTok and Facebook featuring deepfaked local celebrities or politicians promoting "investment opportunities" now include QR codes that lead to fake trading platforms.

Malicious Wi-Fi QR Codes

Public posters offering "free Wi-Fi" via QR code can connect your device to a rogue hotspot that intercepts your traffic. Stick to official Wireless@SG networks.

Building Long-Term Habits

Cybersecurity is not a one-time fix. Treat every QR code you encounter with the same skepticism you'd apply to an email attachment from an unknown sender. A three-second pause to check the URL preview can save you thousands of dollars and months of stress.

Share this knowledge with elderly relatives, foreign domestic workers, and children — the demographics most frequently targeted in Singapore. The Singapore Police Force notes that victims aged 60 and above suffer the largest average losses per scam.

Frequently Asked Questions

Are all QR codes in Singapore dangerous?

No. QR codes themselves are just a way of encoding a URL or payment instruction. The technology is safe. The danger comes from where the code leads. Codes issued by legitimate businesses, banks, and government agencies are safe — the risk is tampered or fraudulent codes distributed by scammers.

Will my bank refund me if I fall victim to a QR code scam?

Under Singapore's Shared Responsibility Framework, banks and telcos may share losses with victims for phishing scams if they failed to meet their duties (for example, not sending real-time alerts). However, if you willingly entered your OTP or approved a transaction on a fake site, recovery is not guaranteed. Report the scam within minutes to improve your chances.

How can I tell if an SGQR sticker has been tampered with?

Look for signs of layering (a sticker on top of another sticker), edges that peel up, mismatched printing quality, or codes that don't match the business name displayed. When in doubt, ask the merchant to verify the payment received your name and amount before you leave.

Is it safe to scan QR codes from restaurant menus?

Generally yes, but check that the code is printed directly on the menu or table (not a loose sticker). The menu URL should match the restaurant's official domain. Avoid entering payment details on a menu-linked site unless you're certain it's legitimate — prefer paying at the counter.

What should I do if I already scanned a suspicious QR code but didn't enter any information?

If you only opened the page and closed it, you're likely safe. Do not tap any download prompts, do not grant any permissions, and clear your browser cache. If the page tried to auto-download an app or file, delete it and run a security scan on your device. Monitor your bank accounts for the next 48 hours as a precaution.

Where can I report a QR code scam in Singapore?

Report to the Singapore Police Force via the online e-services portal, call the Anti-Scam Helpline at 1800-722-6688, and submit the scam details to ScamShield. If money was transferred, contact your bank's fraud hotline immediately — every minute counts for freezing funds.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles