facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··10 min read

QR codes have become part of everyday life in Singapore. You scan them to pay for kopi at the hawker centre, top up your EZ-Link, order food at restaurants, access government services, and even join Wi-Fi networks. But this convenience has a dark side: QR code scams, known as "quishing" (QR phishing), have exploded across the island, with the Singapore Police Force and Cyber Security Agency (CSA) issuing repeated warnings.

In 2024 alone, victims in Singapore lost tens of millions of dollars to scams involving malicious QR codes, ranging from bubble tea surveys to fake parking fines. This comprehensive guide explains how QR code scams work in the local context, the most common tactics used against Singaporean consumers, and step-by-step measures you can take to stay safe.

What Are QR Code Scams?

A QR code scam is a form of phishing where fraudsters use a QR (Quick Response) code to redirect victims to malicious websites, trigger malware downloads, or trick them into authorising fraudulent payments. Because a QR code hides the destination URL behind a pattern of squares, users cannot see where they are going until they scan.

Scammers exploit this blind trust by placing fake codes in public places, sending them via messaging apps, or overlaying them on legitimate posters. Once scanned, the code often leads to a fake banking login page, a spoofed SingPass portal, or an app installer disguised as a legitimate service.

Why Singapore Is a Prime Target

  • High digital adoption: Over 97% of Singaporeans own a smartphone, and QR-based payments (PayNow, PayLah!, GrabPay) are ubiquitous.
  • Cashless culture: Hawker centres, retail stores, and even buskers accept SGQR payments.
  • Trust in institutions: Singaporeans generally trust official-looking notices, which scammers exploit with fake IRAS, LTA, or MOM branding.
  • Multilingual audience: Scam messages in English, Mandarin, Malay, and Tamil widen the attack surface.

The Most Common QR Code Scams in Singapore

Understanding the specific playbooks used locally helps you spot them faster. Here are the dominant scam types the police and banks have flagged.

1. The Bubble Tea Survey Scam

This is perhaps the most infamous quishing scam in Singapore. Victims receive a message or see a poster offering a free cup of bubble tea in exchange for completing a survey via a QR code. Scanning the code leads to an APK file (Android app) that, once installed, contains a Remote Access Trojan (RAT). The malware then monitors the victim's banking app credentials and, in some cases, drains entire savings accounts, sometimes hundreds of thousands of dollars in a single incident.

2. Fake Parking Fine or Traffic Notice

Scammers place counterfeit notices on cars in HDB carparks or private lots. The notice claims the vehicle has been issued a fine and instructs the owner to scan a QR code to "pay immediately to avoid additional penalties." The code leads to a fake LTA or HDB payment portal that harvests credit card details.

3. Restaurant and Hawker Stall Overlay Scams

Fraudsters stick their own QR code stickers over the legitimate SGQR codes at hawker stalls, coffee shops, or restaurants. Customers scan and pay, but the money goes directly to the scammer's e-wallet instead of the merchant. This has been reported in Chinatown, Geylang, and even shopping mall food courts.

4. Fake SingPass or Government Service QR Codes

Emails and SMS messages impersonating IRAS, CPF Board, or ICA include QR codes that lead to fake SingPass login pages. Once you enter your credentials and 2FA code, scammers hijack your account to change bank details, apply for loans, or access sensitive records.

5. Delivery and Parcel Redelivery Scams

With Singaporeans ordering heavily from Shopee, Lazada, Taobao, and Amazon, scam SMS messages claiming a "failed delivery" with a QR code for rescheduling are common. The code leads to a fake SingPost, Ninja Van, or Qxpress site that steals payment details.

6. Investment and Cryptocurrency QR Scams

On Telegram, WhatsApp, and Facebook, scammers promoting fake investment schemes send QR codes that supposedly link to "exclusive trading platforms." Victims deposit funds via a QR wallet address that they never see again.

How Quishing Actually Works: A Technical Breakdown

Knowing the mechanics behind these scams helps you interrupt the attack chain. Here is what typically happens after you scan a malicious code:

  1. Redirection: The QR code contains a shortened or obfuscated URL that hides the true destination.
  2. Landing page delivery: You are taken to a page that mimics a bank, government agency, or delivery firm, often pixel-perfect copies.
  3. Credential harvesting or malware drop: You are asked to log in, enter card details, or download an "app." On Android, sideloaded APKs bypass Google Play protections.
  4. Accessibility service abuse: Malicious apps request Android Accessibility permissions, allowing them to read your screen, capture OTPs, and even control your device.
  5. Silent fund transfer: The attacker waits until you open your banking app, then either steals credentials in real time or initiates transfers while you sleep.

Red Flags: How to Spot a Malicious QR Code

Before you scan, run through this quick mental checklist. If any red flag appears, do not proceed.

Warning SignWhy It Matters
Sticker placed over existing QR codeClassic overlay scam at hawker stalls and shops.
QR code in unsolicited SMS or emailLegitimate banks and agencies rarely send QR codes via SMS.
Urgency ("pay within 24 hours")Pressure tactics are a hallmark of scams.
Prompts to download an APK or unknown appNever sideload apps from links; use Google Play or App Store only.
URL does not match the brand (e.g., dbs-secure-sg.com)Fake domains impersonate real ones with slight variations.
Requests for full card details or SingPass OTPLegitimate services never ask for OTPs via a scanned page.
Poor grammar or awkward Mandarin translationsMany scam pages are auto-translated.

10 Practical Steps to Protect Yourself

Follow these habits every time you interact with a QR code in Singapore.

  1. Preview the URL before opening. Modern iPhones and Android phones display the destination URL when you scan. Read it carefully before tapping.
  2. Look for the SGQR logo. Legitimate payment QR codes in Singapore carry the official SGQR branding with a merchant identification number.
  3. Verify with the merchant. If paying at a stall, confirm the merchant name that appears in your PayNow or PayLah! app matches the shop.
  4. Never install APKs from scanned links. Only download apps from the Google Play Store or Apple App Store. Enable Google Play Protect.
  5. Enable Money Lock on your bank account. DBS, OCBC, and UOB now offer Money Lock, which ring-fences a portion of your funds from digital transfers.
  6. Turn on ScamShield. The ScamShield app by the Singapore Police Force and Open Government Products filters known scam SMS and calls.
  7. Use biometric login for banking apps. Avoid saving passwords in browsers where malware can extract them.
  8. Do not scan QR codes from strangers. Whether on the street, in messages, or on random posters, treat unknown codes as suspicious.
  9. Check the URL bar for HTTPS and correct spelling. Look for the padlock and the exact official domain (e.g., singpass.gov.sg, not singpass-login.com).
  10. Report suspicious codes. Forward scam SMS to 9-SPF-SPF (79737737) or report at ScamShield.gov.sg.

Safe QR Code Practices for Businesses

If you run a business in Singapore, protecting your customers is also protecting your reputation. Here are practical steps merchants should take.

1. Laminate or Frame Your QR Codes

Overlay scams rely on stickers. A laminated, framed, or engraved QR code makes tampering obvious and much harder.

2. Inspect Payment QR Codes Daily

Train staff to physically check every SGQR code at the start and end of each shift. Compare the merchant name shown in test scans against your registered business.

3. Use Branded Short Links for Marketing

When embedding QR codes in flyers, receipts, or ads, use a reputable short-link platform that shows clear analytics and lets you disable compromised links instantly. Tools like Lunyb allow you to create branded, trackable short URLs so customers can verify the destination before clicking. For a broader look at options, see our 2026 URL shortener buyer's guide.

4. Educate Customers

Place a small notice near your QR code reminding customers to verify the merchant name in their payment app before confirming a transfer.

What to Do If You've Been Scammed

Speed matters. Every minute a scammer has access to your accounts increases the damage. Follow these steps immediately:

  1. Call your bank's 24/7 anti-scam hotline. DBS: 1800-339-6963, OCBC: 1800-363-3333, UOB: 1800-222-2121. Ask them to freeze your accounts.
  2. Disconnect the device from the internet. Turn on aeroplane mode to stop malware from communicating with attackers.
  3. Uninstall suspicious apps. Boot into safe mode on Android if the app resists removal.
  4. File a police report. Visit any Neighbourhood Police Centre or lodge a report online at police.gov.sg.
  5. Call the Anti-Scam Helpline at 1800-722-6688. They can coordinate with banks to trace and hold suspicious transfers.
  6. Change all passwords. Especially SingPass, banking, email, and any account tied to your phone number.
  7. Perform a full factory reset. If malware was installed, a reset is the safest way to remove it fully.
  8. Monitor your credit. Check with the Credit Bureau Singapore for any unauthorised loan applications.

Tools and Resources for Singapore Residents

Take advantage of the free protective tools available locally.

ToolWhat It DoesWhere to Get It
ScamShield AppBlocks scam calls and filters scam SMSApp Store / Google Play
Money LockRing-fences bank funds from digital transfersDBS, OCBC, UOB apps
SingPass Face VerificationAdds biometric layer to loginsSingPass app settings
Google Play ProtectScans Android apps for malwarePlay Store settings
Anti-Scam HelplineCoordinates response with banks and policeCall 1800-722-6688
ScamShield.gov.sgCentral reporting portalscamshield.gov.sg

The Future of QR Code Security in Singapore

Regulators are stepping up. The Monetary Authority of Singapore (MAS) has mandated Shared Responsibility Framework rules that require banks and telcos to shoulder more of the burden when scam victims can prove reasonable diligence. Meanwhile, IMDA is working with telcos to filter malicious URLs at the network level, and the SPF continues to expand ScamShield's detection database.

For consumers, though, technology cannot replace vigilance. Every scan is a decision, and every second you take to verify a URL is a second the scammers cannot exploit. Combine healthy scepticism with the tools listed above, and you will make yourself a much harder target.

Frequently Asked Questions

Can I get scammed just by scanning a QR code without clicking anything?

Simply scanning a QR code and previewing the URL is generally safe. The risk begins when you tap the link, enter information, or install a downloaded app. Always read the preview URL before proceeding. Modern iPhones and Android devices both display the destination for a reason.

Are QR codes at hawker centres in Singapore safe to use?

Legitimate SGQR codes are safe, but overlay scams do happen. Always verify that the merchant name displayed in your PayNow or PayLah! app matches the stall before confirming payment. If the name looks unfamiliar or is an individual's name for a business stall, pause and ask the vendor.

What is the difference between phishing and quishing?

Phishing typically uses email or SMS links to trick victims into visiting fake sites. Quishing (QR phishing) uses QR codes as the delivery mechanism instead. Because QR codes obscure the destination URL, quishing often bypasses the visual cues people rely on to spot fake links.

Will my bank refund me if I lose money to a QR code scam?

Under Singapore's Shared Responsibility Framework, banks and telcos may be required to compensate victims if they failed in their duties. However, if you willingly authorised the transfer or ignored scam warnings, recovery is not guaranteed. Report the incident within minutes for the best chance of freezing the funds before they are withdrawn overseas.

How can I safely create QR codes for my own business?

Use a reputable link management platform to generate branded, trackable short URLs and then convert them into QR codes. This lets you monitor scans, detect unusual traffic, and disable the link if it is ever misused. Platforms like Lunyb offer these features, and you can compare alternatives in our Rebrandly review.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles