QR Code Scams in Singapore: How to Stay Safe in 2026
QR codes are now part of daily life in Singapore. We scan them at hawker centres to pay for chicken rice, at MRT stations for e-menus, at carparks for payments, and even on parking coupons. But this convenience has a dark side: QR code scams, also known as quishing, have become one of the fastest-growing fraud tactics targeting Singaporeans.
According to the Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA), scams involving malicious QR codes have surged, with victims losing anywhere from a few hundred dollars to over S$100,000 in a single incident. This guide explains how these scams work, highlights real Singapore cases, and gives you a practical playbook to stay safe.
What Are QR Code Scams?
A QR code scam is a type of phishing attack where criminals use a Quick Response (QR) code to redirect victims to a fraudulent website, trigger a malicious download, or trick them into authorising a payment. Because QR codes are machine-readable, you can't tell what's inside them just by looking.
The scam works because of trust. Most Singaporeans assume a QR code stuck on a shop window, a signboard, or a letter from a "government agency" is legitimate. Scammers exploit that assumption by pasting their own codes over real ones or sending phishing codes through email, WhatsApp, and even physical mail.
Why QR Codes Are a Perfect Scam Tool
- Opaque destinations: You can't preview the URL by eye.
- Universal adoption: SGQR, PayNow, and PayLah! have normalised scanning for payments.
- Mobile-first: Phones have smaller screens, making fake URLs harder to spot.
- Low cost for criminals: A sticker printer and a phishing page are all that's needed.
Common QR Code Scams in Singapore
The SPF, MAS, and local banks have flagged several recurring scam patterns. Here are the most common ones you should know.
1. The "Bubble Tea Survey" Scam
This case made headlines when a 60-year-old woman lost S$20,000 after scanning a QR code stuck on the glass door of a bubble tea shop in Bukit Timah. The sticker invited customers to complete a survey for a free cup of milk tea. Scanning it prompted her to download a third-party Android app that gave scammers remote access to her phone and banking credentials.
2. Fake Parking Fine or Coupon Notices
Scammers paste counterfeit QR codes on car windscreens or over genuine HDB and URA parking coupons. The code leads to a cloned payment page that captures card details or triggers a malicious app install.
3. Fake Hawker and F&B Payment Codes
Fraudsters stick fake SGQR or PayNow stickers over the real ones at hawker stalls, coffee shops, or small F&B outlets. Payments go directly into the scammer's account instead of the merchant's. By the time the stall owner notices, dozens of transactions may already be lost.
4. Fake IRAS, SingPost, or Government Letters
Victims receive physical letters or emails claiming to be from IRAS, SingPost, ICA, or the CPF Board. The QR code supposedly leads to "verify your identity" or "settle outstanding tax." The real destination is a Singpass or banking phishing page.
5. Fake E-Commerce and Carousell Listings
A "seller" or "buyer" sends a QR code via WhatsApp or Telegram, claiming it's needed to receive payment, verify the listing, or confirm delivery. The code triggers a bank transfer out of the victim's account, not into it.
6. Love and Investment Scams
In romance and investment scams, the "partner" or "broker" sends QR codes for crypto wallets or investment platforms. Once scanned and funded, the money is irretrievable.
How Quishing Attacks Actually Work
Understanding the mechanics helps you spot red flags early. Here is the typical attack flow:
- Bait: A sticker, letter, email, or chat message with a QR code is placed in front of the victim.
- Scan: The victim scans with the default camera app or a scanner app.
- Redirect: The code opens a URL, often shortened or disguised to look like a bank, government, or merchant site.
- Harvest or install: The victim is asked to log in, enter OTPs, or download an APK file (on Android).
- Takeover: Credentials are stolen, or the malicious app silently monitors the screen, captures keystrokes, and intercepts SMS OTPs.
- Drain: Scammers log into the banking app, often in the middle of the night, and transfer funds out.
Red Flags: How to Spot a Suspicious QR Code
Not every QR code is dangerous, but these warning signs should make you pause.
Physical Red Flags
- A sticker that looks newly placed over an existing one.
- Peeling edges or misaligned logos.
- QR codes on carpark signs, letterboxes, or lamp posts with no clear owner.
- Codes near ATMs, bank branches, or MRT stations without official branding.
Digital Red Flags
- The URL preview shows an unfamiliar domain (e.g.
singpass-verify.xyzinstead ofsingpass.gov.sg). - You are asked to download an APK file or sideload an app outside the Google Play Store or Apple App Store.
- The page asks for your Singpass password, full NRIC, OTP, or banking credentials immediately.
- The site uses urgent language: "Your account will be frozen in 24 hours."
- Spelling and grammar errors on a supposedly official page.
How to Verify a QR Code Before Acting
Follow this quick 5-step verification process before you tap, log in, or pay.
- Preview the URL. Modern iPhones and Android phones show the destination URL at the top of the screen before opening it. Read it carefully.
- Check the domain. Government agencies use
.gov.sg. Local banks use their official domains (dbs.com.sg, uob.com.sg, ocbc.com, etc.). If anything looks off, stop. - Never download apps from a QR code. Always install banking and government apps directly from the App Store or Google Play.
- Confirm with the merchant. At hawker stalls or shops, check that the name on the PayNow or SGQR confirmation screen matches the stall owner's registered business.
- Use a trusted link checker. If you shorten or share links yourself, use a reputable service with transparent redirect previews, such as Lunyb, which lets recipients see where a link is going before they commit.
What to Do If You've Already Scanned a Malicious QR Code
If you suspect you've been scammed, act within the first 30 minutes. Speed is everything.
- Disconnect your phone from the internet. Switch to airplane mode immediately to stop remote access.
- Call your bank's 24/7 anti-scam hotline. DBS: 1800-339-6963, OCBC: 1800-363-3333, UOB: 1800-222-2121. Request an immediate freeze on your accounts.
- Call the ScamShield Helpline: 1799, or visit scamshield.gov.sg.
- File a police report at any Neighbourhood Police Centre or via eservices.police.gov.sg.
- Factory reset your phone if you installed any suspicious APK. Reinstall apps only from official stores.
- Change all passwords, especially Singpass, email, and banking, from a separate, clean device.
- Enable Money Lock with your bank. Most Singapore banks now offer a feature that locks a portion of your savings from online transfers.
Comparing Safe vs Unsafe QR Code Habits
| Scenario | Safe Habit | Risky Habit |
|---|---|---|
| Paying at a hawker stall | Check that merchant name on screen matches the stall | Tap confirm without reading the recipient |
| Scanning a letter from "IRAS" | Log in to IRAS website directly to verify notice | Scan the QR and enter Singpass credentials |
| Receiving a WhatsApp QR code | Verify sender identity via a phone call | Scan immediately because "a friend" sent it |
| Installing a merchant app | Search the app on Google Play or App Store | Download an APK file from a QR link |
| Parking payment | Use the official Parking.sg app | Scan QR codes on random carpark signboards |
Extra Protection Settings for Singapore Users
Beyond awareness, there are technical controls every Singapore resident should enable today.
On Your Phone
- Install ScamShield (by Open Government Products) from the official app store.
- Enable Google Play Protect on Android and keep sideloading disabled.
- Turn on biometric login for all banking apps.
- Use encrypted DNS (such as Cloudflare 1.1.1.1 or NextDNS) to block known phishing domains at the network level.
On Your Bank Account
- Activate Money Lock (DBS digiVault, OCBC Money Lock, UOB LockAway).
- Lower default daily transfer limits to what you actually need.
- Enable transaction alerts via SMS and in-app push.
- Register for Singpass Face Verification for high-risk transactions.
When Sharing or Shortening Links
If you run a small business or community group in Singapore, how you share links matters. Shortened links from unknown services can look just as suspicious as a scam QR code to a careful customer. Use a reputable shortener with analytics and preview options so your audience can trust the destination. Our guide to the best URL shorteners for 2026 compares the leading options, and you can also read our honest review of Lunyb if you're evaluating it for your business.
What Banks and Authorities in Singapore Are Doing
Singapore has rolled out some of the strongest anti-scam measures in the region. Understanding them helps you take full advantage.
- Shared Responsibility Framework (SRF): MAS and IMDA's framework that assigns responsibility between banks, telcos, and consumers for phishing scam losses.
- Default kill switch: All major local banks let you instantly freeze your account from within the app.
- Anti-Scam Command (ASCom): SPF's dedicated unit that coordinates with banks to trace and freeze scam proceeds in real time.
- ScamShield app and 1799 helpline: Centralised reporting and SMS/call filtering.
- SMS Sender ID Registry (SSIR): Only registered entities can send branded SMS, reducing fake bank SMS.
Protecting Vulnerable Family Members
Many QR scam victims in Singapore are seniors or new technology users. A few practical steps for families:
- Set up Money Lock on their accounts and keep the unlock process offline (requires a branch visit).
- Lower transfer limits to S$500 or less per day.
- Install ScamShield and show them how to forward suspicious SMS.
- Agree on a family rule: no scanning codes from letters, stickers, or chats without calling you first.
- Remove banking apps from phones of relatives who don't actually use digital banking.
Frequently Asked Questions
Is it safe to use PayNow and SGQR at hawker centres?
Yes, PayNow and SGQR are safe systems when used correctly. The risk comes from fake stickers pasted over genuine ones. Always confirm that the merchant name shown on your bank app matches the stall or shop you are paying before you tap confirm.
Can scanning a QR code alone infect my phone?
Simply opening the URL rarely infects your phone on its own, especially on iOS. The real danger is the next step: entering credentials on a phishing page, or installing a malicious APK file on Android. Never sideload apps from QR codes.
What should I do if a scammer already has my Singpass login?
Immediately log in to the official Singpass app or website from a clean device and reset your password. Enable Singpass Face Verification, revoke any suspicious third-party app access, and report the incident at 1799 and to the police. Also inform your bank, since Singpass can be used to open new accounts in your name.
Are QR codes in emails more dangerous than links?
They can be, because QR codes bypass most email security filters that scan traditional links. Scammers increasingly embed QR codes in PDF attachments or images to reach your inbox. Treat any unexpected QR code in an email with the same suspicion as an unknown link.
Will my bank refund me if I lose money to a QR code scam?
Under Singapore's Shared Responsibility Framework, banks may bear losses if they failed to meet their duties (such as sending transaction alerts). However, if you willingly entered OTPs or installed a malicious app, the bank may not reimburse you. Prevention is far more reliable than hoping for a refund.
Final Thoughts
QR code scams in Singapore work because they hijack a habit we've all built: scan, tap, pay, done. The fix isn't to stop using QR codes, it's to add one or two seconds of friction before you commit. Preview the URL. Check the merchant name. Never install an app from a code. Enable Money Lock. Teach your parents the same.
Do that consistently, and you'll sidestep the vast majority of quishing attacks targeting Singapore today, keeping your Singpass, your bank account, and your peace of mind intact.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Phishing Attacks: How to Recognize and Avoid Them in 2026
Phishing attacks are the top entry point for cybercrime in 2026. Learn how to recognize the warning signs, the main attack types — from spear phishing to quishing — and the practical steps you can take to protect your accounts and data.
End-to-End Encryption Explained: How It Works and Why It Matters
End-to-end encryption keeps your messages private from everyone — including the companies that transmit them. This guide explains how E2EE actually works, where to use it, and what its limitations are in 2026.
Email Security Best Practices for 2026: The Complete Guide
Email remains the top attack vector in 2026, with AI-generated phishing and account takeovers reaching new levels of sophistication. This complete guide covers the essential email security best practices every user and organization needs to defend against modern threats.
Phishing Attacks in Singapore: Recognize and Avoid Them in 2026
Phishing attacks in Singapore have grown increasingly sophisticated, targeting bank customers, SingPass users, and SMEs. Learn how to recognize the red flags, avoid common scams, and respond quickly if you're ever compromised.