facebook-pixel

QR Code Scams in Singapore: How to Stay Safe in 2026

L
Lunyb Security Team
··11 min read

QR codes are everywhere in Singapore — on hawker stall payment stickers, car park signs, restaurant menus, parking meters, and even the back of taxi seats. They are convenient, fast, and part of everyday life. Unfortunately, that same convenience has made them one of the fastest-growing attack surfaces for scammers targeting Singaporeans. The Singapore Police Force and the Cyber Security Agency (CSA) have both issued repeated warnings about QR code scams — a technique often called quishing (QR phishing).

This guide explains how QR code scams work in Singapore, highlights real cases that have hit local victims, and walks you through practical steps to stay safe at hawker centres, car parks, retail stores, and online.

What Are QR Code Scams?

A QR code scam is a form of phishing where criminals use a malicious QR code to redirect victims to fake websites, trigger unauthorised payments, or trick them into downloading malware. Because the destination of a QR code is hidden until it is scanned, it is extremely easy for scammers to disguise a dangerous link as a legitimate one.

In Singapore, QR code scams typically follow one of three patterns:

  1. Fake payment stickers pasted over legitimate PayNow or SGQR codes at hawker stalls, drink stores, or parking terminals.
  2. Phishing links on flyers, lucky draw cards, parking tickets, or "survey" posters that redirect to fake bank or government login pages.
  3. Malicious app downloads prompting victims to sideload an Android APK that steals banking credentials and intercepts SMS OTPs.

Why Singapore Is a Prime Target

Singapore has one of the highest QR code adoption rates in the world. SGQR, PayNow, and merchant QR payments are integrated into almost every retail and F&B interaction. According to CSA and MAS advisories, scammers exploit this trust in three ways:

  • Habit: Singaporeans scan QR codes without a second thought.
  • Mobile-first behaviour: Most banking happens on a phone, where fake login pages look nearly identical to real ones.
  • Trust in official-looking branding: Scammers reproduce SPF, LTA, IRAS, HDB, and bank logos with high accuracy.

Losses from phishing and malware-enabled scams in Singapore have crossed hundreds of millions of dollars in recent years, and QR codes are a growing contributor to that total.

Common QR Code Scams in Singapore

1. The Bubble Tea "Survey" Scam

One of the most publicised cases in Singapore involved an elderly woman who scanned a QR code sticker on the glass door of a bubble tea shop. The sticker offered a free cup of milk tea in exchange for completing a survey. The code led to a fake app download that gave scammers remote access to her phone. More than S$20,000 was drained from her bank account overnight.

2. Fake PayNow Stickers at Hawker Centres and Carparks

Scammers paste their own QR code sticker directly over a merchant's legitimate SGQR or PayNow code. Customers scan, pay, and the money goes to the scammer instead of the stall. Variations have appeared at coffee shops in Bedok, Toa Payoh, and Jurong, and on parking meters in private estates.

3. Fake Parking Fine or LTA Notice

A fake notice is placed on a windscreen or lamp post with a QR code to "pay the fine" or "appeal online". The code leads to a phishing site that collects Singpass or bank credentials.

4. Fake Food Delivery or E-Commerce Refund

Victims receive a WhatsApp or Telegram message with a QR code claiming to process a refund from Shopee, Lazada, foodpanda, or Grab. The code opens a fake payment gateway that captures card details.

5. Quishing Emails Targeting Workers

Employees receive an email that looks like it comes from HR, IT, or Microsoft 365, asking them to scan a QR code to "re-verify" their account. Because the QR opens on a personal phone, corporate security tools cannot inspect the link.

How to Spot a Malicious QR Code

Unlike a suspicious URL in an email, a QR code gives you almost no visual information. You need to inspect the preview URL and the destination page carefully. Here are the warning signs:

  • The QR sticker looks freshly pasted over another sticker, or has peeling edges.
  • The preview URL shown by your camera is a random shortener or an unfamiliar domain.
  • The destination asks you to download an APK file (never do this on Android outside the Play Store).
  • The page asks for your Singpass password, bank login, full card number, or OTP.
  • The URL mimics a real brand but with a misspelling (e.g. dbss-sg.com, paynow-verify.net, singpass-login.app).
  • You feel rushed — "limited time offer", "your account will be suspended", or "pay within 10 minutes".

10 Steps to Stay Safe from QR Code Scams in Singapore

1. Always Preview the URL Before Tapping

Both iOS and Android show a preview of the link when you scan a QR code with the native camera app. Read the full domain carefully. If it does not match the brand you expect, do not open it.

2. Inspect the Sticker Physically

At hawker stalls, coffee shops, and parking terminals, look for signs of tampering. If a QR sticker is pasted over another, peeling, or looks printed on cheap paper, alert the stall owner and pay by cash or card instead.

3. Never Download Apps from a QR Code

Legitimate Singapore banks, government agencies, and major F&B brands will never ask you to download an APK or sideload an app via a QR code. Only install apps from the official App Store or Google Play Store.

4. Turn On "Scam Shield" and App Restrictions

Singapore banks (DBS, OCBC, UOB, Standard Chartered, Citi) and the government's ScamShield app offer anti-malware features that block sideloaded apps during banking sessions. Enable these protections and keep your phone's OS updated.

5. Use a Separate Payment Method for Unknown Merchants

When paying at a stall you have never visited, use physical cash, a contactless card tap, or scan the merchant's QR directly from the official bank app (DBS PayLah!, OCBC Digital, UOB TMRW) rather than your phone camera. The bank app validates SGQR codes.

6. Verify Official Notices Independently

Received a parking fine, IRAS tax notice, or HDB letter with a QR code? Do not scan it. Instead, log in to the official portal yourself (mytax.iras.gov.sg, hdb.gov.sg, or the LTA OneMotoring site) and check for the notice there.

7. Treat Shortened Links with Extra Caution

Scammers often hide malicious destinations behind URL shorteners. Before clicking any shortened link from a QR code, expand it using a link preview tool. Reputable shorteners such as Lunyb provide safe, transparent redirects and let legitimate businesses use custom branded domains — which also helps you recognise authentic links. If you want to understand which shorteners are trustworthy, our 2026 buyer's guide to URL shorteners compares the leading options.

8. Never Enter Singpass or Banking Credentials on a Page Opened via QR

This is the single most important rule. No government agency or bank in Singapore will ever require you to log in via a QR code sent through SMS, WhatsApp, email, or a physical sticker. Always open Singpass or your banking app directly.

9. Report Suspicious Codes

If you suspect a QR code is fraudulent:

  • Call the ScamShield Helpline at 1799.
  • Report via the ScamShield app.
  • Make a police report at police.gov.sg/iwitness.
  • Alert the merchant or property management on-site so they can remove the fake sticker.

10. Educate Vulnerable Family Members

Elderly parents and young children are the most frequently targeted groups. Walk them through what a safe QR scan looks like, help them enable ScamShield, and set up transaction limits on their bank accounts. DBS, OCBC, and UOB all allow you to cap daily PayNow and online transfer limits — reduce these to a sensible level.

QR Code Scam Red Flags: Quick Reference Table

Red FlagWhat It Usually MeansWhat to Do
Sticker pasted over another QR codeFake PayNow overlay scamPay by cash/card; alert stall owner
Preview URL uses an unknown or misspelled domainPhishing siteDo not open; close camera app
Asked to download an APK fileBanking trojan / malwareDelete immediately; never install
Page asks for Singpass password or OTPCredential harvestingClose page; report to ScamShield 1799
Urgent deadline or threat of fineSocial engineering pressureVerify via official portal directly
QR code sent via WhatsApp from unknown numberMass phishing campaignDelete and block the sender

What To Do If You've Already Scanned a Malicious QR Code

If you suspect you have fallen for a QR code scam, speed matters. Follow this checklist within the first hour:

  1. Disconnect your phone from the internet — enable Airplane Mode immediately to stop any installed malware from communicating.
  2. Call your bank's 24/7 fraud hotline to freeze your accounts (DBS: 1800 339 6963, OCBC: 1800 363 3333, UOB: 1800 222 2121).
  3. Freeze your Singpass at singpass.gov.sg or via the Singpass app's "Account Settings".
  4. Uninstall any app you were prompted to download, then do a full factory reset if you are unsure.
  5. Change all critical passwords — bank, email, Singpass, iCloud/Google — from a different, trusted device.
  6. File a police report and report through the ScamShield app.
  7. Enable Money Lock (available on DBS, OCBC, UOB and others) on a portion of your savings to prevent future digital transfers.

How Businesses in Singapore Can Protect Customers

If you run a hawker stall, café, retail shop, or carpark, you have a responsibility to protect your customers. A few simple measures:

  • Laminate your SGQR / PayNow sticker and sign it with a marker across the laminate so tampering is visible.
  • Check your QR code daily — a quick scan to confirm the merchant name is correct.
  • Display your UEN or business name near the QR so customers can verify it matches the one shown in their bank app.
  • Use branded short links from reputable providers rather than random shortened URLs on marketing materials. For an in-depth look at which link management platforms are trustworthy for business, see our honest review of Lunyb and our Rebrandly 2026 review.
  • Train staff to recognise the signs of overlay stickers and to help confused customers who received a wrong-payment notification.

The Role of Authorities and Industry

Singapore has one of the most proactive anti-scam ecosystems in the world. The Anti-Scam Command (ASCom), ScamShield, the Shared Responsibility Framework (SRF) between banks and telcos, and the SGQR governance body are all working to reduce scam losses. However, individual vigilance remains the first line of defence. No framework can protect you if you willingly type your OTP into a fake page.

Expect continued rollout of features like:

  • Mandatory in-app warnings before high-value transfers.
  • Money Lock and "kill switch" features across all major banks.
  • Delayed activation of newly added payees.
  • Stronger SMS sender ID registration to block spoofed messages.

Frequently Asked Questions

Are QR code scams common in Singapore?

Yes. The Singapore Police Force and CSA have issued multiple advisories warning that QR code phishing (quishing) is one of the fastest-growing scam types. Cases involving fake payment stickers, fake surveys, and malicious APK downloads have resulted in individual losses ranging from a few hundred dollars to over S$100,000.

Is it safe to scan QR codes at hawker centres?

Generally yes, but always verify the merchant name that appears in your bank app before confirming payment. If the name does not match the stall, cancel the transaction immediately. For extra safety, scan directly through your bank's app (PayLah!, OCBC Digital, UOB TMRW) rather than your phone's camera, as the bank app validates SGQR codes.

What should I do if I accidentally downloaded an app from a QR code?

Immediately enable Airplane Mode, uninstall the app, call your bank's fraud hotline to freeze your accounts, change your passwords from a separate device, and perform a factory reset. Then file a police report and alert ScamShield at 1799.

Can iPhones get infected by malicious QR codes?

iPhones are harder to infect because iOS does not allow sideloading of apps outside the App Store (as of 2026, sideloading in Singapore is still restricted). However, iPhone users are still vulnerable to phishing pages that steal Singpass, bank, or card credentials. The rule remains: never enter sensitive credentials on a page opened from a QR code.

How do I verify a shortened link before clicking?

Use a link expander tool or paste the shortened URL into a preview service (many URL shorteners, including Lunyb, offer link previews). Legitimate businesses often use branded short domains so you can recognise them at a glance. If a shortened link appears on an unexpected QR code — especially one tied to banking, government, or payments — treat it as suspicious until proven otherwise.

Final Thoughts

QR codes are not going away — they are too useful. But in Singapore's hyper-digital payment landscape, a few seconds of caution before every scan can save you thousands of dollars and months of recovery. Preview every URL, never download apps from a QR, never enter Singpass or OTPs on a page opened via QR, and help the people around you (especially elderly family members) do the same.

Stay sharp, stay sceptical, and when in doubt — don't scan.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles