QR Code Scams in Singapore: How to Stay Safe in 2026
QR codes are everywhere in Singapore — on hawker stall payment stickers, car park signs, restaurant menus, parking meters, and even the back of taxi seats. They are convenient, fast, and part of everyday life. Unfortunately, that same convenience has made them one of the fastest-growing attack surfaces for scammers targeting Singaporeans. The Singapore Police Force and the Cyber Security Agency (CSA) have both issued repeated warnings about QR code scams — a technique often called quishing (QR phishing).
This guide explains how QR code scams work in Singapore, highlights real cases that have hit local victims, and walks you through practical steps to stay safe at hawker centres, car parks, retail stores, and online.
What Are QR Code Scams?
A QR code scam is a form of phishing where criminals use a malicious QR code to redirect victims to fake websites, trigger unauthorised payments, or trick them into downloading malware. Because the destination of a QR code is hidden until it is scanned, it is extremely easy for scammers to disguise a dangerous link as a legitimate one.
In Singapore, QR code scams typically follow one of three patterns:
- Fake payment stickers pasted over legitimate PayNow or SGQR codes at hawker stalls, drink stores, or parking terminals.
- Phishing links on flyers, lucky draw cards, parking tickets, or "survey" posters that redirect to fake bank or government login pages.
- Malicious app downloads prompting victims to sideload an Android APK that steals banking credentials and intercepts SMS OTPs.
Why Singapore Is a Prime Target
Singapore has one of the highest QR code adoption rates in the world. SGQR, PayNow, and merchant QR payments are integrated into almost every retail and F&B interaction. According to CSA and MAS advisories, scammers exploit this trust in three ways:
- Habit: Singaporeans scan QR codes without a second thought.
- Mobile-first behaviour: Most banking happens on a phone, where fake login pages look nearly identical to real ones.
- Trust in official-looking branding: Scammers reproduce SPF, LTA, IRAS, HDB, and bank logos with high accuracy.
Losses from phishing and malware-enabled scams in Singapore have crossed hundreds of millions of dollars in recent years, and QR codes are a growing contributor to that total.
Common QR Code Scams in Singapore
1. The Bubble Tea "Survey" Scam
One of the most publicised cases in Singapore involved an elderly woman who scanned a QR code sticker on the glass door of a bubble tea shop. The sticker offered a free cup of milk tea in exchange for completing a survey. The code led to a fake app download that gave scammers remote access to her phone. More than S$20,000 was drained from her bank account overnight.
2. Fake PayNow Stickers at Hawker Centres and Carparks
Scammers paste their own QR code sticker directly over a merchant's legitimate SGQR or PayNow code. Customers scan, pay, and the money goes to the scammer instead of the stall. Variations have appeared at coffee shops in Bedok, Toa Payoh, and Jurong, and on parking meters in private estates.
3. Fake Parking Fine or LTA Notice
A fake notice is placed on a windscreen or lamp post with a QR code to "pay the fine" or "appeal online". The code leads to a phishing site that collects Singpass or bank credentials.
4. Fake Food Delivery or E-Commerce Refund
Victims receive a WhatsApp or Telegram message with a QR code claiming to process a refund from Shopee, Lazada, foodpanda, or Grab. The code opens a fake payment gateway that captures card details.
5. Quishing Emails Targeting Workers
Employees receive an email that looks like it comes from HR, IT, or Microsoft 365, asking them to scan a QR code to "re-verify" their account. Because the QR opens on a personal phone, corporate security tools cannot inspect the link.
How to Spot a Malicious QR Code
Unlike a suspicious URL in an email, a QR code gives you almost no visual information. You need to inspect the preview URL and the destination page carefully. Here are the warning signs:
- The QR sticker looks freshly pasted over another sticker, or has peeling edges.
- The preview URL shown by your camera is a random shortener or an unfamiliar domain.
- The destination asks you to download an APK file (never do this on Android outside the Play Store).
- The page asks for your Singpass password, bank login, full card number, or OTP.
- The URL mimics a real brand but with a misspelling (e.g. dbss-sg.com, paynow-verify.net, singpass-login.app).
- You feel rushed — "limited time offer", "your account will be suspended", or "pay within 10 minutes".
10 Steps to Stay Safe from QR Code Scams in Singapore
1. Always Preview the URL Before Tapping
Both iOS and Android show a preview of the link when you scan a QR code with the native camera app. Read the full domain carefully. If it does not match the brand you expect, do not open it.
2. Inspect the Sticker Physically
At hawker stalls, coffee shops, and parking terminals, look for signs of tampering. If a QR sticker is pasted over another, peeling, or looks printed on cheap paper, alert the stall owner and pay by cash or card instead.
3. Never Download Apps from a QR Code
Legitimate Singapore banks, government agencies, and major F&B brands will never ask you to download an APK or sideload an app via a QR code. Only install apps from the official App Store or Google Play Store.
4. Turn On "Scam Shield" and App Restrictions
Singapore banks (DBS, OCBC, UOB, Standard Chartered, Citi) and the government's ScamShield app offer anti-malware features that block sideloaded apps during banking sessions. Enable these protections and keep your phone's OS updated.
5. Use a Separate Payment Method for Unknown Merchants
When paying at a stall you have never visited, use physical cash, a contactless card tap, or scan the merchant's QR directly from the official bank app (DBS PayLah!, OCBC Digital, UOB TMRW) rather than your phone camera. The bank app validates SGQR codes.
6. Verify Official Notices Independently
Received a parking fine, IRAS tax notice, or HDB letter with a QR code? Do not scan it. Instead, log in to the official portal yourself (mytax.iras.gov.sg, hdb.gov.sg, or the LTA OneMotoring site) and check for the notice there.
7. Treat Shortened Links with Extra Caution
Scammers often hide malicious destinations behind URL shorteners. Before clicking any shortened link from a QR code, expand it using a link preview tool. Reputable shorteners such as Lunyb provide safe, transparent redirects and let legitimate businesses use custom branded domains — which also helps you recognise authentic links. If you want to understand which shorteners are trustworthy, our 2026 buyer's guide to URL shorteners compares the leading options.
8. Never Enter Singpass or Banking Credentials on a Page Opened via QR
This is the single most important rule. No government agency or bank in Singapore will ever require you to log in via a QR code sent through SMS, WhatsApp, email, or a physical sticker. Always open Singpass or your banking app directly.
9. Report Suspicious Codes
If you suspect a QR code is fraudulent:
- Call the ScamShield Helpline at 1799.
- Report via the ScamShield app.
- Make a police report at police.gov.sg/iwitness.
- Alert the merchant or property management on-site so they can remove the fake sticker.
10. Educate Vulnerable Family Members
Elderly parents and young children are the most frequently targeted groups. Walk them through what a safe QR scan looks like, help them enable ScamShield, and set up transaction limits on their bank accounts. DBS, OCBC, and UOB all allow you to cap daily PayNow and online transfer limits — reduce these to a sensible level.
QR Code Scam Red Flags: Quick Reference Table
| Red Flag | What It Usually Means | What to Do |
|---|---|---|
| Sticker pasted over another QR code | Fake PayNow overlay scam | Pay by cash/card; alert stall owner |
| Preview URL uses an unknown or misspelled domain | Phishing site | Do not open; close camera app |
| Asked to download an APK file | Banking trojan / malware | Delete immediately; never install |
| Page asks for Singpass password or OTP | Credential harvesting | Close page; report to ScamShield 1799 |
| Urgent deadline or threat of fine | Social engineering pressure | Verify via official portal directly |
| QR code sent via WhatsApp from unknown number | Mass phishing campaign | Delete and block the sender |
What To Do If You've Already Scanned a Malicious QR Code
If you suspect you have fallen for a QR code scam, speed matters. Follow this checklist within the first hour:
- Disconnect your phone from the internet — enable Airplane Mode immediately to stop any installed malware from communicating.
- Call your bank's 24/7 fraud hotline to freeze your accounts (DBS: 1800 339 6963, OCBC: 1800 363 3333, UOB: 1800 222 2121).
- Freeze your Singpass at singpass.gov.sg or via the Singpass app's "Account Settings".
- Uninstall any app you were prompted to download, then do a full factory reset if you are unsure.
- Change all critical passwords — bank, email, Singpass, iCloud/Google — from a different, trusted device.
- File a police report and report through the ScamShield app.
- Enable Money Lock (available on DBS, OCBC, UOB and others) on a portion of your savings to prevent future digital transfers.
How Businesses in Singapore Can Protect Customers
If you run a hawker stall, café, retail shop, or carpark, you have a responsibility to protect your customers. A few simple measures:
- Laminate your SGQR / PayNow sticker and sign it with a marker across the laminate so tampering is visible.
- Check your QR code daily — a quick scan to confirm the merchant name is correct.
- Display your UEN or business name near the QR so customers can verify it matches the one shown in their bank app.
- Use branded short links from reputable providers rather than random shortened URLs on marketing materials. For an in-depth look at which link management platforms are trustworthy for business, see our honest review of Lunyb and our Rebrandly 2026 review.
- Train staff to recognise the signs of overlay stickers and to help confused customers who received a wrong-payment notification.
The Role of Authorities and Industry
Singapore has one of the most proactive anti-scam ecosystems in the world. The Anti-Scam Command (ASCom), ScamShield, the Shared Responsibility Framework (SRF) between banks and telcos, and the SGQR governance body are all working to reduce scam losses. However, individual vigilance remains the first line of defence. No framework can protect you if you willingly type your OTP into a fake page.
Expect continued rollout of features like:
- Mandatory in-app warnings before high-value transfers.
- Money Lock and "kill switch" features across all major banks.
- Delayed activation of newly added payees.
- Stronger SMS sender ID registration to block spoofed messages.
Frequently Asked Questions
Are QR code scams common in Singapore?
Yes. The Singapore Police Force and CSA have issued multiple advisories warning that QR code phishing (quishing) is one of the fastest-growing scam types. Cases involving fake payment stickers, fake surveys, and malicious APK downloads have resulted in individual losses ranging from a few hundred dollars to over S$100,000.
Is it safe to scan QR codes at hawker centres?
Generally yes, but always verify the merchant name that appears in your bank app before confirming payment. If the name does not match the stall, cancel the transaction immediately. For extra safety, scan directly through your bank's app (PayLah!, OCBC Digital, UOB TMRW) rather than your phone's camera, as the bank app validates SGQR codes.
What should I do if I accidentally downloaded an app from a QR code?
Immediately enable Airplane Mode, uninstall the app, call your bank's fraud hotline to freeze your accounts, change your passwords from a separate device, and perform a factory reset. Then file a police report and alert ScamShield at 1799.
Can iPhones get infected by malicious QR codes?
iPhones are harder to infect because iOS does not allow sideloading of apps outside the App Store (as of 2026, sideloading in Singapore is still restricted). However, iPhone users are still vulnerable to phishing pages that steal Singpass, bank, or card credentials. The rule remains: never enter sensitive credentials on a page opened from a QR code.
How do I verify a shortened link before clicking?
Use a link expander tool or paste the shortened URL into a preview service (many URL shorteners, including Lunyb, offer link previews). Legitimate businesses often use branded short domains so you can recognise them at a glance. If a shortened link appears on an unexpected QR code — especially one tied to banking, government, or payments — treat it as suspicious until proven otherwise.
Final Thoughts
QR codes are not going away — they are too useful. But in Singapore's hyper-digital payment landscape, a few seconds of caution before every scan can save you thousands of dollars and months of recovery. Preview every URL, never download apps from a QR, never enter Singpass or OTPs on a page opened via QR, and help the people around you (especially elderly family members) do the same.
Stay sharp, stay sceptical, and when in doubt — don't scan.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How Hackers Use Shortened URLs to Spread Malware (2026 Guide)
Shortened URLs are a favorite tool for cybercriminals delivering phishing kits, infostealers, and ransomware. Learn how these attacks work in 2026, which red flags to watch for, and how to safely preview, block, and respond to malicious short links.
Irish Data Breaches 2026: What You Need to Know
Irish data breaches are rising sharply in 2026, driven by ransomware, AI-powered phishing and supply-chain attacks. This guide covers the DPC's enforcement priorities, notable incidents, GDPR fines, and the practical steps Irish businesses and individuals should take right now to stay protected.
Is Public WiFi Safe? The Truth in 2026
Is public WiFi safe in 2026? Thanks to HTTPS, WPA3, and encrypted DNS, the biggest old threats are gone — but rogue hotspots, phishing portals, and shoulder surfing still demand caution. Here's the honest truth and 10 practical steps to stay secure.
How to Stay Safe on Public WiFi: The Complete 2026 Security Guide
Public WiFi networks are convenient but risky — attackers can intercept data, spoof hotspots, and hijack sessions. This complete 2026 guide walks you through practical steps, device hardening, and smart habits to stay safe on any open network.