The Difference Between Misinformation, Disinformation and Malinformation
Intent Is the Only Thing That Separates Them
Misinformation, disinformation, and malinformation are not three degrees of the same mistake. They do not differ only in how false they are. The actual differentiator is the creator's intent, and you cannot reliably see intent from the message itself. That is why the exact phrase misinformation vs disinformation vs malinformation definitions matters: the definitions hinge entirely on what the person who made the content was trying to do, not on what the content looks like. Misinformation is false information shared without intent to deceive. Disinformation is false information deliberately created and shared to cause harm. Malinformation is genuine information shared with intent to cause harm, often by moving private information into the public sphere. A reader can see the message. The creator's mind is the one thing the message does not carry.
Intent Difference: Misinformation
Start with the least malicious case, which is also the most common in Singapore group chats. Misinformation is the photo of a hawker stall closing down that your aunt forwards to the family chat, believing it is true. The stall really did close, but the photo is from three years ago and the stall has since reopened. She is not trying to deceive anyone. She read it, believed it, and shared it. The forwarding is the act that spreads it. The intent is the absence of intent to deceive. WhatsApp marks these with the forwarded-as-received label, a structural feature built into the platform precisely because it cannot read your aunt's intent. That label signals to you that the person who sent it is not necessarily the person who originated the claim.
Types of False Information: The First and Most Common Kind
Emotional Override and Correction Blindness
The failure case for misinformation is not malice. It is emotional override. A reader shares a claim because it provokes anger, fear, or hope, and that emotional response short-circuits the verification step entirely. The consequence is that a false claim spreads precisely because it feels true. The correction is the hard part. Correction blindness sets in when the fact-check arrives after the emotional investment; the reader dismisses it because it comes from a source they distrust. Or the correction arrives too late and lands in a thread nobody reads. A fast correction nobody sees has limited real-world effect.
Who Fixes This in Singapore
Factually, the government fact-checking portal, publishes clarifications on false claims circulating locally. Black Dot Research, the independent Singapore-based fact-checking and media literacy organisation, is the International Fact-Checking Network signatory in Singapore.
- Misinformation: False information shared without intent to deceive
- Disinformation: False information deliberately created and shared to cause harm
- Malinformation: Genuine information shared with intent to cause harm, such as doxxing or revenge porn
- Definitions source: First Draft News (2017)
- Singapore scam cases 2024: 46,563 cases
- Singapore scam total losses 2024: SGD 651.8 million
- Scam statistics source: Singapore Police Force Annual Scams and Cybercrime Brief 2024
Disinformation Campaign Singapore: Designed Deception
When the intent hardens into a plan, you have disinformation. This is the deliberate creation and sharing of false information with the specific goal of harming a person, an organisation, or a public process. A disinformation campaign in Singapore is not a mistake that got out of hand. It is a designed operation. The difference from misinformation is the intent to deceive, which is the entire point. A common local form is the impersonation scam: the perpetrator poses as a government official, a bank officer, or a family member in urgent distress. These are not accidents. The false claim is built to extract money or data, and the construction is deliberate. The Singapore Police Force Anti-Scam Command publishes the scam typology framework covering job scams, phishing scams, e-commerce scams, investment scams, impersonation scams, and love scams. Those are the categories of deliberate deception.
POFMA and the Definition of Falsehood
The Protection from Online Falsehoods and Manipulation Act, the POFMA Act 2019, commenced on 2 October 2019. POFMA does not care whether the false statement of fact was shared with or without intent to deceive. It addresses false statements of fact regardless of intent, which makes it broader than the academic definitions. The POFMA Office sits within the Ministry of Digital Development and Information. The Act gives the government the power to issue correction directions and, in some cases, takedown directions. It provides an appeal mechanism to the High Court for any person subject to a direction. POFMA is a legal mechanism that can compel correction or removal. Fact-checking is a voluntary act of verification. That distinction, legal compulsion versus editorial practice, is why POFMA exists and why it gets used on a scale that fact-checking alone cannot reach.
Singapore Malinformation Example: Genuine Data, Malicious Use
Doxxing and the Law
Malinformation breaks the pattern because the information itself is true. The harm comes from the sharing. Malinformation is genuine information shared with intent to cause harm, and the clearest example is doxxing: publishing someone's home address, phone number, or place of work without their consent, not to inform the public but to expose them to harassment. The Protection from Harassment Act 2014, known as POHA, covers this in Section 3: publishing personal information with intent to cause harassment, alarm, or distress. The information is real. That is what makes it malinformation. The victim's address is a true fact. The intent to harm is what makes it an offence.
How Data Gets Out
The Personal Data Protection Commission, the PDPC, administers the Personal Data Protection Act 2012. That Act imposes nine core obligations: consent, purpose limitation, notification, access and correction, protection, retention limitation, transfer limitation, and accountability. Those obligations apply to the organisations that hold the data before it ever gets leaked.
How the Intent Difference Changes Your Response
The practical problem is that intent is often unknowable by the recipient. You receive a forwarded message containing a fabricated screenshot, a claimed endorsement, or a personal testimony that never happened. Is the sender spreading misinformation or disinformation? You cannot always tell. Separate the question of guilt from the question of action. The intent difference matters not because it changes the message but because it changes your next move. A misinformed relative needs a correction delivered with the relationship intact. A disinformation campaign needs to be reported and left alone. If the content is a false statement of fact in Singapore, report it to the POFMA Office or flag it to Factually. If it is a scam, the Singapore Police Force wants the report. Use the ScamShield app built by the National Crime Prevention Council and the Singapore Police Force.
Satire, Deepfake and Cheapfake: Method Is Not Intent
Satire is the edge case that proves the rule. Satire is content created with artistic or comedic intent that an audience is expected to recognise as exaggeration. It is not false information because the intent is not to deceive; it is to amuse or to criticise. But satire becomes a cheapfake when the satirical framing is stripped away and the image or quote is presented as real. A cheapfake is a low-tech manipulation: an image cropped, a quote reordered, a video slowed down. A deepfake is AI-generated synthetic media. The distinction is the method of fabrication, not the intent. You can have a deepfake made as satire and a cheapfake made to defraud. The Parliamentary Elections (Amendment) Act 2024 prohibits publication of digitally manipulated content depicting a candidate saying or doing something they did not, from 15 October 2024. That is a legal line drawn around the method, not the intent.
Why Intent Matters for the Reader
The Traps Are the Same
The emotional traps are the same across all three categories. Source confusion makes you believe a claim because the person who forwarded it is trusted, without checking whether that person is the original source. Emotional override makes you share a claim because it provokes anger, fear, or hope, short-circuiting the verification step.
The Claimed-Versus-Real Gap
A message may claim verification by the Singapore Police Force or the Ministry of Health, and no such endorsement exists. A post may claim millions of views, and the real human reach is a fraction of that. The claimed first-hand witness in a forwarded message does not exist; the personal testimony is fabricated or aggregated from multiple unknown sources. These are not rare failures. They are the standard operating procedure of a disinformation operation. Your defence is the Understand, Research, Evaluate framework from the National Library Board, embedded in Singapore's school curriculum and public libraries. It does not depend on any specific technology, and it will still work when the next platform appears.
What to Do Instead of Sharing
Three Moves, in Order
First, determine whether the content is false. Check the Factually portal or Black Dot Research before you share. Black Dot Research launched in 2019 and is the independent fact-checking and media literacy organisation in Singapore. Second, determine whether the content is harmful in a legal sense. If it is a false statement of fact in Singapore, POFMA applies regardless of intent and the POFMA Office takes the report. If it is true but private and shared to harm, the Protection from Harassment Act applies. If it involves your personal data being misused, the PDPC is the enforcement body. Third, determine whether the content is a scam. The Singapore Police Force recorded 46,563 scam cases in 2024 with SGD 651.8 million in total losses. That figure is revised annually by the Police Force's Annual Scams and Cybercrime Brief. Do not rely on a figure you saw six months ago; the scam typologies change and the template messages change daily.
The Verification Route Is Still Open
The deeper problem is that the intent distinction, while essential for definitions, is nearly useless as a real-time filter. You cannot read the creator's mind. What you can do is stop the content at the forwarding stage. The forwarded-as-received label on WhatsApp is a warning flag. A legitimate message from your bank does not arrive as a forwarded-as-received. A government agency does not send you an unsolicited message asking you to click. If it is urgent, it will still be urgent in ten minutes, which is how long a reverse image search takes. Uploading a suspicious image to a public search site may reveal the user's identity or location, so think before you upload. The tool may change: Google Images, TinEye, Yandex. The principle of checking whether an image has appeared before in a different context is durable. The same goes for the source: check the original source of the forwarded message, not the friend who sent it.
At 1am, Do Nothing
It is 1am. You are alone, and you have received a message that looks like a bank alert. The Singapore Police Force Anti-Scam Command is not a chatbot you can ping at 1am. The ScamShield app is, and it is free. The response that works at 1am is the one that costs you nothing: do not act. Call the bank directly using the number on the back of your card, not the number in the message. The bank does not penalise you for calling at 1am. The impersonation scam depends on urgency, and urgency is the signal that the message is a scam. The scam message wants you to act before you think. Introduce a delay. Ten minutes of checking is the difference between losing nothing and losing your savings. If the message claims to be from a government agency, hang up and call the agency directly. The POFMA Office does not call you to tell you that you have a correction order.
The One Habit That Beats Every Tool
Build a habit of checking before you share. Not checking everything. That is a full-time job. But the first time you feel the emotional pull, the anger, the fear, the hope that makes you want to forward it to everyone, that is the moment to stop. Do not share. Open a new tab. Type the claim into a search. If it is a falsehood, the Factually portal or Black Dot Research will have it. If it is a scam, the Singapore Police Force will have a warning. If it is none of those, check whether the source is the person who originally wrote it or the friend who forwarded it. Source confusion is the entry point for everything else. The reason the intent distinction matters is not so you can accuse the sender of malice. It is so you can choose a response that matches the actual harm. A misinformed relative needs your patience. A disinformation campaign needs your silence and a report. Malinformation needs the police, because doxxing is a crime under the Protection from Harassment Act.
Claimed and Real Verification
There is a final trap that catches careful readers: the appeal to authority that is not an authority at all. A message that claims the Singapore Police Force has verified it is a lie, unless the Police Force has actually published it. The Police Force publishes its scam typologies and statistics in the Annual Scams and Cybercrime Brief. It does not circulate WhatsApp messages. A claim that cites the Personal Data Protection Commission should be checked against the PDPC's actual enforcement decisions, which are published. The gap between claimed verification and real verification is the gap that disinformation lives in. The claimed endorsement does not exist. The actual endorsement is a matter of public record, and it is your right to verify it. If a source will not survive a five-minute check, it is not a source. It is a lead.
Platform Rules Versus the Law
The distinction between content moderation and legal action is the last thing to hold. Platforms like WhatsApp, Telegram, and TikTok remove content under their own terms of service. That is a private agreement between the platform and its users. It is not a legal process. A platform can leave a falsehood up because it does not violate the platform's rules, and it can take down something that is true because it violates the rules against harassment. The platform is not a court. In Singapore, the legal process goes through the Singapore Police Force, the POFMA Office, or the PDPC. When you report to a platform, you are asking a private company to enforce its rules. When you report to the Police, you are initiating a legal process under Singapore law. The Singapore Online Criminal Harms Act, which commenced on 1 February 2024, adds further powers. The reader who understands this distinction is much harder to manipulate, because they stop expecting the platform to do the job of the law.
What It Costs
You do not need a new app, a subscription, or a course. You need the reflex. The next time you are about to share something that made you feel something, you have two options. One is to share it, and to be the person who spreads misinformation, or worse, the person who gets used as a vector for disinformation. The other is to take ninety seconds. Open a new tab. Put the claim in the search. If the first result is a fact-check, you have your answer. If the first result is the original claim repeated, click the link that looks like it is from a government or an established newsroom. If the claim is about a scam, add the word Singapore Police Force to your search. The search will cost you ninety seconds. The share will cost you your credibility, your relationship with the person you forwarded it to, and potentially your money. The Singapore Police Force's own numbers for 2024, 46,563 cases and SGD 651.8 million in losses, are the cost of the ninety seconds skipped.
What to Do When You See It
When you have decided the content is false, your next move is not a debate. Do not argue with the sender. Do not post a correction in the group chat and wait for applause. The correction will be ignored by everyone who already shared it, because correction blindness is real. Instead, do three things. First, do not share it and do not act on it. Second, report it to the platform using the report function, which flags it under the platform's terms of service. Third, if it is a false statement of fact in Singapore, report it to the POFMA Office. If it is a scam, report it to the Singapore Police Force. If the content is malinformation, genuine private information shared to harm, report to the Police under the Protection from Harassment Act. Do not forward it, not even to ask if it is true. Forwarding it once more spreads the harm. The person it hurts is not hypothetical. The person it hurts is the victim, and you will have chosen to participate.
Handling the Family Forward
The habit of checking before sharing applies to the family group chat as well as the public feed. The mother who forwards a warning about a new scam is not a villain. She is a misinformed person who wants to protect you. The correct response is not to scold her. Send her the Factually link that debunks the claim, and do it kindly. The moment you make her feel stupid is the moment she stops coming to you with anything. The disinformation operator knows this. That is why the forwarded messages are written to trigger alarm: alarm overrides judgement. The message that begins with a personal testimony, "my friend's cousin works at the bank and she told me", is the classic fabrication. The claimed first-hand witness does not exist. The message is designed to be forwarded as received, because the label is the cover. When you see the label, you know the origin is unknown. When the origin is unknown, the only unknown is the harm the content was built to do.
A Note on Scope
This is not legal advice, and it is not a substitute for the Protection from Online Falsehoods and Manipulation Act. The Act is long. It was amended on 1 October 2025, and the definitions in Section 2(1) are precise. If you are a content creator, a platform operator, or a person who has been served a correction order, read the Act itself and consider the appeal mechanism to the High Court. What you get here is the framework for daily life: the intent difference between misinformation, disinformation, and malinformation, the Singapore context for each, and the habit that protects you. The definitions come from First Draft News in 2017, and they remain the clearest statement of the distinction. The Singapore examples come from the public record: POFMA directions, Police Force statistics, PDPC decisions. None of it is secret. None of it requires special access. It is all available to the reader who cares to look, and the looking is the point.
How to Tell the Difference
The honest answer is that you cannot always tell, and anyone who says otherwise is selling something. You cannot read the creator's intent from the message any more than you can read the chef's mood from the dish. What you can do is sort the message by the one thing you can observe: whether the claim is false, true-but-private, or a scam. If it is false, you have a misinformation or disinformation case, and POFMA applies either way. If it is true but private, you have a malinformation case, and POHA applies. If it is a scam, the Singapore Police Force wants it. The intent distinction is not a sorting tool. It is a calibration tool. It tells you how angry to be, not what to do. Your response to a misinformed relative should be gentle. Your response to a disinformation campaign should be a report. Your response to malinformation should be a police report. Same message, different intent, different response. The intent is the thing you will never know for certain.
The Final Instruction
The next time you see a message that makes you feel something, do not share it. Do not reply to it. Do not even open the thread. Put the phone down. Walk away for the amount of time it takes to make a cup of tea. Then come back and check the facts. That is the whole method. It is not glamorous. It will not make you the most popular person in the group chat. But it is the step that breaks the chain. The misinformation stops with you because you checked. The disinformation campaign fails because you did not amplify it. The malinformation does not travel because you did not forward it. The Singapore Police Force reported 46,563 scam cases in 2024 and SGD 651.8 million in losses. Every one of those numbers started with a message that felt urgent. The urgency is the scam. The tea break is the defence. Take the tea break.
- POFMA full name: Protection from Online Falsehoods and Manipulation Act 2019
- POFMA commencement: 2019-10-02
- POFMA amendment: 2025-10-01, check the official text for current provisions
- POFMA administering body: POFMA Office, Ministry of Digital Development and Information
- PDPA full name: Personal Data Protection Act 2012
- PDPC role: Administers the PDPA, publishes enforcement decisions on data breaches
- Factually launch: 2012-05-18
- Black Dot Research launch: 2019, independent IFCN signatory
- ScamShield operating body: National Crime Prevention Council and Singapore Police Force
- Singapore scams 2024: 46,563 cases, SGD 651.8 million losses