Common Scam Types Active in Singapore: Job, Phishing, E-Commerce, Investment, and Impersonation
Common Scams in Singapore Right Now: What to Actually Watch For
If a text lands on your phone right now claiming your Singpass will be deactivated, do not click the link. Open the Singpass app instead. If nothing is wrong there, the text is a scam. Delete it. The Singapore Police Force Anti-Scam Command recorded 8,474 e-commerce cases in the first half of 2025, then phishing at 5,543 and job scams at 5,258. Every one of them works the same way: an emotional hook, a fabricated sense of urgency or opportunity, and a request that bypasses your normal caution. You are not reading this for general interest. You are reading it so that when a notification lands on your phone, you recognise the pattern and do not act.
Singapore Scam Typology 2025: The Police Framework
The police organise their reporting around a fixed set of scam types, and that framework is the one this guide follows. The categories are job scams, phishing scams, e-commerce scams, investment scams, impersonation scams, and love scams. Phishing is the delivery method for many impersonation scams, and fake friend call scams use the same emotional manipulation as love scams, but the police classification determines where the case is filed and how the Anti-Scam Command, established in 2019, coordinates its disruption. The framework itself is stable. What changes is the specific script.
The Anti-Scam Centre Impersonation Twist
Government-official impersonation scams in 2025 have a variant where scammers pose as Anti-Scam Centre officers. It is a cruel inversion because it uses the victim's awareness of scams against them. The mechanism is a spoofed call or SMS that creates an officialdom halo. The red flag is a request for payment, credentials, or a verification code delivered under a false pretence.
Job Scam Singapore Red Flags: The Fake Hiring Script
The police recorded 5,258 job scam cases in the first half of 2025. The mechanism is a fake job offer, delivered via WhatsApp or Telegram, promising high pay for simple tasks such as liking videos, writing reviews, or boosting online content. The variant surging in 2025 is the advance-fee version: you complete the task, see your balance grow in the app, and then are told you must deposit your own money to release the earnings.
The Move to WhatsApp Is the Tell
The red flag is the instruction to move the conversation to WhatsApp or Telegram after a platform like LinkedIn or Facebook rejects the initial contact. A legitimate recruiter uses a company email domain and does not interview via chat. The failure case is when the job posting is so perfect it survives your initial scepticism. The structural feature: the interviewer never asks for more than basic details and uses a personal number. If you are asked to pay anything, for processing, tax, or release, you are the target. Report it to the police and walk away. The job was never real.
Phishing Scam SMS: The Spoofed Sender ID
The most common phishing variant in 2025 is an SMS claiming your Singpass account will be deactivated unless you click a link to verify your identity. The link leads to a fraudulent Singpass login page that harvests your credentials and your one-time password. The mechanism relies on the SMS Sender ID Registry, which was introduced to allow registered senders like banks and government agencies to use alphanumeric IDs such as Singpass or DBS. Scammers spoof these IDs, making the notification appear at the top of your legitimate SMS thread.
Check the URL Before You Tap
The red flag is the URL. A real Singpass login page is at singpass.gov.sg, not a misspelled variant or a shorttened link. The failure case is when the text claims your account has been compromised and you must act within minutes. That urgency is the emotional override that short-circuits your verification. If you receive a text with a link, do not click. Call the number listed on the app, or open the Singpass app directly and log in. If nothing is wrong, you have your answer.
Phishing Scam SMS: The SingPost and Bank Variants
Beyond Singpass, the fake delivery notification is the most persistent phishing variant. The SingPost scam SMS in 2025 uses a fake customs duty payment request, with a link to a fraudulent SingPost website that asks for your credit card details. The DBS phishing method in 2025 is a fake SMS claiming unauthorised transactions, with a link to a fake DBS login page. The OCBC phishing SMS surge in December 2021, which cost victims SGD 13.7 million across 790 cases, is the original template. The pattern of a spoofed sender ID and a link to a fake login page has not changed.
Private Numbers Are the New Red Flag
The red flag is the sender ID itself. While some scammers spoof SingPost or DBS, the registry makes it harder for them to do so. You will increasingly see texts from private numbers. If you receive a text from a private number claiming to be a bank, that is the scam. The failure case is when you are expecting a delivery, so the SingPost link does not trigger your suspicion. Never click a link in a text about a delivery or a transaction. Go to the website, track your parcel, or call the bank's hotline. The few extra minutes of effort are the entire game.
Phishing Scam SMS: The Spoofed Sender ID
The most common phishing variant in 2025 is an SMS claiming your Singpass account will be deactivated unless you click a link to verify your identity. The link leads to a fraudulent Singpass login page that harvests your credentials and your one-time password. The mechanism relies on the SMS Sender ID Registry, which was introduced to allow registered senders like banks and government agencies to use alphanumeric IDs such as Singpass or DBS. Scammers spoof these IDs, making the notification appear at the top of your legitimate SMS thread.
Check the URL Before You Tap
The red flag is the URL. A real Singpass login page is at singpass.gov.sg, not a misspelled variant or a shorttened link. The failure case is when the text claims your account has been compromised and you must act within minutes. That urgency is the emotional override that short-circuits your verification. If you receive a text with a link, do not click. Call the number listed on the app, or open the Singpass app directly and log in. If nothing is wrong, you have your answer.
Phishing Scam SMS: The SingPost and Bank Variants
Beyond Singpass, the fake delivery notification is the most persistent phishing variant. The SingPost scam SMS in 2025 uses a fake customs duty payment request, with a link to a fraudulent SingPost website that asks for your credit card details. The DBS phishing method in 2025 is a fake SMS claiming unauthorised transactions, with a link to a fake DBS login page. The OCBC phishing SMS surge in December 2021, which cost victims SGD 13.7 million across 790 cases, is the original template. The pattern of a spoofed sender ID and a link to a fake login page has not changed.
Private Numbers Are the New Red Flag
The red flag is the sender ID itself. While some scammers spoof SingPost or DBS, the registry makes it harder for them to do so. You will increasingly see texts from private numbers. If you receive a text from a private number claiming to be a bank, that is the scam. The failure case is when you are expecting a delivery, so the SingPost link does not trigger your suspicion. Never click a link in a text about a delivery or a transaction. Go to the website, track your parcel, or call the bank's hotline. The few extra minutes of effort are the entire game.
E-Commerce Scam Carousell Singapore: The Fake Buyer and the Fake Payment
The e-commerce scam on Carousell is so common that the platform built an entire Carousell Protection feature specifically to counter it. The scam works in two ways. The first is the fake buyer: you list an item, receive a note from a buyer who says they have paid, and then you get a phishing email that appears to be from Carousell, asking you to click a link to release the funds. The link leads to a fake Carousell login page, and you have just handed over your credentials. The second variant is the fake buyer sending a phishing link to the seller claiming payment was made, followed by a fake Carousell Protection payment page that harvests your bank credentials.
Stay Inside the App
The red flag is that Carousell does not send payment links. Transactions are completed within the app's own protected checkout. If you are asked to verify your account or receive payment via an external link, it is a scam. The failure case is when the buyer seems genuinely enthusiastic and does not lowball you, which is rare on the platform. Complete all communication and payment within the Carousell app. If a buyer insists on WhatsApp, report and block. The same applies to Facebook Marketplace and Telegram, which are also common platforms for e-commerce scams in 2025. If a text contains a link, it is a phishing attempt.
E-Commerce Scam Carousell Singapore: The Delivery and Payment Bypass
On Telegram and Facebook, the e-commerce scam takes a different shape: the fake delivery company. You sell an item, and the buyer says they have arranged for a courier to pick it up. Minutes later, you receive a note from a courier, usually SingPost or a generic logistics firm, with a link to schedule a pickup or pay a small insurance fee. The link leads to a fake delivery company page requesting your credit card details. This is a direct phishing attack.
You Do Not Pay for the Buyer's Courier
The red flag is that no courier service works this way. You, the seller, do not pay for the buyer's delivery. The failure case is when you are relieved to have made a sale and let your guard down. The structural feature is the same as every other phishing attack: an urgent request for payment or credentials via a link. If you are selling on any platform, ignore any note that is not a direct negotiation about price or pickup time. Genuine buyers do not send links. They ask questions. If a text contains a URL, assume it is a fake delivery company link and stop responding.
Investment Scams: The Guaranteed Return That Is Not
Investment scams are the single most damaging category in Singapore by dollar value. The 2025 mid-year stats show 2,430 cases, but the financial losses of SGD 144.6 million dwarf every other scam type. The mechanism is the too-good-to-be-true heuristic: a cold call, WhatsApp note, or Telegram group promising guaranted returns on crypto, foreign exchange, or high-yield bonds. The current variant in 2025 is the crypto recovery scam, where a victim who has already lost money once is approached by a specialist who says they can recover the lost funds for an upfront fee.
No One Guarantees Returns
The red flag is the phrase guaranted returns. Nothing is guaranted in investing. No legitimate financial adviser will promise them. The platforms used are WhatsApp and Telegram, which are encrypted and allow scammers to create a false sense of community with fake screenshots of profits. The failure case is when the victim is so convinced by the success of their first few small withdrawals that they invest a larger sum. If you are approached out of the blue with an investment opportunity, it is a scam. If you are on a platform and a stranger slides into your DMs with a stock tip, it is a scam. The only legitimate investment advice is professional advice. Everything else is a fraud.
Impersonation Scams: The Government Official and the Bank Officer
Impersonation scams involve a scammer pretending to be someone in authority: a police officer, a bank employee, or a government official. The 2025 variant that the police specifically warn about is the government-official impersonation scam where scammers pose as Anti-Scam Centre officers. The mechanism is a call from a spoofed number that appears to be a legitimate government line. The scammer claims there is a case against you, and that you must verify your identity by providing your bank details or transferring money to a safe account.
Hang Up and Call the Real Number
The red flag is the request itself. No government or police officer will ever ask you to transfer money to a safe account or read out your bank credentials over the phone. Impersonation scam cases in 2025 stand at 2,814, and the payment method is almost always PayNow or a bank transfer, which is instant and irreversible. The failure case is when the scammer reads back details about you that they have harvested from a data breach, making the call seem real. If you receive an unsolicited call from a government or police official, hang up immediately. Do not call the number back. Look up the number yourself and call it. The Anti-Scam Command, established in 2019, can freeze accounts within hours of a report, but only if you act immediately. Every minute you spend on the phone with the scammer is a minute the money is moving.
Love Scams: The Long Game of Emotional Override
Love scams are the most emotionally devastating category, and the police track them separately from the other impersonation types because the mechanism is different. The scammer does not impersonate an official. They impersonate a romantic partner. The approach is a random note on a dating app, a quick move to WhatsApp or Telegram, and then a slow build of trust over weeks or months. The love is intense, and then the emergency arrives: a medical bill, a business deal, a customs fee to release a gift.
Never Send Money to Someone You Have Not Met
The red flag is the refusal to video call or meet in person, and the request for money for a person you have never met. The platforms used are WhatsApp and Telegram, which are encrypted and allow the scammer to create a false sense of intimacy. The failure case is when you have been chatting for months and you feel you know the person, so you ignore the warning signs. Never send money to someone you have not met in person. The emotional override is the entire game, and it is designed to short-circuit your logic. Report the profile to the platform, report it to the police, and do not respond to further notes. Love is not a wire transfer.
Fake Friend Call Scams: The WhatsApp Takeover
One of the fastest-growing variants in 2025 is the fake friend call scam, which hijacks the WhatsApp or Telegram account of someone you know. The mechanism is the WhatsApp account takeoever scam: the scammer requests your verification code under a false pretence, for example by posing as a friend whose account is locked and needs confirmation. Once they have the code, they take over your account and message all your contacts with a sob story: I lost my phone, I need you to pay my bill or you will not see me for a month.
Call the Person on Their Saved Number
The red flag is the urgent request for money from a friend or family member via a messaging app. The failure case is when the note comes from someone you know by name, and the story is plausible enough that you send a PayNow before you check. If you receive a request for money, call the person on a number you have saved, not the number in the text. Do not reply to the note itself. The same applies to the Telegram account takeoever scam, which uses a phishing link claiming account violation and a fake Telegram login page that harvests credentials. The red flag is the forwarded as received label on the note, which indicates the sender has had their account hijacked. These notes are sent to many people at once, in an attempt to catch one person who will not verify.
How to Report and What Happens Next
If you have been scammed, the first step is to contact your bank immediately. The Anti-Scam Command works with banks, fintech companies, and telecommunication providers to freeze accounts, and their intervention method of real-time fund flow analysis means they can sometimes stop the transfer if you act within hours. The bank transfer is the most common payment method for scams in 2025, and PayNow is used in e-commerce and impersonation scams, so the window for recovery is measured in hours, not days. After you have called your bank, report to the police Anti-Scam Command. You can do this via the ScamShield app, which also serves as a proactive tool: it checks incoming calls and SMS against a list maintained by the police and blocks them. ScamShield is a Singapore app and hotline that blocks scam calls and SMS and allows user reporting, and the ScamShield bot allows you to submit screenshots for verification. The ScamShield Alert WhatsApp channel is a police advisory channel that publishes the latest scams, and the Weekly Scams Bulletin is distributed via police social media channels. The police also have a dedicated hotline. Call them directly. The failure case is when you are too embarrassed to report. Do not be. The police explicitly state that no victim is blamed, and the report is what allows them to track the scam and potentially recover funds.
Tools and Resources: What Works and What Does Not
The ScamShield app is your primary defence, but you need to know its limits. The app checks calls and SMS against a database of known scam numbers, which means it has a high true positive rate for numbers that have already been reported. However, it is only as good as its update frequency. The specific URLs and sender IDs used in active campaigns change daily, so a new scam might slip through. The tool accuracy is high for known scams, but it is not a defence against a well-crafted spear-phishing email that has not yet been reported. The language coverage of ScamShield is in English, which is fine for most readers, but if you are more comfortable in another of Singapore's languages, check the police website for advisories in Malay, Mandarin, and Tamil. The user burden of verifying a note is low: you can forward a suspicious SMS to the reporting service that sends it to the police. The privacy preservation is a consideration: when you report a number, you are sharing the sender's details, not your own. Do not upload your screenshots to a public website to ask if it is a scam. That exposes your own number to more scammers. Instead, use the ScamShield bot or the police channels.
The Structural Features That Never Change
The specific scam scripts change every month, but the structural features are constant. The first is the too-good-to-be-true heuristic: if an offer seems too good to be true, it is. The second is the officialdom halo: scammers use government logos, .gov.sg-like URLs, and official-sounding language to borrow credibility. The third is the emotional override: the note triggers fear, greed, or hope, and that emotion short-circuits your verification. The fourth is the verification bypass: you are rushed into an action, clicking a link, transferring money, before you have time to check. The defence is lateral reading: when you receive a note, open a new tab and search for the sender's name plus scam. Check the source. Is it a .gov.sg domain? The Cyber Security Agency of Singapore publishes scam advisories; so does the police. The ScamShield website at scamshield.gov.sg is the resource. If you receive a note that asks you to verify your Singpass, remember that Singpass will never ask you to click a link in an SMS. The fake WhatsApp login page is designed to harvest your credentials, so always type the URL directly into your browser rather than clicking a link. The reverse image search is a powerful verification technique: if you receive a photo from a friend or love interest, and the image appears elsewhere on the internet in a different context, it is a scam. The algorithm that surfaces your content does not care about accuracy. It optimises for engagement.
The single most important habit is to slow down. The ScamShield app is a useful filter, but it is not a substitute for your own judgement. The National Crime Prevention Council's I Can ACT Against Scams campaign breaks it into three steps: Acknowledge the threat, Check the facts, and Tell someone. The Check step is where you do the lateral reading and reverse image search. The Tell step is where you break the isolation that the scammer has created. The fake friend call scam was designed to bypass your suspicion by coming from a trusted contact. The reverse is true: your trusted contact is the one person you should verify with. If you have a question, call them on a number you have saved. If you are on WhatsApp and someone claims to be your child with a new number, call the old number. The verification bypass is a feature of the scam, not a bug. The failure case is when you are alone, it is 2am, and the note seems urgent. No legitimate emergency requires you to act on a link you received in a text. The police and the banks will never ask you to transfer money to a safe account. The government will never ask you to pay a fine via PayNow. If you are in doubt, hang up, close the app, and call the hotline.
The platforms used for scams in 2025 are dictated by the scammer's need for reach and anonymity. WhatsApp and Telegram are the primary channels for job, investment, and fake friend call scams because they offer easy group creation and end-to-end encryption. Facebook and Carousell are the primary channels for e-commerce scams because they have a large audience of people looking to buy or sell. The SingPost phishing SMS variant uses the same fake delivery link approach as the fake delivery company link on Carousell. The Singpass phishing method in 2025 is the fake deactivation warning, which relies on the officialdom halo of a government service. The ScamShield bot function allows users to submit screenshots or descriptions for scam verification, which is a useful second opinion if you are not sure. The Weekly Scams Bulletin is published on the ScamShield website and the police social media channels, including @singaporepoliceforce on Facebook, @singaporepoliceforce on Instagram, and @sppf_sg on TikTok. The Anti-Scam Command also runs Project Frontier, which launched in 2023 and is a collaboration with banks to warn customers when they are about to transfer money to a known fraudster. The intervention method is an immediate pop-up warning, which gives you a moment to pause.
The Failure Case: When It Happens to You
Despite all the warnings, you may still get caught. The scammer has a playbook; you need one too. The first thing to do is not to panic. Call your bank immediately and request a kill switch on your account. The Anti-Scam Command can freeze accounts within hours of a victim report, but only if the bank is alerted first. The second step is to report to the police via the ScamShield app or the hotline. The police will give you a case number, which you need for your insurance claim, if any. The third step is to update the friends and family who may have received a note from you if your account was taken over. The WhatsApp account takeoever scam means the scammer has access to your contacts. Warn them not to click any links you sent. The fourth step is to review your privacy settings and enable two-factor authentication on all your accounts. The final step is to report the scam to ScamShield, which helps the police track the campaign and warn others. The forwarded as received label on WhatsApp is a structural feature that should trigger your suspicion, not your dismissal. The MLC is a Singapore charity running public education campaigns, but it does not take reports. The Singapore Police Force and the Personal Data Protection Commission are the authorities.
This guide explains how to verify information and understand Singapore's online content laws. It does not campaign for or against any legislation. If you believe you have encountered a scam, contact the police directly. If you believe a scam website is hosting your personal data, contact the Personal Data Protection Commission. The police can act on the scam; the PDPC can act on the data breach. The tool accuracy of any verification method depends on the source. A reverse image search will find where an image has appeared before, but it will not tell you if the image is real. An AI detection tool might give a false positive rate that terrifies you into a wrong conclusion. The only reliable method is to combine lateral reading with a check of the sender's identity. The verification bypass is what you are avoiding. The most dangerous moment is not when you click the link, but the twenty seconds after you read the note and before you have decided to call your friend. That is the moment the emotional override works. That is the moment to breathe.