Cybersecurity Basics: Passwords, Two-Factor Authentication and Passkeys for Everyday Singapore Users
How passwords, 2FA, and passkeys differ in security, why SMS 2FA is vulnerable to SIM swap scams in Singapore, and the steps to take after an account takeover.
Change your Singpass password now. Then revoke every session you do not recognise. Someone may be inside your account right now, and the first job is to lock them out. Do this whether the compromised account is your bank, your email, or Singpass itself. Report the breach to the platform and to the Singapore Police Force Anti-Scam Command. After the immediate threat is contained, the longer game begins. The way you authenticate online in Singapore is shifting fast. The SMS code you have relied on for years is now a liability. Here is a plain-language run-through of passwords, two-factor authentication, and passkeys that Singapore residents actually need, and it will show you exactly why.
Credential Stuffing and Phishing
Attackers do not guess your credentials by hand. They take lists of usernames and passcodes leaked in data breaches and automate them across dozens of sites. Most people reuse credentials, and the attackers bank on that. Your email and passcode for a low-security forum from 2018 is being tried against your bank right now. Phishing is the other half. A spoofed SMS claiming to be from DBS or the police sends you to a fake Singpass login page. You hand over the one credential that matters. The Personal Data Protection Commission has published enforcement decisions on data breaches where organisations failed to make reasonable security arrangements under the PDPA. Those decisions show the same pattern every time: credentials get exposed, and the damage spreads because one key opens many doors.
Strong Passphrases Beat Complexity
The old advice to mix upper case, lower case, numbers, and symbols is dead. The National Institute of Standards and Technology now recommends against required character-type mixing, and the Cybersecurity Agency of Singapore follows suit. A passphrase of four or more random words is the strong credential-creation method Singapore authorities now advise. 'Correct horse battery staple' is a passphrase. 'P@ssw0rd2024' is a guessable pattern. The reason is entropy. A four-word random passphrase has hundreds of bits of entropy. A complex but short string can be cracked in minutes by a brute-force attack. Make each passphrase unique and never reuse it. A unique passphrase limits the damage of a single data breach. If you cannot remember which passphrase goes where, you are not suffering from a memory problem. You are suffering from the absence of a password manager.
Use a Password Manager and a Breach Checker
A reputable manager generates and stores a random credential for every site. It is the single best investment in your digital defence. The CSA explicitly recommends using one. The zero-knowledge architecture means encryption and decryption happen only on your device. Even the company that makes the software cannot read your vault. Your master passphrase is the one you do memorise. It must be high-entropy and never reused anywhere else. Check your existing credentials against a breach-checking tool like Have I Been Pwned. It lets you search your email address across known data breaches and monitor domains for future exposure. If a credential shows up in a breach, change it immediately everywhere it was used. The pattern is simple: one unique passphrase for the master vault, one random credential per site, and a breach checker to catch the ones that slip through.
Two-Factor Authentication: Why SMS OTPs Fail You
Two-factor authentication setup Singapore users need starts with understanding what the second factor actually is. Something you know. Something you have. Something you are. SMS-based one-time passcodes used to be the default second factor, but they are the weakest link. A SIM swap attack works when an attacker convinces your mobile carrier to port your number to a new SIM card. All your SMS codes then arrive on their phone instead of yours. Singapore has seen reported cases of SIM swap fraud. The vector is well documented. The SS7 protocol is another hole, allowing attackers to intercept SMS in transit. And SMS codes are trivially phishable. A fake banking site asks you to enter the code you just received, and you hand over the second factor along with your passphrase.
Authenticator Apps and Security Keys
Authenticator apps using Time-based One-Time Passcodes, per RFC 6238, are better than SMS. The code is generated on your device and never traverses the mobile network. But they are still phishable in real time. A sophisticated phishing kit can relay the code to the legitimate site while you are still on the fake one. The gold standard is a FIDO2 security key. It is a physical device that performs a cryptographic challenge tied to the specific domain. A passkey is the passwordless evolution of this, built on the FIDO2 standard. Singpass guidance has been moving in this direction. Since 2020, all Singpass transactions require 2FA. The multi-user SMS OTP scheme was phased out in 2024. Current Singpass methods are the Singpass app push notification, Face Verification, and a limited SMS OTP for backward compatibility on certain devices. The push notification is a huge improvement. It requires you to approve a login on your phone, and it works over the internet, not the phone network.
Passkeys vs Passwords: The Phishing-Proof Upgrade
The passkeys versus passwords question has a clear answer. Passkeys win, and the reason is structural. A passkey is a cryptographic key pair stored on your device, and it is origin-bound to a specific domain. The passkey for Singpass will never work on a fake Singpass site. The browser verifies the domain before sending the cryptographic assertion. No shared secret is transmitted. There is nothing to phish and nothing to steal in a server-side data breach. The FIDO Alliance published its multi-device credential specification in 2022, which allows passkeys to sync across your devices through your platform ecosystem. Google Password Manager syncs passkeys with end-to-end encryption. Apple, 1Password, Bitwarden, and Dashlane have all shipped passkey support. You can also use a FIDO2 Certified security key with USB-A, USB-C, NFC, or Bluetooth Low Energy. Google's Advanced Protection Program used to require two of them for high-value accounts. A passphrase protects you from guessing. A passkey protects you from deception.
Assume You Are in a Breach
Assume your credentials are already in a data breach. The Personal Data Protection Commission has fined organisations under the PDPA for failing to protect personal data, and those enforcement decisions are public. The mandatory data breach notification requirement has been in effect since February 2021. Organisations must tell the PDPC and affected individuals about notifiable data breaches. Your job is to assume you are on the list and act. Change the credential on every account that shares the compromised one. Do it now. Enable multi-factor authentication on your email first. Your email is the master key to resets for everything else. Use a different passphrase for your email than for anything else. A breach checker will tell you which of your addresses have appeared in known leaks. It will also tell you if your domain is being searched by attackers, a common prelude to targeted phishing.
ScamShield and Verifying Suspicious Messages
ScamShield is your reporting channel for phishing attempts. The app blocks scam calls and SMS using a database built from Singapore Police Force scam reports, and it allows you to report suspicious messages directly. The ScamShield hotline is 1800-722-6688, operated by the Singapore Police Force Anti-Scam Command, formed in 2022 as a centralised unit that investigates scams and publishes typology statistics. Download ScamShield now. When you receive a forwarded message claiming to be from a bank or the police, stop and verify it on the official channel. A scammer can spoof a sender ID, so the call is not the verification. Hang up and call the official number on the back of your bank card. The police will never ask you to transfer money to a safe account. They will never ask for your Singpass credential or OTP over the phone.
Locking Down Your Singpass
The Singpass app push notification is the recommended method. When you log in to a government service, bank, or participating private sector service, you approve the login on your phone using your fingerprint or face. This is true multi-factor authentication. It combines something you have, the phone, with something you are, biometric authentication. Enable Face Verification in the Singpass app. It adds an additional liveness check that is harder to spoof than a fingerprint. Turn on notifications so you see every login attempt in real time. When a request comes in that you did not make, reject it and change your Singpass credential immediately. The Singpass app also supports SMS OTP as a fallback on devices without a camera or biometric sensor. Disable that fallback if your phone has the hardware. SMS is the weakest link.
One-Time Passcode vs Authenticator App: The Trade-Off
One-time passcodes come in two flavours. The SMS version arrives over the phone network, vulnerable to SIM swap fraud and SS7 interception. An authenticator app generates a TOTP that changes every 30 seconds, and the secret is stored only on your device. TOTP is not exposed to SIM swap. It is exposed to real-time phishing. If you enter a TOTP into a fake site, the attacker can immediately replay it to the real site. For this reason, a passkey is strictly better than both. It is tied to the domain and cannot be replayed on a lookalike. Enable passkeys where they are offered. Use an authenticator app where passkeys are not yet supported. Reserve SMS OTPs for accounts with no better option. Your bank may still require SMS OTP because of legacy systems. Push back and ask for a security token or app-based approval if they offer one.
When Your Account Is Already Compromised
If you suspect fraud, the order of operations is: change the credential, revoke sessions, report, and freeze. Change the credential on the compromised account first. Also change it on any other account that shares the same one. Revoke unknown sessions in the account settings. An attacker may have an active session that survives your credential change. Then report to the platform itself using its in-app reporting flow. File a report with the Singapore Police Force Anti-Scam Command. The police operate the ScamShield hotline at 1800-722-6688, and they take reports online through the police website. If your Singpass is compromised, do not just change the credential. Call Singpass to lock your account. The full weight of your digital identity is at stake: your NRIC number, your address, your tax records, your CPF. An attacker with your Singpass can set up a business in your name, redirect your government mail, and take over your bank accounts.
Digital Footprint and Data Breach: Minimising Exposure
Your digital footprint is the trail of data you actively leave behind: forum posts, social media updates, and images you upload. Your digital shadow is the data collected about you passively, such as browsing history, location data, and data broker profiles. A data breach can expose both. The Personal Data Protection Act requires organisations to protect personal data in their possession. The PDPC has enforced this with fines against companies that failed to make reasonable security arrangements. You cannot delete a data breach from the internet. You can reduce the damage by using unique credentials, enabling multi-factor authentication, and monitoring your accounts. The single most effective step is to use a breach checker like Have I Been Pwned. It alerts you when your email address appears in a new breach. This free service aggregates data from thousands of hacked websites. It is the fastest way to know when you need to rotate credentials.
| Password alone | No | Yes | Stolen via email, SMS, or fake site; reused credentials make it worse |
| SMS OTP | No | No | Code can be relayed in real time; SIM swap diverts it entirely |
| Authenticator app (TOTP) | Partially | Yes | Not exposed to SIM swap, but real-time phishing can relay the code |
| Push notification approval | Partially | Yes | User must approve; phishing can still trick a careless tap |
| Passkey (FIDO2) | Yes | Yes | Origin-bound to domain; no shared secret to phish or steal |
Phishing vs Scam Calls: A Fuller Threat Picture
Phishing is broader than SMS. It includes email, malicious websites, and QR codes. A spoofed SMS is one delivery mechanism where the sender ID is faked to appear as a legitimate organisation, and the link leads to a fake version of the official website. The ScamShield app blocks known scam numbers, but it is not perfect against brand-new spoofed numbers. The human check still matters. The Singapore Police Force categorises scams into six types: job scams, phishing scams, e-commerce scams, investment scams, impersonation scams, and love scams. Phishing scams alone accounted for 8,500 cases and over S$49 million in losses in 2024, according to the Singapore Police Force. The investment scam category had the highest total losses. Phishing touches everything because any scam needs credentials to get through the door. Verify the source before you act. Never click a link in an unsolicited message. Look at the URL, check the domain, and if in doubt, type the address manually into your browser.
Personal Data Protection Commission: Your Rights and the Rules
The Personal Data Protection Commission administers the PDPA. Its enforcement decisions are a public record of what goes wrong. The PDPA imposes eleven obligations on organisations: consent, purpose limitation, notification, access and correction, protection, retention limitation, transfer limitation, data breach notification, data portability, and the do-not-call registry. The consent obligation requires organisations to obtain consent before collecting, using, or disclosing personal data. The purpose limitation obligation means they cannot use your data for something a reasonable person would not expect. The protection obligation requires reasonable security arrangements. The breach notification obligation forces disclosure when those arrangements fail. If a company mishandles your data, complain to the PDPC. It has the power to issue directions and impose penalties. The PDPC is part of IMDA, and it publishes decisions that are readable by laypeople. You do not need a lawyer to understand when a company has failed you.
Turn On Passkeys Wherever You Can
Go into your Google account, your Apple account, your banking app, and your Singpass app. Look for the passkey option. Enable it. For the accounts that do not offer passkeys yet, switch your second factor from SMS to an authenticator app. Do this for your email first. Your email is the master key to every reset. Set aside 30 minutes this week, not next month. While you are in the settings, revoke any sessions you do not recognise and check your recovery phone number and email. Attackers change those to lock you out. The measure of success is not that you have read this. It is that you can log into your bank with your fingerprint on your phone and never once receive an SMS code again. That is the difference between being a target and being a dead end.