Singapore · Weekly briefing · Nº 042

Life

Scams and Singpass phishing for newcomers in Singapore

How EP/FIN holders get targeted — fake bank/police WhatsApp, Singpass device resets, money-mule job ads, gov.sg SMS ID, ScamShield 1799, and SPF i-Witness reporting.

LifeArriving & Living3 min read

Short answer: Government, banks, and CPF will never ask you to transfer money, share OTP/Singpass passwords, or install sideloaded apps. Install ScamShield, learn the gov.sg SMS sender, and call 1799 when unsure — then your bank’s number from the card/app, not from the message.

New EP holders are high-value scam targets: fresh FIN cards, new Singpass, banks still unfamiliar, and recruiters already asking for passport scans. r/askSingapore’s recurring pattern is the same — WhatsApp “bank fraud”, fake police, job ads that want NRIC/EP photos, then a Singpass login that drains accounts.

Non-negotiables (memorise these)

Government officials, banks, and CPF Board will never ask you over a call or chat to:

  • Transfer money to “safe” accounts
  • Share bank login, OTP, or Singpass password
  • Install apps from outside official stores
  • Hand over cash, gold, or jewellery for “investigation”
  • Approve a Singpass transaction you did not start

SPF’s own banner points to the 24/7 ScamShield Helpline: 1799. Use it when unsure.

Week-one hardening for foreigners

ActionWhy
Install ScamShield and grant call/SMS filter permissionsBlocks numbers SPF has flagged; filters suspicious SMS from unknown/overseas senders
Learn gov.sg SMS sender IDAgency SMS consolidates under the government sender — see sms.gov.sg
Singpass: strong unique password + face verification habitsCompromised Singpass unlocks banks, CPF, IRAS
Bank app: transaction limits, Money Lock / similar locks if offeredLimits blast radius if OTP is phished
Never send front/back of EP + selfie holding FIN to “HR on Telegram”Classic mule / loan-shark intake

If you already clicked / shared

  1. Hang up / stop the chat — do not “cooperate to clear your name”
  2. Call 1799 and your bank’s official hotline from the card/app (not a number in the SMS)
  3. Reset Singpass via the official helpdesk / security flow; review devices and recent transactions
  4. File SPF i-Witness / Police e-services report with numbers, links, and account details
  5. If a cracked APK was installed, factory-reset the phone after securing accounts

Photos of an EP alone are not usually enough to empty a bank overnight — but combined with OTP phishing or a Singpass device transfer they are. Speed matters more than embarrassment.

Money-mule and “easy side job” traps

Ads that pay you to receive and forward money, register companies, or open accounts for “overseas clients” are how foreigners become the arrested middle layer. Side income on a work pass already has MOM limits — side income guide — and mule activity is criminal, not a grey gig.

Pair with day-one admin

Singpass and banking setup belong in apps that matter and opening a bank account. Emergency numbers sit in 995 / 999 / embassies. Scam hygiene is the missing layer between those guides.

Family note: report-card portal SMS threads are prime phishing bait — open school links from the saved portal bookmark, not from rushed WhatsApp forwards.

Questions, answered

Will the police or my bank ask me to transfer money to a “safe” account?
No. SPF, banks, and CPF Board never ask you over WhatsApp, phone, or chat to move money, share OTP/Singpass passwords, install sideloaded apps, or hand over cash/jewellery for an “investigation.” Hang up and call ScamShield 1799 or the number on your bank card/app.
What should new EP holders install in week one against scams?
Install ScamShield and grant call/SMS filter permissions, learn that genuine agency SMS consolidates under the gov.sg sender ID, harden Singpass with a unique password and careful face-verification habits, and set bank transaction limits or Money Lock-style controls if your bank offers them.
I already shared OTP or clicked a Singpass link — what now?
Stop the chat immediately. Call 1799 and your bank’s official hotline, reset Singpass via the official security flow, review devices and recent transactions, and file an SPF i-Witness / Police e-services report with numbers, links, and account details. Speed beats embarrassment.
Is a job ad asking for EP front/back photos plus a selfie safe?
Treat it as high risk. Passport/EP photo packs on Telegram or “easy side jobs” that pay you to receive and forward money are classic mule intake. Real HR uses company domains and never needs you to open accounts for overseas clients.
Does ScamShield replace calling the bank after a phishing hit?
No. ScamShield filters and the 1799 helpline help you verify threats; account freezes, OTP resets, and recovery still go through your bank’s official channels and, when needed, a police report.

Sources & citations

Admin and policy details change. Prefer the official page when making decisions; we cite primary sources for Singapore government and statutory guidance.

  1. ScamShield — home (opens in a new tab)
  2. ScamShield — phishing scams (opens in a new tab)
  3. ScamShield — set up the app (opens in a new tab)
  4. GovTech — five ways to keep Singpass safe (opens in a new tab)
  5. Singpass — security (opens in a new tab)
  6. CPF — account safeguards / scam cues (opens in a new tab)
  7. sms.gov.sg — government SMS sender ID (opens in a new tab)