Man Jailed After Driving Around Singapore With SMS Blaster That Sent More Than 10,500 Phishing Messages

Business

Man Jailed After Driving Around Singapore With SMS Blaster That Sent More Than 10,500 Phishing Messages

A Malaysian man who drove around Singapore for up to 12 hours a day while carrying an “SMS blaster” that transmitted thousands of phishing messages has been sentenced to 21 months in jail and fined S$1,500.

Ong Kak Seng, 28, was sentenced on Sept 14 after pleading guilty to one charge of cheating as part of a criminal conspiracy.

Two other charges were taken into consideration during sentencing. He will serve an additional week in jail if he fails to pay the fine.

The case highlights how scammers are increasingly using specialised equipment to send fraudulent messages directly to large numbers of mobile phones.

More than 10,500 phishing messages sent

Between Oct 13 and Nov 18, 2025, Ong drove around Singapore with the device hidden in the back of his car.

The SMS blaster was designed to mimic a mobile network and push messages to phones within its coverage area.

Investigators found that at least 31,820 mobile phones had fallen within the device’s range during the period.

A total of 10,533 phishing messages targeting WhatsApp accounts were transmitted.

The messages were designed to trick recipients into entering their WhatsApp login details through a fraudulent website. Those details could then be used by others to take over victims’ accounts.

At least one victim lost more than S$1,800 after being deceived into transferring money to a bank account controlled by a third party.

Ong was offered RM1,000 a day

Ong became involved after accumulating about RM80,000 in debt to unlicensed moneylenders.

In October 2025, a man known as “Bai Ge” offered him RM1,000 a day to drive around densely populated areas in Singapore or Hong Kong with the device in his car.

Ong chose Singapore because he could use his own vehicle rather than rent one in Hong Kong.

He later travelled to Malaysia to learn how to assemble the equipment, which included batteries, an antenna, wires and remote controls.

He then brought the components into Singapore, assembled the device and concealed it under a cardboard box in the rear of his car.

He also bought two mobile phones, one of which was used to operate the equipment.

He continued after discovering the scam

Ong initially believed he was helping to promote illegal online gambling.

However, after several days of driving, he discovered that the device was actually transmitting phishing messages aimed at stealing WhatsApp account credentials.

Despite realising what was happening, he continued carrying out the work because he needed the money.

Court proceedings heard that Ong even warned his own sister about the phishing messages when he visited her while the device was still inside his car.

He knew she might receive one of the messages and told her not to open links leading to websites from suspicious WhatsApp or SMS messages.

His warning was particularly significant because his sister had previously fallen victim to a scam.

Arrested in islandwide police operation

Police received reports in October and November 2025 about suspicious messages being sent to members of the public.

An islandwide operation was conducted on Nov 18 and 19 to identify and arrest people involved in the phishing campaign.

Ong was arrested on Nov 18.

Officers searched his car and accommodation and seized the SMS blaster and related equipment.

By the time he was arrested, Ong had received RM5,000 for his role.

Another person, whom Ong understood to be involved in similar activity, was also driving around Singapore as part of the operation.

Cross-border scam network

The case was not an isolated act of opportunistic fraud.

Prosecutors highlighted the scale and organised nature of the operation, noting that it involved multiple people and crossed national borders.

The person who recruited Ong was based in Malaysia, while Ong carried out the physical operation in Singapore.

The use of an SMS blaster also allowed the operation to reach large numbers of mobile phones without relying solely on conventional bulk messaging systems.

This made the scheme particularly dangerous because messages could appear directly on phones in the device’s vicinity.

A warning about phishing messages

The case also underscores the risks posed by phishing attempts that try to steal messaging-app credentials rather than directly asking victims for money.

Once attackers gain control of a WhatsApp account, they can potentially impersonate the account holder and approach the victim’s contacts for money or other sensitive information.

Users should avoid clicking suspicious links, entering login credentials on unfamiliar websites or responding to unexpected messages asking for account information.

The Singapore case shows how quickly a single mobile device can be used to expose tens of thousands of people to fraudulent messages.

For Ong, the operation ended with a 21-month jail sentence and a fine. For Singapore’s authorities, the case offers another warning about the increasingly sophisticated tools being used by organised scam networks to reach potential victims at scale.

Leave a Reply

Your email address will not be published. Required fields are marked *