Singapore Police Warn of New iMessage Phishing Scam Impersonating DBS and Shopee

Asia

Singapore Police Warn of New iMessage Phishing Scam Impersonating DBS and Shopee

Singapore users are being warned about a new phishing scam exploiting Apple’s iMessage, with criminals posing as DBS fraud investigators or Shopee customer-support personnel to trick victims into handing over sensitive banking information.

The Singapore Police Force said the latest scam variant typically begins with an iMessage claiming that a pending transaction requires urgent verification. Recipients are then instructed to call a phone number provided in the message to supposedly resolve the issue.

The scam starts with an urgent warning

The fraudulent message is designed to create panic.

A recipient may be told that a transaction is pending or that suspicious activity has been detected. Instead of directing the person to an official banking or shopping app, the message provides a telephone number for the victim to call.

Once the victim contacts the number, scammers allegedly pose as fraud investigators or customer-service representatives.

They may then claim that the person’s payment card has been compromised and ask for card details and one-time passwords, or OTPs, supposedly to “verify” the account.

That is where the scam can become financially devastating.

Police said victims may only realise they have been deceived after noticing unauthorised transactions on their cards or bank accounts, or unauthorised logins to their e-commerce accounts.

It is part of a much bigger iMessage scam wave

The warning comes after Singapore police reported a major increase in scams exploiting Apple iMessage.

Since June 2026, the Cyber Command has detected and disrupted more than 30,000 Apple iMessage accounts linked to the wider scam campaign. Police previously estimated that scams impersonating courier companies had caused about S$2.2 million in losses.

Earlier versions of the campaign impersonated courier companies including Ninja Van, J&T Express and SPX Express.

Scammers sent messages containing links to fake websites designed to resemble legitimate courier, government or financial websites. Victims could then be asked to make a small payment before being prompted to enter card details or banking credentials.

Why iMessage is being exploited

Police said iMessage operates separately from Singapore’s SMS anti-scam protections.

In some cases, scammers have attempted to persuade recipients to reply with messages such as “Y” or “1”. Police believe this can help circumvent an iMessage security feature that initially makes links from unknown senders unclickable until the recipient interacts with the sender.

Once the victim responds, a malicious link may become clickable.

The fake website can then be used to collect information such as credit-card details, internet-banking credentials and OTPs.

In previous cases, police said scammers were also able to add victims’ credit cards to Apple Pay or Google Pay or provision bank digital tokens on unfamiliar devices.

DBS has issued its own warnings

DBS has separately warned customers about phishing attempts designed to steal banking credentials, card information, OTPs and digital-token approvals.

The bank says customers should use official DBS channels for banking-related requests and should never provide card details, digibank credentials, OTPs or Digital Token approvals to unverified sources.

DBS also states that its emails and SMSes do not contain clickable links.

How to protect yourself

Singapore authorities are urging the public to take several precautions.

First, do not click links in unexpected messages, even if the message appears to come from a familiar company.

Second, never provide your OTP, password, banking credentials or card information to someone who contacts you unexpectedly.

If a message claims that there is a problem with your bank account or Shopee account, open the official app yourself or independently locate the organisation’s official contact details rather than using the phone number or link provided in the suspicious message.

Apple users should also make sure iMessage’s “Filter Unknown Senders” and “Filter Spam” functions are enabled and report suspicious messages through the appropriate in-app reporting functions.

For additional assistance, Singapore’s 24-hour ScamShield helpline can be reached at 1799.

The warning is bigger than DBS and Shopee

The latest scam illustrates how quickly criminals can change the identity they use to appear legitimate.

Today it may be a bank or e-commerce platform. Earlier campaigns impersonated courier companies, government agencies and other trusted organisations.

The technology may change, but the basic strategy remains the same: create urgency, make the victim trust the impersonator and persuade them to hand over information that should never be shared.

So if an unexpected iMessage tells you that your money is in danger, don’t panic, don’t call the number provided and don’t share an OTP.

The safest response may be the simplest one:

Close the message and verify everything through an official channel.

WWC ONE MEDIA J.M.D

Leave a Reply

Your email address will not be published. Required fields are marked *