SINGAPORE — Singapore is stepping up its fight against a new and potentially troubling scam tactic involving so-called SMS blasters, devices capable of sending deceptive messages directly to nearby mobile phones and potentially bypassing some of the safeguards consumers have come to rely on.
The threat highlights a major shift in how scammers operate. While Singapore has spent years strengthening filters against suspicious SMS messages and blocking known malicious links at the telecommunications-network level, criminals are increasingly exploring methods designed to get around traditional defences.
The concern is simple: What happens when a scam message does not travel through the normal SMS route in the first place?
What Are SMS Blasters and Why Are They a Growing Concern?
SMS blasters, also known in some contexts as fake base stations or rogue cellular transmitters, can impersonate legitimate mobile network infrastructure and transmit messages to phones within range.
This means victims may receive fraudulent messages that appear to come directly to their devices without scammers necessarily using conventional telecommunications channels.
The technology has raised concerns because Singapore’s existing anti-scam measures have focused heavily on disrupting malicious messages travelling through legitimate telecom networks.
According to the Infocomm Media Development Authority (IMDA), Singapore has adopted a multi-layered strategy against scam calls and SMS, including network-level filtering by telcos, blocking known malicious links and identifying suspicious message patterns. IMDA said that in 2024 alone, 117 million potential scam calls and 50 million SMS messages were blocked.
But emerging tactics such as SMS blasters demonstrate why the fight against scams remains a constant technological race.
Singapore Has Already Tightened Its SMS Defences
Singapore introduced the SMS Sender ID Registry to make it more difficult for scammers to impersonate legitimate organisations through alphanumeric sender names.
IMDA previously said the registry was introduced after a sharp rise in SMS scams, with registered sender IDs receiving protection against spoofing. Authorities later strengthened the system further, requiring organisations using alphanumeric sender IDs to register and labelling certain non-registered messages as “Likely-SCAM”.
Telcos have also been required to implement network-level anti-scam filters that detect known malicious URLs and suspicious patterns commonly associated with fraudulent SMS messages.
The SMS blaster threat, however, shows that scammers are not standing still.
Why the Scam Threat Matters for Every Phone User
The danger of phishing messages goes beyond simply receiving an annoying SMS.
A convincing fake message can lead victims to phishing websites designed to steal banking details, credit card information, passwords or One-Time Passwords (OTPs). In other cases, scammers use fraudulent messages to take over messaging accounts such as WhatsApp before targeting the victim’s contacts.
Singapore Police recently warned about phishing scams involving WhatsApp messages impersonating SingPost. Since March 15, 2026, police said at least 10 cases had been reported, with losses of at least S$22,000. Victims were directed to phishing websites and asked to provide banking credentials, card details or OTPs.
Police have also repeatedly warned that scammers are increasingly targeting WhatsApp accounts.
In one advisory issued in May 2026, authorities said at least 52 cases involving social media impersonation scams arising from compromised WhatsApp accounts had been reported since April 1, with losses of at least S$46,000.
The pattern is increasingly clear: One compromised account or stolen credential can quickly lead to multiple victims.
WhatsApp Account Takeovers Are Adding to the Risk
Scammers have used multiple methods to seize control of WhatsApp accounts.
One common tactic involves tricking victims into surrendering their verification codes. A victim may receive an SMS or WhatsApp notification containing an OTP, followed by a message from what appears to be a known contact asking for the code.
But the “contact” may already have had their account compromised.
Once the victim provides the OTP, scammers can gain access to the WhatsApp account and use it to target friends, family members and colleagues.
Singapore Police said users should never provide WhatsApp OTPs to anyone and should regularly check linked devices and enable Two-Step Verification.
The Bigger Picture: Singapore’s Scam Fight Is Working — But New Threats Keep Emerging
Singapore has seen some encouraging signs in its broader fight against scams.
According to the Singapore Police Force’s mid-year scam and cybercrime figures, overall scam cases fell 14.4 per cent in the first half of 2026 compared with the same period in 2025. Total losses also dropped 17.9 per cent to about S$410.6 million.
However, phishing remained the second most common scam type, with 3,104 cases and S$9.6 million lost during the first six months of 2026.
Meanwhile, compromised WhatsApp accounts have become an increasingly important avenue for scammers. Police said 391 of Singapore’s social media impersonation scam cases in the first half of 2026 involved criminals approaching victims through compromised WhatsApp accounts.
The numbers underline a difficult reality: Even as authorities block millions of suspicious calls and messages, scammers continue developing new ways to reach potential victims.
Singapore Is Also Tightening Rules for Online Messaging Platforms
The fight against scams is now extending beyond traditional SMS.
In August 2026, Singapore announced new anti-scam requirements for designated online messaging services, including WhatsApp and Telegram, aimed at making it harder for unknown contacts to reach users.
The measures form part of enhanced codes of practice issued under Singapore’s Online Criminal Harms Act framework, reflecting growing concerns about scams and malicious activity moving across messaging and social platforms.
The shift is significant because scammers no longer depend on just one communication channel.
A victim may receive an SMS, then be redirected to WhatsApp, Telegram, a fake website or even a fraudulent phone call.
How Singaporeans Can Protect Themselves
Authorities continue to urge the public to remain cautious, regardless of how legitimate a message may appear.
Key steps include:
- Do not click suspicious links in SMS or messaging apps.
- Never share passwords, banking credentials or OTPs.
- Be suspicious of urgent messages demanding immediate action.
- Verify unusual requests through official channels.
- Check WhatsApp’s Linked Devices section for unfamiliar devices.
- Enable Two-Step Verification on WhatsApp.
- Use ScamShield and other official anti-scam tools.
- Contact your bank immediately if you believe your financial information has been compromised.
- Call the ScamShield Helpline at 1799 if you need help verifying a potential scam.
The latest SMS blaster threat serves as another reminder that technology alone cannot completely eliminate scams.
Singapore’s filters, sender registries and network-level protections have blocked millions of suspicious communications. But as scammers experiment with new methods designed to bypass traditional systems, the most important line of defence may still be the person holding the phone.
And that means one suspicious message could still be all it takes.
The next fake SMS may not look suspicious at all — and that is exactly what makes Singapore’s newest scam threat so dangerous.

Leave a Reply