Asia

Two Malaysian Phone Shop Employees Arrested in Singapore Over Alleged Singpass Account Scam Scheme

Two Malaysian men working at a mobile phone shop in Singapore have been arrested over their suspected involvement in a coordinated scheme that allegedly exploited customers’ Singpass credentials to create e-wallet accounts without their knowledge.

The suspects, aged 25 and 47, were arrested on Aug 25 following a police operation involving Singapore Police Force’s Cyber Command and the Singpass Trust and Safety team at the Government Technology Agency (GovTech), according to authorities.

Investigators allege that the men took advantage of opportunities arising from their work to gain access to customers’ Singpass accounts. In one case, police said a customer buying a new SIM card was offered help updating the mobile number linked to their Singpass account — but an e-wallet account was allegedly created in the customer’s name without their knowledge.

More Than 160 E-Wallet Accounts Allegedly Created

Police said the compromised credentials were allegedly used to register more than 160 LiquidPay accounts, with the accounts estimated to have received around S$110,000 in proceeds linked to scams. Further investigations identified another 171 Singapore citizens and foreign workers whose Singpass accounts were connected to the same activity.

Authorities said the affected LiquidPay accounts have been frozen.

The two men were expected to face charges of assisting another person to retain benefits from criminal conduct, an offence that carries a maximum penalty of 10 years’ imprisonment, a fine of up to S$500,000, or both, according to police. As with all criminal cases, the allegations have yet to be proven in court.

The latest arrests come amid a series of enforcement actions involving alleged misuse of Singapore’s national digital identity system.

Earlier in August, three people were arrested in a separate alleged scheme targeting work permit holders. Police said compromised Singpass accounts in that case were used to register more than 30 LiquidPay accounts and over 1,200 mobile phone lines.

In July, five people were also arrested over alleged job scams in which victims were reportedly deceived into giving up control of their Singpass accounts under the guise of employment applications.

The separate cases highlight a growing concern for authorities: digital identity credentials can potentially be abused to open or access services ranging from financial accounts and e-wallets to mobile phone lines when they fall into the wrong hands.

Police Issue Fresh Warning: Never Share Your Singpass Credentials

Singapore Police have repeatedly warned the public against giving away Singpass passwords or two-factor authentication details — even when someone promises quick cash, discounts, jobs, or assistance with administrative tasks.

Authorities are also investigating individuals who may have voluntarily relinquished their Singpass credentials. Under Singapore’s Computer Misuse Act, disclosing Singpass credentials to facilitate an offence can carry penalties of up to three years in jail, a S$10,000 fine, or both.

For anyone who suspects their Singpass account has been compromised, Singpass advises users to act quickly by securing related bank accounts, suspending or recovering their Singpass account, resetting passwords and reviewing account activity for anything suspicious.

The Bigger Picture

What makes this case particularly alarming is the alleged exploitation of ordinary, everyday interactions. A customer seeking help with a SIM card or account update may not immediately suspect that access to a national digital identity could be misused to create financial accounts behind the scenes.

The investigation also serves as a stark reminder that digital convenience comes with a shared responsibility for digital security. No matter how legitimate a request may appear, users should never hand over passwords, one-time codes or authentication details to another person.

As Singapore’s investigation continues, the case is likely to intensify scrutiny over how digital identity credentials are handled by businesses and individuals — and how quickly criminals are adapting to exploit trust in an increasingly digital world.


Leave a Reply

Your email address will not be published. Required fields are marked *