Phishing is the scam that pretends to be someone you trust. A message lands in your inbox or on your phone claiming to be from your bank, a delivery company, a government agency, or a well known shop, and it tries to trick you into clicking a link, handing over a password, or sharing a one time code. Recognising phishing Singapore residents receive every day is one of the most useful digital skills you can build, because these messages are the front door to most online fraud.
The good news is that phishing follows patterns. Once you know the tricks, the fakes start to stand out. This guide shows you the warning signs in emails and SMS, the rules that keep you safe no matter how convincing a message looks, and exactly what to do when a suspicious one arrives.
The Warning Signs to Watch For
Phishing messages lean on a handful of tactics again and again. The first is urgency. Scammers want you to act before you think, so they warn that your account will be closed, a payment has failed, a parcel is stuck, or suspicious activity has been detected. A real organisation rarely demands that you act within minutes through a link in a message. When a message tries to rush you, slow down; that pressure is itself a warning sign.
The second is the fake or mismatched link. The visible text might read like an official website, but the actual address it points to is something else entirely. On a computer you can hover your mouse over a link to see where it really goes, without clicking. On a phone, press and hold to preview the address. If the domain looks odd, misspelled, or unrelated to the company, do not touch it. Scammers also use shortened links and lookalike domains that swap or add a letter, so read carefully.
The third is the spoofed sender. The name shown might say your bank, but the email address behind it is a jumble or a free webmail account. In SMS, scammers may fake a sender name to sit in the same thread as genuine messages, which is why you should never judge a message by the sender name alone. Singapore has moved many legitimate business SMS senders to a registered system to cut down on spoofing, but you should still treat any unexpected message with caution.
The fourth is the request itself. Phishing almost always asks for something it should not: your password, your full card number, your one time password, your NRIC, or a login through a link. No genuine bank, agency, or company will ask you to confirm these through a message. The phrase “verify your account” followed by a link is one of the most common hooks of all.
Other tells include odd spelling and grammar, greetings that do not use your name, offers that seem too good to be true, and attachments you were not expecting. Any one of these should put you on guard. Several together mean the message is almost certainly a scam.
The Rules That Keep You Safe
You do not need to identify every trick to stay safe. A few firm rules cover almost every case, because they protect you even when a fake is very well made.
Never click links in unexpected messages. If a message says there is a problem with your bank, delivery, or government account, do not use its link. Instead, open the official app or type the known website address yourself, or call the number printed on your card or the company’s real website. This single habit defeats most phishing, because the scam depends on you using their link rather than reaching the organisation directly.
Never share your passwords or one time passwords with anyone. A one time password, often called an OTP, is the code sent to approve a login or payment. No genuine staff member will ever ask you to read it out or type it into a link. Anyone who asks for your OTP is trying to break into your account. The same goes for full card numbers and account passwords.
Do not open unexpected attachments, and do not enable anything a message tells you to enable to view a document. Treat requests to install an app from a link, or to grant remote access to your device, as major red flags.
The table below sorts the common signs so you can check a suspicious message at a glance.
| Warning sign | What it looks like | Safe response |
|---|---|---|
| Urgency | “Act now or your account closes” | Slow down, do not rush |
| Fake link | Address differs from the company | Do not click, go direct instead |
| Spoofed sender | Odd address behind a trusted name | Judge by content, not the name |
| Request for secrets | Asks for OTP, password, or card | Never share, no one legitimate asks |
| Too good to be true | Prizes, refunds, easy money | Assume it is a scam |
What to Do When a Suspicious Message Arrives
When a message trips your radar, the calm response is to do nothing it asks and then verify through a channel you trust. If it claims to be your bank, log in through the official app or call the number on the back of your card. If it claims to be a government agency, go to the agency’s official website yourself. Reaching the organisation through a route you chose, rather than one the message gave you, is the whole game.
If you are unsure whether a message is genuine, treat it as suspicious until proven otherwise. It is far better to ignore a real message and follow up yourself than to trust a fake. You can also use Singapore’s anti scam tools to help. The ScamShield app can filter and flag scam messages and calls, and it is a sensible thing to have installed. If you receive a scam message, report it, block the sender, and delete it.
If you think you have fallen for a phishing attempt, act quickly. Contact your bank straight away to freeze cards or accounts if you shared any financial details, and change the passwords for any account that may be exposed. Report the scam to the Police through their official channels, and you can seek advice from the ScamShield Helpline, whose number is listed on the official ScamShield website. Do not stay silent out of embarrassment; fast reporting gives the best chance of limiting the damage and helps the authorities warn others.
Phishing works by rushing you and impersonating someone you trust. Strip away the urgency and the borrowed logo, and you are left with a stranger asking for your secrets. Keep the simple rules in mind, never click unexpected links or share your OTP, always verify through official channels, and report what you spot, and you take away almost all of the scammer’s power.