Phishing used to be easier to spot. There were clumsy sentences, odd sender names, strange grammar, and links that looked like they had been assembled in a hurry. Those clues still appear, but they are no longer enough. In 2026, Singapore residents and SMEs face phishing attempts that can be polished, localised and personally relevant because scammers can use artificial intelligence to write better messages, imitate voices, alter faces on video calls and generate fake customer-service scripts at scale.
CSA Singapore warned in July 2026 that AI is reshaping phishing and scam operations by lowering the cost of deception. Threat actors can now generate more convincing phishing lures, create realistic voice clones and video deepfakes, and build tools that help them bypass traditional security checks. That does not mean every scam is powered by advanced AI. It means Singaporeans can no longer rely on poor language, awkward layouts or an unfamiliar accent as the main warning signs.
The risk is practical, not theoretical. A scammer who pretends to be a bank officer, courier company, Microsoft technician, MAS officer, supplier, boss or family member can now sound more credible. A fake link can be supported by a well-written WhatsApp message. A phishing email can reference a real invoice format. A fake video call can appear to show a senior executive approving a transfer. For SMEs, this pushes ordinary payment approval, vendor onboarding and account-reset workflows into higher-risk territory.
This guide explains how AI-enabled phishing works in Singapore, why it matters even as reported phishing attempts fluctuate, and what residents, finance teams, HR staff, educators and business owners should do before clicking, paying or sharing credentials.
How This Scam Works in Singapore
AI phishing usually begins with a familiar pretext. The message may claim to be from a bank, SingPost, Ninja Van, a government agency, Microsoft support, a marketplace buyer, a supplier, a school, a telco or a senior colleague. The delivery channel can be SMS, iMessage, WhatsApp, Telegram, email, social media direct message, search advertisement, QR code, pop-up alert or phone call. The criminal objective is to move the victim from a trusted surface into a controlled environment: a fake website, remote access session, payment instruction, video call or chat thread.
The first layer is language. AI tools allow scammers to write clean English, adapt to Singlish-lite phrasing, produce Mandarin or Malay variants, and remove obvious spelling mistakes. This is especially dangerous for phishing emails aimed at SMEs, where messages may refer to invoices, delivery notices, account verification, recruitment documents or urgent procurement requests. The message no longer has to look amateurish to be malicious.
The second layer is personalisation. Scammers can scrape public information from LinkedIn, company websites, ACRA-style business listings, marketplace profiles, social media posts and leaked data. An SME finance executive may receive an email that names a real supplier. A resident may receive a message that looks linked to an actual parcel delivery. A job seeker may be contacted about a role that matches their online profile. AI helps criminals turn fragments of public context into a message that feels tailored.
The third layer is voice and video. In deepfake or voice clone variants, a scammer may imitate a director, finance head, client, public officer or family member. The request is usually urgent: approve a transfer, share a one-time password, install software, disclose bank log-in details, change a supplier bank account, or keep the matter confidential. In some business cases, scammers may stage a video call where faces or voices appear to match senior executives. The point is not cinematic perfection. The point is to create enough trust and time pressure that the victim stops following verification procedures.
The fourth layer is technical steering. CSA and SPF have highlighted variants where victims are pushed towards phishing links, fake pop-ups or remote access tools. In technical support scams involving Microsoft impersonation, victims may see a browser pop-up that claims their device has been blocked or infected. If they call the number shown, the scammer may pose as a support technician and then escalate the story to police or money-laundering allegations. Once remote access is granted, the scammer can view files, capture credentials, guide transfers or make unauthorised transactions.
Singapore's trusted digital infrastructure is often abused in the storyline. Scammers may mention Singpass, PayNow, MAS, SPF, CSA, bank fraud departments, courier companies or government payouts. They may claim that funds must be moved to a safe account, that a bank account is under investigation, that a delivery fee is unpaid, or that an SME's invoice will be delayed unless new payment details are used. The references are designed to sound official, but the requested action is the red flag.
Real-World Impact and Statistics
The broader scam environment remains serious. SPF's Annual Scam and Cybercrime Brief 2025 reported 37,308 scam cases in 2025, down 27.6 per cent from 51,501 cases in 2024, while scam losses fell 17.9 per cent to about S$913.1 million. A decline in cases is welcome, but the amount remains severe, and SPF continues to warn that scammers adapt quickly when a particular channel becomes harder to exploit.
CSA's July 2026 update on Singapore's cyber threat landscape adds an important nuance. Reported phishing activity in Singapore fell to about 4,800 attempts in 2025, a 21 per cent decrease from about 6,100 in 2024, but AI is making phishing lures more convincing. CSA also noted that threat actors can use AI to generate realistic voice clones and video deepfakes, and to develop tools that may bypass multi-factor authentication. Fewer reported attempts do not automatically mean lower risk for every household or SME, because a smaller number of better-targeted attempts can still cause major harm.
For individuals, the damage often extends beyond one lost transfer. A phishing victim may lose bank savings, credit card details, Singpass-linked personal data, passport information, CPF-related documents or access to messaging accounts. Personal data exposed in one incident can later be reused for impersonation, loan applications, mule recruitment or further social engineering. Under Singapore's PDPA framework, organisations also have obligations around protecting personal data, which makes phishing a business risk as well as a consumer risk.
For SMEs, AI phishing can become business email compromise, supplier impersonation, payroll fraud or ransomware entry. A single fake instruction can redirect an invoice payment to a mule account. A fake HR document can steal Microsoft 365 credentials. A fake video call can override normal scepticism. Once a mailbox is compromised, scammers may study previous invoices and reply inside genuine email threads, making the next fraudulent request harder to detect.
There are also legal consequences for those who assist scam operations. Money mules, account sellers and people who let others use their bank accounts can face serious investigation and penalties under Singapore law. Where systems are accessed without authorisation, offences under the Computer Misuse Act may be relevant. The victim may feel embarrassed, but reporting quickly is still the right move because rapid bank and police action can improve the chance of freezing funds.
How to Protect Yourself
Treat unexpected urgency as a security signal. If a message says you must act immediately, keep the call open, maintain secrecy, transfer money, install an app, scan a QR code or provide credentials, slow down. Scammers use urgency because verification breaks the spell. A legitimate bank, government agency or technology provider should be able to withstand a short pause while you check.
Verify through a channel you find independently. Do not use the phone number, link or QR code provided in the suspicious message. Search for the official website, use your banking app directly, call the number printed on the back of your card, or contact the organisation through a previously known channel. For government services, check that websites end in .gov.sg and that you are on a secure connection before entering any information.
Never share one-time passwords, Singpass credentials, bank log-in details, card numbers or screen-sharing access because someone asks over a call or message. SPF, MAS, CSA and banks do not need your password to help you. Microsoft does not display support phone numbers inside genuine error or warning messages. A real courier company does not need your banking credentials to redeliver a parcel.
For voice or video requests, create a family or workplace verification phrase. This should be a short, private phrase that is not posted online and not stored in a shared email inbox. If someone calls claiming to be a family member in distress, hang up and call their usual number. If a senior executive asks for an urgent payment over voice or video, verify through a separate channel such as the company directory, a second authorised approver or an in-person confirmation.
For SMEs, payment controls need to assume that email, voice and video can be spoofed. Use dual approval for changes to bank details, new beneficiaries and urgent transfers. Require callback verification to a previously validated supplier contact, not the number in the latest email. Keep vendor master data changes separate from payment approval. Train staff to report suspicious requests without fear of blame, because silence helps scammers.
Secure accounts with phishing-resistant habits. Use password managers so fake domains are easier to spot, turn on multi-factor authentication, keep devices and browsers updated, and avoid installing remote access tools unless your organisation's IT team initiated the support session through a known channel. For personal phones, install and use ScamShield, and check suspicious messages or websites before acting.
What to Do If You Are Targeted
If you have not clicked or shared anything, do not engage further. Take a screenshot, block the sender if appropriate, and report the message through ScamShield or the platform involved. Sharing reports helps improve detection and disruption, especially when many people receive the same campaign.
If you clicked a link but did not submit information, close the page and clear the tab. Do not download files, allow notifications or install profiles. If the page asked you to log in, visit the real site separately and change your password if you are worried. If the same password is used elsewhere, change it there too.
If you entered banking details, card information, Singpass credentials or one-time passwords, act immediately. Contact your bank's fraud hotline and ask for urgent assistance, including card blocking, account freezing or activation of the bank's kill switch where available. Then make a police report. If you are unsure what to do next, call the 24/7 ScamShield Helpline at 1799.
If you installed remote access software, disconnect the device from the internet, stop using it for banking and get it checked. Change important passwords from a separate clean device. Inform your bank and monitor transactions. For company devices, alert IT or your managed service provider immediately because one compromised endpoint can expose mailboxes, shared drives and customer data.
If your SME has sent money to a fraudulent account, escalate fast. Notify the bank, file a police report, preserve the full email headers, chat messages, invoices, phone numbers, transaction references and screenshots. Do not delete the mailbox or wipe devices before evidence is preserved. If personal data may have been exposed, assess whether PDPA breach notification obligations apply and involve legal or data protection support where needed.
Common Mistakes to Avoid
Do not assume a message is safe because it is well written. AI has made polished writing cheap. A scam can use proper grammar, local references and a professional tone.
Do not assume a call is genuine because the person knows your name, company or recent activity. Much of that information may be public, leaked or inferred. The more specific the message feels, the more important independent verification becomes.
Do not trust a video call simply because you recognise a face. Deepfake scams do not need to fool a forensic analyst; they only need to fool a tired employee for a few minutes during an urgent request.
Do not use links from search advertisements without checking the domain. Scammers can buy ads that appear above legitimate results, especially for banking, courier, software support and government-related searches.
Do not keep scam concerns quiet because you feel embarrassed. Early reporting can help banks freeze funds, help police trace mule accounts, and help colleagues or family members avoid the same trap.
Do not let convenience override payment procedures. For SMEs, the most dangerous phrase is often "just this once". If a control can be bypassed during a stressful Friday afternoon, scammers will eventually find that gap.
FAQ
What is an AI phishing scam?
An AI phishing scam is a phishing attempt that uses artificial intelligence to improve the deception. This may include better-written messages, personalised lures, voice cloning, deepfake video, fake customer support scripts, automated chat responses or tools that help scammers test which messages get victims to click.
Are AI phishing scams common in Singapore?
Singapore authorities have warned that AI is reshaping scam operations, even though not every scam uses advanced AI. CSA reported about 4,800 phishing attempts in 2025, down from about 6,100 in 2024, while warning that AI can make phishing lures, voice clones and deepfakes more convincing. SPF's wider scam statistics show that scams remain a high-loss threat.
How can I tell if a deepfake call is fake?
Look at the request rather than only the face or voice. If the caller asks for secrecy, urgent payment, credentials, OTPs, remote access or a change of bank details, treat it as suspicious. End the call and verify through a separate official or previously known channel.
What should SMEs do about AI phishing?
SMEs should strengthen payment approval, supplier verification, mailbox security and staff reporting. Require dual approval for urgent transfers and bank-detail changes, verify suppliers through known contacts, use MFA, train staff on voice and video impersonation, and preserve evidence quickly if an incident occurs.
Should I call 1799 for suspicious AI scam messages?
Yes, call the 24/7 ScamShield Helpline at 1799 if you are unsure whether something is a scam. If money has already been transferred or credentials have been shared, contact your bank immediately as well and make a police report.
Can scammers bypass multi-factor authentication?
Some phishing attacks are designed to steal OTPs, trick users into approving push notifications, or capture active session tokens through fake login pages. MFA remains important, but it must be paired with domain checking, password managers, device hygiene and a habit of refusing unexpected credential requests.
Does PDPA matter for phishing scams?
Yes. For organisations, a successful phishing incident may expose customer, employee or vendor personal data. Businesses should assess what data was accessed, contain the breach, document the incident and consider whether notification obligations under Singapore's PDPA apply.
Conclusion
AI has not changed the basic defence against phishing: stop, check, and verify independently. What it has changed is the reliability of old warning signs. Bad grammar, awkward voices and strange-looking messages can no longer be the main line of defence for Singapore residents or SMEs.
The practical response is disciplined verification. Do not click because a message looks polished. Do not pay because a voice sounds familiar. Do not install software because a pop-up looks urgent. Use official channels, protect your credentials, strengthen workplace payment controls, and call ScamShield at 1799 when in doubt. In 2026, the strongest anti-scam habit is not technical sophistication. It is refusing to let urgency replace verification.