Scam.SG
  • Articles
Report a Scam
  1. Home
  2. Scam Prevention
  3. DBS and Shopee iMessage Phishing Scams: How Fake Hotlines Steal Your Card Details
Scam Prevention

DBS and Shopee iMessage Phishing Scams: How Fake Hotlines Steal Your Card Details

Admin
4 September 2026
DBS and Shopee iMessage Phishing Scams: How Fake Hotlines Steal Your Card Details

Summarise this page with:

ChatGPTCopilotClaudeGrokPerplexity
Share this article:

Direct Answer

Scammers are sending iMessages that impersonate DBS fraud investigators or Shopee support staff, claim that a transaction is pending, and direct recipients to call a fake hotline. Do not call the number in the message or disclose card details, passwords or one-time passwords; check the transaction in the official app and contact the organisation through its verified website or the number on your card.

Introduction

An alert about an unfamiliar purchase can make anyone act quickly. That reaction is exactly what the latest phishing campaign is designed to exploit.

On 2 September 2026, the Singapore Police Force (SPF) warned about phishing scams sent through Apple iMessage. The senders pose as DBS fraud investigators or Shopee e-commerce support personnel. Their message claims that a pending transaction needs urgent verification and supplies a telephone number to call. The number does not lead to DBS or Shopee. It leads to the scammer.

The call is the real trap. A fake support agent says that the recipient's payment card has been compromised, then asks for card information and one-time passwords (OTPs) under the guise of cancelling the transaction or securing the account. Those details can be used for unauthorised card payments, bank-account activity or access to an e-commerce account.

This variant deserves attention because it does not need a suspicious-looking web link. Many people have learnt not to tap links in unsolicited SMS messages, but may still call a displayed number. An iMessage can also arrive from an email address or Apple account rather than an ordinary mobile number, making familiar SMS sender-ID cues less useful.

The safest response is simple: leave the message, open the DBS or Shopee app yourself, and verify the claim there. If help is needed, use a contact number taken from the official website, the banking app or the back of the payment card.

How This Scam Works in Singapore

The SPF advisory describes a short, believable sequence.

First, the target receives an unsolicited iMessage. The message appears to come from a bank fraud team or e-commerce support desk and refers to a pending card transaction. It creates pressure by implying that a quick response is needed to stop a charge.

Second, the message asks the recipient to call a hotline. The absence of a clickable phishing link may make the message feel safer, but the telephone number is controlled by the scammer. A professional greeting, local accent or convincing explanation does not make it genuine.

Third, the caller is told that their card details have been compromised. The supposed investigator asks for the card number, expiry date, security code, account credentials or OTP. The scammer may say the information is required to verify ownership, reverse a payment or protect the account.

Fourth, the stolen details are used. The victim may later discover unauthorised transactions on a card or bank account, or an unauthorised login to a Shopee account. An OTP is an approval code, not an identity-check answer. Anyone asking you to read it aloud is asking for the ability to authorise an action.

The impersonated brands fit the script. DBS is a major Singapore bank, while Shopee is widely used for online shopping. A message about a card payment on a familiar platform is plausible even when the recipient has not recently shopped there. Scammers do not need to know that the target is a DBS customer or Shopee user; they can send the same bait widely and wait for a match.

This is phishing even though the decisive interaction happens by telephone. The message establishes a false identity and directs the target into a controlled channel where credentials are harvested. SPF advises treating any unsolicited message or call requesting OTPs, passwords or banking credentials as suspicious.

Real-World Impact and Statistics

SPF did not state a case count or loss figure for the specific DBS-and-Shopee variant in its 2 September advisory. That distinction matters: figures from other iMessage campaigns should not be presented as losses from this exact scheme.

The broader picture shows why the warning is serious. According to SPF's mid-year crime statistics, Singapore recorded 16,821 scam cases in the first half of 2026. That was 14.4 per cent fewer than in the first half of 2025. Reported losses fell 17.9 per cent to about S$410.6 million, but scams remained the country's predominant crime type.

SPF also reported that 80.8 per cent of scam cases in the first half of 2026 involved self-effected transfers. Manipulation rather than a purely technical breach remained central to most cases. The current iMessage scheme differs because stolen card details and OTPs can lead to unauthorised transactions, but the social-engineering principle is the same: the scammer persuades the target to defeat a security control.

E-commerce scams were the most common scam type in the first half of 2026. Investment scams caused the largest losses, at S$169.8 million or 41.4 per cent of total scam losses. These figures do not measure the new DBS-and-Shopee campaign, but they show the scale of fraud surrounding online commerce, payments and impersonation in Singapore.

For individuals, the harm can extend beyond one card charge. Stolen credentials may expose transaction history, saved addresses or account information. Reused passwords can put other services at risk. For SMEs, a compromised staff card or marketplace account can disrupt purchasing, advertising and customer service, while an apparent support call may reach an employee authorised to make payments.

Singapore's Personal Data Protection Act (PDPA) requires organisations to protect personal data in their possession or control. It does not require a customer to give sensitive information to an unsolicited caller. Likewise, unauthorised access to an account may engage the Computer Misuse Act, but legal remedies after an offence are no substitute for cutting off the scam before credentials are disclosed.

How to Protect Yourself

Do not use the contact route supplied in the alert. If an iMessage claims that a DBS or Shopee transaction is pending, do not call its number. Open the official DBS digibank or Shopee app from your device's home screen. Check transactions and notifications there. If you need to call, obtain the number from the official website, app or back of your card.

Keep OTPs private. A bank or legitimate service provider will not need you to read an OTP over an unsolicited call. Read the full OTP message before doing anything; it usually states what action or amount the code will approve. If you did not initiate that action, do not enter or disclose the code.

Do not confirm partial information. A caller may already know your name, telephone number or the last digits of a card. Such details can come from previous data leaks, social media or another compromised account. They do not prove that the caller represents DBS, Shopee, MAS or SPF.

Use controls that limit damage. Turn on instant transaction notifications, set sensible card and transfer limits, and use two-factor authentication. Review saved cards in shopping accounts and remove those no longer needed. Businesses should issue cards with low limits for routine marketplace purchases and require a second person to approve unusual payments.

Use iPhone filtering and reporting tools. Apple's “Filter Unknown Senders” setting can separate messages from people not in your contacts. Use the in-app report function for junk or suspicious messages where available. Filtering reduces exposure, although it cannot decide whether every message is genuine.

Check suspicious messages with ScamShield. The ScamShield app and scamshield.gov.sg provide Singapore-specific scam information and checking tools. The 24-hour ScamShield Helpline at 1799 can help if you are unsure whether a contact is genuine.

Protect accounts with unique passwords. A password manager makes it easier to use a different password for DBS-related services, email, Apple ID and Shopee. If one account is compromised, password reuse can turn a single incident into several account takeovers.

Give staff a verification script. SMEs should tell employees to stop any call involving credentials, OTPs or urgent card action. The employee should independently call the bank or platform through an approved number. This removes guesswork during a pressured conversation.

What to Do If You Are Targeted

If you received the message but did not call or disclose anything, take a screenshot for reporting, block or report the sender, and delete the message after preserving what you need. Check the relevant account through the official app. Do not reply, as a response confirms that the account is active.

If you called but gave no sensitive information, end the call. Do not accept a return call from the same “agent”. Contact DBS or Shopee independently and explain what happened, especially if you confirmed account details that could help a later impersonation attempt.

If you disclosed card information, credentials or an OTP, act immediately:

  1. Call your bank's official fraud hotline and ask it to block the card, secure the account and review pending transactions. Use the number on the card or official website.
  2. Use the bank's emergency self-service or “kill switch” function if available. Do not wait to see whether a transaction appears.
  3. Change the affected account password from a trusted device. Change any other account that reused the same password, starting with your email and Apple ID.
  4. Contact Shopee through its official app if the e-commerce account may be compromised. Review logged-in devices, orders, saved payment methods and delivery addresses.
  5. Call the ScamShield Helpline at 1799 for guidance. Make a police report and retain the message, sender details, telephone number, call time, transaction records and any case reference from the bank.
  6. Monitor statements and notifications. Tell the bank promptly about each transaction you do not recognise.

The Monetary Authority of Singapore (MAS) and IMDA's Shared Responsibility Framework covers defined phishing-scam scenarios and assigns duties to financial institutions and telcos. It is not an automatic guarantee that every scam loss will be reimbursed. Report quickly and provide complete evidence so the bank can assess the case under the applicable rules.

Common Mistakes to Avoid

Calling “just to check”. The number is part of the scam. Once connected, the caller can apply pressure and collect information even if no OTP is disclosed.

Trusting the brand name or profile image. Display names, logos and account pictures can be copied. Verify through a channel you found independently.

Assuming iMessage is proof of legitimacy. Encryption protects delivery between Apple users; it does not certify that a sender is DBS or Shopee.

Reading an OTP without checking its purpose. The wording often reveals that the code approves a purchase, login or wallet enrolment. A supposed fraud investigator does not need the code to cancel a transaction.

Waiting until business hours. Fraud moves quickly. Banks maintain emergency reporting channels, and ScamShield 1799 operates around the clock.

Deleting everything too early. Preserve screenshots, call records and transaction details before blocking the sender. Evidence helps the bank and SPF trace the incident.

Blaming the victim instead of fixing the process. These messages are built to trigger a fast response. Families and SMEs are better protected by a clear rule: stop, open the official app, and make an independent call.

FAQ

How can I tell whether a DBS fraud alert is genuine?

Do not decide from the message's appearance alone. Check your DBS account through the official digibank app and contact DBS using the number on your card or its official website. Never use a telephone number supplied in an unsolicited iMessage.

Will DBS or Shopee ask for my OTP to cancel a transaction?

No legitimate fraud investigator or support agent should ask you to disclose an OTP over an unsolicited call. An OTP authorises a specific action. If you did not initiate that action, do not share or enter it.

Is it safe to call the number if I do not reveal my card details?

No. Calling exposes you to a social-engineering script and may confirm that your iMessage account is active. Verify the claim using the official app or an independently sourced contact number.

What if the message contains no link?

It can still be phishing. In this variant, the fake hotline replaces the fake website. The scammer harvests credentials during the telephone call.

Does the +65 prefix make the sender or hotline genuine?

No. A Singapore-looking number is not proof of identity. Caller information can be manipulated, and online messaging accounts may not use ordinary mobile numbers at all.

What should an SME do if an employee disclosed a company card OTP?

Contact the issuing bank immediately, block the card, review pending transactions and preserve evidence. Reset any affected marketplace or email credentials, notify the appropriate internal security or finance contact, and make a police report. Review approval limits and staff verification procedures after the immediate incident is contained.

Can I obtain reimbursement under Singapore's Shared Responsibility Framework?

The framework applies to specified phishing scenarios and sets duties for financial institutions and telcos. Outcomes depend on the facts and whether relevant duties were breached. Report the incident promptly to the bank and provide all available evidence; do not assume reimbursement is automatic.

Conclusion

The latest DBS and Shopee iMessage scam turns a familiar safety warning on its head. There may be no link to tap. The dangerous instruction is the request to call a number controlled by the scammer.

Treat every unexpected transaction alert as a prompt to check independently, not to follow the message. Open the official app, use a verified contact number, and keep card credentials and OTPs to yourself. If you have already disclosed information or see an unauthorised transaction, contact your bank immediately, secure the affected accounts, call ScamShield at 1799 and make a police report.

Sources: Singapore Police Force advisory dated 2 September 2026; SPF Mid-Year Crime Statistics 2026; MAS and IMDA Shared Responsibility Framework; ScamShield Singapore; PDPC guidance.


For Consumer

  • Search a Company
  • Company Directory
  • Whitelist Directory
  • Virtual Office Directory
  • Company Location Map
  • Report a Scam
  • Submit a Review
  • Flag a Business
  • E-Commerce Abuse Reports
  • Articles & Community
  • Scam Statistics
  • View Scam Types

For Business

  • Verify Your Business
  • What is TrustScore
  • Claim Your Business
  • Certification Partnership
  • Advertise with Us
  • Submit an Article
  • Work with Us
  • Intelligence Services
  • Singapore Standard Industrial Classification

Platform

  • About Scam.SG
  • Watchlist
  • News & Alerts
  • Data Sources
  • Editorial Standards
  • Media
  • Publications
  • Contact Us
  • Sitemap

About Scam.SG

Scam.SG is Singapore's homegrown business trust and anti-scam platform, with authenticity profiles on over 612,000 Singapore-registered businesses. We verify businesses, educate the public on how scams operate, and detect and disrupt scam activity, helping consumers and business associates reduce the risk of falling into a scam. Our analysis uses proprietary algorithms to assess and score Singapore business entities based on publicly available data signals. A lower score does not mean a business is a scam. Visit scam.sg/terminology for definitions of all platform terms.

Disclaimer

Scam.SG is operated by OnScam (SG) Pte. Ltd. We are not affiliated with, endorsed by, or sponsored by any government agency or department. The information provided on Scam.SG (the “Website”) is sourced from publicly available data, including but not limited to ACRA (Accounting and Corporate Regulatory Authority) data from data.gov.sg and other publicly accessible sources. Whilst we strive to ensure the accuracy and reliability of the data presented, we cannot guarantee its completeness or timeliness. Read more at our disclaimer page.


Privacy Policy
Terms & Conditions
Terminology
Disclaimer
Notice & Take Down
Dispute Resolution
Copyright
Sitemap
Scam.SG
© 2026 Scam.SG, operated by OnScam (SG) Pte. Ltd.