A convincing Facebook advertisement can still lead to a fake shop. An Instagram page that looks like a familiar personality can still sell a fictitious investment. Singapore police and Meta say they took action against nearly 3.8 million scam-linked entities, pages and accounts on the two platforms in 2026. That is a measure of disrupted online infrastructure, not a count of Singapore victims or proof that every suspicious ad has disappeared.
The practical rule is simple: treat an ad as a lead to check, not a reason to pay. Leave the platform, find the seller or institution through its own independently verified channel, and check the destination for your money before you transfer it. The same rule matters to SMEs buying from unfamiliar vendors and to businesses whose names or staff photos may be copied into fake promotions.
How Social-Media Scam Ads Work in Singapore
In a 23 September 2026 announcement, the Singapore Police Force (SPF) described several leads it referred to Meta: accounts impersonating social-media influencers to promote fictitious investments; concert-ticket offers; and food or other goods advertised at exceptionally low prices. The common move is to borrow trust from something familiar: a person, a brand, a desirable product or the apparent legitimacy of a paid placement.
A shopping ad might take you to a site that resembles a retailer, or into a direct-message conversation where the seller asks for a bank transfer before dispatch. For tickets, a seller might say availability is limited and demand an immediate deposit. In an investment pitch, the page may use a recognisable face and invite you to contact an account claiming to offer a special opportunity. These are warning scenarios based on the categories SPF identified, not claims about a particular account or a verified victim’s individual experience.
The payment instruction is often more revealing than the attractive creative. Is the payee an unrelated individual? Does the supposed company refuse to invoice you through its normal channel? Does the person asking for payment tell you not to call the business directly? Stop there. A polished page, a large following or a sponsored label does not authenticate the seller or the bank account.
There is another layer. SPF says Meta found interconnected pages behind individual leads, including dormant “shell pages” built for possible later use. A page that appears empty today may be repurposed. Equally, the appearance of an old page is not proof that its current operator is genuine. Check the particular offer, URL, payee and contact details each time rather than relying on the age of a profile.
What the SPF–Meta Figures Actually Show
SPF said it referred more than 20,000 Meta accounts, pages and pieces of content for disruption between January and June 2026. Meta then investigated related networks, rather than considering each referral in isolation. According to the joint announcement, Meta removed or restricted more than 113,000 entities and pages connected to fraud and scams in the first half of the year. A June operation dealt with more than 33,600 entities associated with investment, deceptive e-commerce and other fraud types. In July, Meta removed more than 3.64 million shell pages that had not yet been used to conduct scams, SPF said. The agencies described the overall action as affecting nearly 3.8 million scam-linked entities, pages and accounts in 2026.
These figures refer to different categories and operational periods. Do not add them together to estimate how many people were targeted, or assume that 3.8 million completed frauds occurred in Singapore. The shell-page figure is especially important: those pages were described as pre-built infrastructure removed before use, not as 3.64 million successful scams. The distinction makes the enforcement result more intelligible and prevents a frightening but false interpretation of the headline number.
For a separate view of real-world harm, a 24 September SPF release said 259 people were assisting with investigations after a two-week islandwide operation. Preliminary investigations linked them to more than 648 cases, mainly involving e-commerce, phishing, job, government-official impersonation, investment and lucky-draw scams; victims reportedly lost around S$5.2 million. This is an investigation report, not an outcome or a breakdown of losses caused by Facebook and Instagram ads. Keep the two announcements separate.
How to Protect Yourself Before You Pay
Start outside the advertisement. Search for the seller’s official website yourself instead of following a link in the ad. If a shop claims to have a physical Singapore presence, check its published address and contact number independently. For a registered business, look up the entity in ACRA’s Bizfile records and make sure the name on the invoice and payment instruction is consistent. ACRA registration establishes an entity record; it does not guarantee that a social-media account belongs to that entity or that a particular offer is safe.
Check regulated investment claims at the source. If an ad promises returns or invokes a financial institution, use the MAS Financial Institutions Directory and Investor Alert List as appropriate. Search for the precise legal name and verify the contact channel on the institution’s own site. An omitted alert-list entry is not a seal of approval, and a real licensed firm can still be impersonated. Do not send money because a page shows a familiar name or a screenshot of supposed earnings.
Inspect the payment route. A seller moving you from a public ad to an unfamiliar messaging account, asking for payment to a personal account, or pressuring you to bypass a marketplace’s checkout and buyer protections deserves closer scrutiny. A genuine seller can explain who receives the payment, what is being supplied and how delivery or refunds work. Retain the listing URL, screenshots, invoice and payment details before paying, especially for an expensive item or bulk SME purchase.
Verify tickets without rushing. For concerts or events, use the organiser’s announced ticketing channel. A photograph of a ticket, a claim of “last pair available”, or a profile with many likes is not evidence that a ticket can be transferred or that the seller has it. If the offer exists only in a direct message, confirm the organiser’s rules and the platform’s transfer process before parting with money.
Protect your business identity too. SME owners should periodically search for copies of their business name, logo and staff profiles on Facebook and Instagram. Tell customers which accounts and payment methods are official on your own website and receipts. If you find an impersonator, preserve the profile URL and screenshots, report the account to the platform and warn customers through channels you already control. Do not send a warning that repeats the fake link without context; it can drive more people to the fraudulent page.
What to Do If You Have Already Responded
If you have paid, call your bank’s fraud hotline immediately through its official app, website or the number on your card. Give the bank the recipient details, transaction time and amount, and ask what urgent steps it can take. Recovery is not guaranteed, but delay reduces the options available. If you provided online-banking credentials or an OTP, tell the bank exactly what you disclosed and follow its instructions to secure access; change passwords from a trusted device.
Keep evidence: the advertisement and account URL, messages, payment confirmation, phone numbers and any site address. Report the incident to the police and report the ad or account within Facebook or Instagram so the platform can investigate. For uncertainty about a suspicious message, link or offer, use the ScamShield app or helpline at 1799; SPF describes the helpline as available 24/7. ScamShield can help you assess a possible scam, but it is not a substitute for contacting your bank urgently after a payment.
If your company’s name has been used, keep a dated record of affected pages and customer reports. Contact your payment provider if someone is routing victims to an account deceptively presented as yours. Use your existing customer channels to publish a short correction with the exact official domain and payment policy. Avoid asking customers to send you OTPs or full banking details to “verify” a complaint; that would copy the scammer’s pattern.
Common Mistakes to Avoid
The first is assuming that takedown numbers make the platform safe by default. Meta’s large enforcement operation shows that investigations can identify connected networks, but new ads and accounts can still appear. Judge the particular transaction, not the platform’s overall reputation.
The second is confusing a real business with a real advertisement. An impersonator can copy a genuine Singapore company’s branding or an influencer’s photos. Even a correct ACRA record or MAS licence cannot establish who controls the social page or where a bank transfer goes. Compare the account and payment details with independently found official details.
The third is treating a small initial purchase as proof of safety. An early delivery or apparently successful withdrawal does not guarantee the next transaction. For SMEs, a familiar-looking vendor who suddenly changes bank details should trigger a call to a previously verified contact, not a reply to the message announcing the change.
Finally, do not keep negotiating with a suspicious seller to “recover” a deposit by sending a further fee. Save the conversation and move the issue to your bank, the platform and the police. No one can promise to retrieve a transfer merely by contacting you in a comment or direct message.
FAQ
Were 3.8 million Singaporeans scammed on Facebook and Instagram?
No. SPF and Meta reported action against nearly 3.8 million scam-linked entities, pages and accounts in 2026. The total includes more than 3.64 million shell pages removed before they were used for scams. It is not a victim count or a measure of money lost.
Does a sponsored label mean an advertisement has been verified?
No. It indicates a paid placement, not that the seller, its claims or its bank account has been authenticated for your transaction. Check the trader and payment route independently before paying.
How do I check an investment advertisement that uses a familiar personality?
Do not contact the account in the ad. Look up the financial firm’s precise legal name using the MAS directory, check relevant MAS alerts and reach the firm through a number or website you located independently. A real person’s photograph does not authorise the offer.
Can an ACRA record prove a social-media shop is genuine?
No. It can help confirm that an entity exists, but a scammer may impersonate a registered business. Match the account, domain, invoice and recipient details with the company’s independently published channels.
What if I clicked an ad but did not pay?
Do not enter any further credentials or card details. If you entered a password, change it through the real service and review account security. If you downloaded a file or granted unusual permissions, stop using the affected device for banking until you have assessed it. Check the link or message with ScamShield and report the suspicious account to the platform.
Who should I contact after transferring money?
Call your bank’s official fraud hotline immediately, then make a police report with the ad URL, account details and payment records. You can call ScamShield at 1799 for guidance if you are unsure whether the approach was a scam. Do not rely on the account that advertised the offer to resolve the loss.
Conclusion
The SPF–Meta operation removed or restricted a large network of scam-linked online assets, including pages prepared for future use. It does not remove the need to check the next ad in your feed. Before paying for an investment, ticket or online purchase, verify the real seller or institution through an independent channel and confirm the recipient of the money. If you have already transferred funds, call your bank first; for a suspicious approach you are still assessing, call ScamShield on 1799.