Scam.SG
  • Articles
Report a Scam
  1. Home
  2. Scam Prevention
  3. Fund Recovery Scams in Singapore: The Second Trap After Fun Coffee Losses
Scam Prevention

Fund Recovery Scams in Singapore: The Second Trap After Fun Coffee Losses

Admin
29 August 2026
Fund Recovery Scams in Singapore: The Second Trap After Fun Coffee Losses

Summarise this page with:

ChatGPTCopilotClaudeGrokPerplexity
Share this article:

Losing money to an investment scheme creates exactly the conditions a recovery scammer wants: urgency, embarrassment and a strong need to believe that one more payment could put things right. The second approach may even look more credible than the first. The caller knows the platform name, the amount invested or the victim's contact details. They may present themselves as a claims agent, lawyer, investigator, liquidator or representative of the failed platform.

That is the trap now facing some people affected by Fun Coffee. In its 27 August advisory, the Singapore Police Force (SPF) said fraudsters were claiming to represent Fun Coffee or outside service providers. They offered to recover money, then demanded bank transfers described as deposits, tax payments or fees. No recovery followed.

The warning matters beyond one platform. Recovery fraud, sometimes called a “recovery room” scam, can follow investment, cryptocurrency, job, e-commerce or impersonation scams. The first loss also tells criminals that the target has funds, responds to online approaches and wants a remedy. A leaked customer list, compromised chat group or data shared among criminal networks can make the follow-up unusually personal.

How This Scam Works in Singapore

The first contact usually arrives through WhatsApp, Telegram, SMS, email or a social-media message. It may come soon after a platform stops withdrawals or after victims begin discussing their losses in an online group. The sender says a refund programme, class action, government operation or private recovery process has begun.

The pitch often follows a predictable sequence:

  1. The scammer proves apparent inside knowledge. They quote the name of the failed platform, use a victim's name or refer to an earlier transaction. That information is not proof of authority. It may have come from the original scam operation, a compromised group or data sold to another fraud team.
  2. They manufacture legitimacy. The message may use copied company details, a forged appointment letter, a fake law-firm identity or a website resembling a professional claims service. A Singapore telephone number or UEN displayed on a document does not establish that the sender controls the real entity.
  3. They promise a recoverable balance. The victim is shown a supposed account statement or told that investigators have traced funds. Some offers guarantee a percentage of the loss. Genuine recovery is rarely guaranteed, particularly when money has moved through overseas accounts or cryptocurrency wallets.
  4. They demand money before releasing money. The labels change: security deposit, tax, anti-money-laundering clearance, wallet activation, legal retainer, conversion fee or administrative charge. The core red flag is the same. A stranger says you must send fresh funds to unlock old funds.
  5. The charges multiply. After one payment, another obstacle appears. A “tax authority”, “bank officer” or “compliance department” may join the conversation. Each new payment is framed as the final step.
  6. The scammers seek wider access. Some ask for NRIC images, bank statements, card details, Singpass information, one-time passwords or remote-access software. This can turn an advance-fee fraud into identity theft, account takeover or unauthorised transfers.

Fun Coffee participants were reportedly asked to download an app and transfer Tether, or USDT, to wallet addresses while being offered high returns and recruitment commissions. When users could not withdraw, the recovery story gave scammers a second reason to request money. Cryptocurrency makes the pressure more dangerous because wallet transfers are generally difficult to reverse and may cross jurisdictions quickly.

Do not assume that a contact is genuine because they know your exact loss. That knowledge can be evidence that the recovery approach is connected to the first fraud.

Real-World Impact and Statistics

SPF's Mid-Year Scam and Cybercrime Brief 2026 recorded 16,821 scam cases and about S$410.6 million in losses in the first half of the year. Cases fell 14.4 per cent and losses fell 17.9 per cent compared with the first half of 2025, but the remaining harm was still severe. SPF also found that 80.8 per cent of reported scams involved victims voluntarily transferring money after social engineering.

Investment scams caused the largest losses in the first half of 2026: S$169.8 million across 2,256 cases, according to SPF figures reported by CNA. That works out to an average of roughly S$75,000 per case, although individual losses vary widely. Large initial losses create fertile ground for recovery fraud because a demand for a few thousand dollars can appear small beside the amount a victim hopes to retrieve.

This is not a wholly new method. In February 2024, SPF said at least 29 fund recovery service scam cases had been reported since the start of that year, with losses of at least S$1.2 million. The August 2026 Fun Coffee warning shows that the same method is being adapted to a current scheme and its known victim pool.

The official recovery system looks very different from a private message demanding a fee. In the first half of 2026, the Anti-Scam Centre recovered more than S$97.7 million in scam proceeds and helped avert at least S$127.1 million in potential losses, according to SPF's brief. Those outcomes depend on rapid reports, bank cooperation, tracing and lawful freezes. They are not created by paying an unknown “agent” to release a balance.

Victims can also suffer damage beyond the second payment. Identity documents may be reused to open accounts or support further impersonation. Login details can expose email, cloud storage and social media. A business victim may disclose supplier records, invoices or customer data, creating obligations to assess a possible data breach under Singapore's Personal Data Protection Act (PDPA). Installing malware or allowing unauthorised control of a device may also involve conduct investigated under the Computer Misuse Act.

How to Protect Yourself

Treat every unsolicited recovery offer as high risk, even when it contains accurate personal details. Pause the conversation and verify the claim without using any telephone number, link, email address or website supplied by the sender.

Do not pay to “unlock” a recovery. Taxes are not normally settled by transferring money to a stranger's bank account or cryptocurrency wallet. A demand for a refundable deposit, wallet validation payment or clearance charge is an advance-fee warning sign.

Check the entity and the individual separately. For a claimed Singapore law practice, search the official Legal Services Regulatory Authority directory and call the published office number. For a financial institution, use the MAS Financial Institutions Directory. Search the MAS Investor Alert List as an additional check, while remembering that absence from the list is not proof of approval.

Confirm the communication channel. A real company's name, UEN or employee name can be copied. Type the official website address yourself and use contact details from the official directory. Ask whether the named person works there and whether the recovery programme exists.

Protect accounts before a problem occurs. Enable two-factor authentication for email, Apple ID, Google accounts, financial services and cryptocurrency exchanges. Use unique passwords, set lower transaction limits and activate your bank's security features. ScamShield can filter suspicious calls and messages, but no filter can validate every recovery offer.

Never provide Singpass credentials or OTPs. Singpass does not require you to reveal a password or one-time code to a recovery agent. Do not scan a Singpass QR code sent through an unsolicited conversation. Read the consent screen before approving any Singpass request.

Do not install remote-access apps. A supposed claims officer does not need AnyDesk, TeamViewer or similar software to process a refund. If someone asks to see your banking screen, end the contact.

For SMEs, apply the same payment controls used against business email compromise. Require independent callback verification, dual approval for exceptional transfers and a second reviewer for any payment linked to refunds, litigation or asset recovery. If customer or employee data may have been disclosed, document the incident and assess whether notification duties under the PDPA are triggered.

What to Do If You Are Targeted

If you received an offer but did not pay, stop replying, block the account and preserve the messages. Take screenshots that show the profile, telephone number, wallet address, bank account, website and payment instructions. Report the approach through the relevant platform and seek guidance from ScamShield at 1799.

If you transferred money, call your bank's official fraud hotline immediately. Ask it to stop or recall the transfer and secure affected accounts. Do not wait for the recovery scammer's promised deadline. Then call 1799 and lodge a police report online through SPF's e-services or at a Neighbourhood Police Centre. Call 999 if there is an immediate threat or crime in progress.

If cryptocurrency was sent, contact the exchange used for the transfer without delay. Provide the transaction hash, destination wallet address, time, amount and police report number when available. A blockchain transaction may not be reversible, but prompt reporting can help an exchange or investigators identify and restrict funds that reach a controlled service.

If you shared passwords or OTPs, use a clean device to change the affected passwords and sign out other sessions. Start with email because it can reset many other accounts. Contact the bank, card issuer and cryptocurrency exchange. If remote access was granted, disconnect the device from the internet, remove the software and seek professional technical help before using it for banking again.

Preserve evidence rather than deleting it. Keep chat exports, emails with full headers, receipts, bank references, wallet transaction records, website addresses and copies of documents sent by the scammer. Record what information you disclosed. This gives the bank and police a clearer timeline and helps an SME assess any data exposure.

Common Mistakes to Avoid

The most costly mistake is paying a small “final fee” because it seems proportionate to the original loss. Once paid, it usually becomes proof that another demand may succeed.

Do not rely on testimonials in a recovery group. Scammers can operate several accounts that praise the service, post fake withdrawal receipts and pressure hesitant victims. A video call is not conclusive either; stolen footage, deepfakes and accomplices can create a convincing presentation.

Do not confuse an ACRA registration with regulatory approval. Registration shows that an entity exists in the business registry. It does not automatically authorise investment management, legal practice or fund recovery. Check the regulator or professional directory relevant to the claimed service.

Avoid posting full transaction records, NRIC images or wallet details in public victim groups. These spaces can help people share warnings, but they are also useful hunting grounds for recovery scammers. Redact personal and financial details.

Finally, do not let embarrassment delay a report. SPF and banks handle scam cases every day. Speed matters more than explaining why the first or second payment felt convincing.

FAQ

Is every paid fund recovery service in Singapore a scam?

No, but an unsolicited guarantee of recovery combined with an upfront payment is a serious warning sign. Verify a lawyer through the Legal Services Regulatory Authority, a financial institution through MAS, and any company through independently sourced contact details. Ask for written terms and do not treat a UEN or polished website as sufficient proof.

Why would a recovery scammer know how much I lost?

The original scam operator may reuse or sell victim data. Information may also come from compromised chat groups, public posts, uploaded documents or a second form filled in on a fake recovery website. Accurate details show access to data, not authority to recover funds.

Can MAS, SPF or a bank ask me to pay tax before returning scam money?

Be highly suspicious of such a claim delivered through an unsolicited message. Government officials and banks do not direct people to transfer “clearance” money to personal accounts or crypto wallets. End the contact and call the agency or bank using its official published number.

Can cryptocurrency sent to a recovery scammer be reversed?

Blockchain transfers are generally not reversible by the sender. Contact the exchange and police immediately with the transaction hash and wallet address. Funds may sometimes be traced or restricted when they reach a cooperative exchange, but recovery is not guaranteed.

What should I tell the ScamShield Helpline?

Tell the officer how you were contacted, what the person claimed, whether you paid, what account or wallet received the money and what information you disclosed. ScamShield at 1799 can help assess the situation and direct you to the right next step, but it does not lodge a police report for you.

Should I hire a lawyer after an investment scam?

Legal advice may be useful where the amount is substantial or there are identifiable parties and assets. Choose a lawyer independently through the official Singapore directory, explain the payment trail and ask for a realistic assessment. Be wary of anyone guaranteeing recovery or claiming special access to frozen funds.

What should an SME do if staff sent company or customer data?

Contain access, preserve logs, inform management and assess the nature and scale of the data disclosed. Change credentials and contact affected financial providers. The organisation should also assess its obligations under the PDPA, including whether the incident is a notifiable data breach, and seek legal or cybersecurity advice where needed.

Conclusion

The Fun Coffee warning captures the defining feature of fund recovery scams: fraudsters turn an earlier loss into leverage for a second payment. A convincing name, precise loss figure or professional-looking document does not change the basic test. If an unknown person says you must transfer money before lost funds can be released, stop and verify the claim through official channels.

If you have already engaged with a recovery service, contact your bank immediately, preserve the evidence, call the 24/7 ScamShield Helpline at 1799 and lodge a police report. A prompt report gives legitimate recovery efforts their best chance; another payment to the scammer does the opposite.


For Consumer

  • Search a Company
  • Company Directory
  • Whitelist Directory
  • Virtual Office Directory
  • Company Location Map
  • Report a Scam
  • Submit a Review
  • Flag a Business
  • E-Commerce Abuse Reports
  • Articles & Community
  • Scam Statistics
  • View Scam Types

For Business

  • Verify Your Business
  • What is TrustScore
  • Claim Your Business
  • Certification Partnership
  • Advertise with Us
  • Submit an Article
  • Work with Us
  • Intelligence Services
  • Singapore Standard Industrial Classification

Platform

  • About Scam.SG
  • Watchlist
  • News & Alerts
  • Data Sources
  • Editorial Standards
  • Media
  • Publications
  • Contact Us
  • Sitemap

About Scam.SG

Scam.SG is Singapore's homegrown business trust and anti-scam platform, with authenticity profiles on over 612,000 Singapore-registered businesses. We verify businesses, educate the public on how scams operate, and detect and disrupt scam activity, helping consumers and business associates reduce the risk of falling into a scam. Our analysis uses proprietary algorithms to assess and score Singapore business entities based on publicly available data signals. A lower score does not mean a business is a scam. Visit scam.sg/terminology for definitions of all platform terms.

Disclaimer

Scam.SG is operated by OnScam (SG) Pte. Ltd. We are not affiliated with, endorsed by, or sponsored by any government agency or department. The information provided on Scam.SG (the “Website”) is sourced from publicly available data, including but not limited to ACRA (Accounting and Corporate Regulatory Authority) data from data.gov.sg and other publicly accessible sources. Whilst we strive to ensure the accuracy and reliability of the data presented, we cannot guarantee its completeness or timeliness. Read more at our disclaimer page.


Privacy Policy
Terms & Conditions
Terminology
Disclaimer
Notice & Take Down
Dispute Resolution
Copyright
Sitemap
Scam.SG
© 2026 Scam.SG, operated by OnScam (SG) Pte. Ltd.