A call from a Singapore-looking number can feel more trustworthy than an overseas call, especially when the caller knows your name, cites a bank account, mentions your NRIC, or says a government agency is investigating you. That is exactly why government official impersonation scams remain dangerous. The fraud is not built around a clever technical exploit alone. It is built around fear, authority and the instinct to comply when someone claims to represent the state.
The latest variant highlighted by the Singapore Police Force involves scammers calling from unknown eight-digit telephone numbers beginning with 3. The caller may first pretend to represent a bank, financial institution or telecommunication company. Once the victim is worried, the call escalates. A second scammer may claim to be from the police, MAS, a ministry, a court or another official body. The victim is accused of money laundering, unauthorised loans, illegal phone-line use or involvement in a criminal case. From there, the scammer tries to control the victim's next steps.
For residents, this can lead to immediate financial loss. For SMEs, it can also disrupt payroll, supplier payments and customer trust if an employee is tricked into disclosing corporate banking access or transferring funds from a business account. Scam-prevention educators should treat this as a high-priority teaching topic because the scam copies real administrative language, uses social engineering across multiple calls, and exploits Singaporeans' familiarity with verification and compliance procedures.
How This Scam Works in Singapore
The scam usually begins with an unsolicited phone call. In the July 2026 advisory, SPF described callers using unknown eight-digit numbers that begin with 3. That detail matters because many people have learned to be cautious of overseas numbers, but may still answer a local-looking number without the same level of suspicion. The number is not proof that the call is safe. Scammers can use call-routing methods, compromised lines or other infrastructure to create a convincing first impression.
The first caller often adopts a commercial identity: a bank officer, telco representative, financial institution employee or customer service agent. The issue sounds urgent but plausible. The victim may be told that a phone line registered under their name is linked to criminal activity, that their bank account is involved in suspicious transactions, or that there is an unresolved compliance matter. This stage is designed to make the victim anxious and willing to be transferred.
The second stage is the authority handover. The scammer says the case must be referred to a government official, police officer, MAS officer, MinLaw officer or foreign law enforcement agency. The victim may then receive another call, a video call, a messaging app instruction, or a fake document. Some versions use official-looking badges, case numbers, forged letters, deepfake-style video or screenshots of government web pages. The goal is to make the victim believe the situation is already formal and serious.
Once fear has been established, the scammer moves to control. The victim may be told not to speak to family members, bank staff or police officers because the matter is confidential. They may be instructed to keep the call active while travelling to a bank branch or ATM. They may be told to move money into a "safe account", hand cash or valuables to a courier, buy cryptocurrency, install a remote access app, disclose Singpass or bank login details, increase transfer limits, or verify identity through a link. Every one of these instructions is a red flag.
Singapore Government officials do not ask members of the public to transfer money, disclose bank login details, install apps from unofficial sources, hand over valuables, or continue a call that is supposedly transferred to the police. MAS officials will not ask you to move funds to protect an account. SPF officers will not direct you to send money to prove innocence. A real investigation may be serious, but it will not be handled through secretive payment instructions over an unsolicited call.
The same tactics can be aimed at SMEs. A caller may claim to be from a regulator, bank compliance department, telco or enforcement unit and ask a finance staff member to urgently verify corporate credentials. A smaller company without written approval protocols is especially vulnerable because one frightened employee may believe that speed is more important than verification.
Real-World Impact and Statistics
SPF's July 2026 advisory said at least 12 cases involving this phone-number variant had been reported since May 2026, with losses of approximately S$274,000. The Straits Times also reported that police were warning the public about scam calls from numbers starting with 3, underlining how quickly a narrow phone tactic can become a public-risk issue.
The larger trend is more troubling. In Singapore's 2025 scam and cybercrime statistics, SPF reported that total scam cases fell to 37,308 and total losses fell to about S$913.1 million, but the median loss per case still rose to S$1,644. That means fewer reports did not translate into a low-risk environment. Scammers are becoming more selective, more persuasive and more capable of extracting larger sums from victims who do engage.
Government official impersonation scams were among the biggest concerns in 2025. CNA reported from SPF's annual figures that losses from government official impersonation scams surged 60.5 per cent to about S$242.9 million in 2025. This category ranked behind investment scams by loss amount, which is not reassuring. It shows that impersonation scams can produce life-changing losses because victims are pushed to transfer savings, liquidate assets or surrender valuables under pressure.
Recent Singapore coverage also shows that agencies are changing public-facing practices because of impersonation risk. CNA and The Straits Times reported in August 2026 that Singapore removed many public officers' contact details from the Singapore Government Directory to reduce the risk of scammers harvesting names, emails and office phone numbers for phishing or impersonation. That move is a reminder that scam prevention is not only an individual responsibility. Institutions are also reducing exposed information because criminals are turning public data into social-engineering fuel.
The impact is not only financial. Victims may feel shame, anxiety and fear of legal consequences even after the scam is exposed. Families may argue over why money was transferred. SME employees may worry about disciplinary action. In severe cases, a compromised device or disclosed credential can create follow-on risks under the Computer Misuse Act framework, PDPA obligations for organisations, and bank fraud investigations. The practical lesson is blunt: the earlier the call is interrupted and independently verified, the better the chance of limiting harm.
How to Protect Yourself
Treat unsolicited authority calls as unverified until you have checked them through official channels. If a caller says they are from SPF, MAS, a ministry, a bank, a telco or a court, do not use the callback number, link or messaging account they provide. End the call and contact the organisation through its official website, app, branch number or hotline. If you are unsure whether something is a scam, call the 24/7 ScamShield Helpline at 1799.
Do not transfer money to a "safe account". The phrase itself is a major warning sign. Singapore Government officials and MAS officers will not ask you to move money to protect it, prove innocence or assist an investigation. Banks may freeze or restrict accounts through formal channels, but they will not ask you to transfer savings to an account controlled by a stranger.
Never disclose bank login details, card PINs, OTPs, Singpass credentials, security questions or corporate payment tokens over a call. A caller who already knows your name or partial NRIC is not necessarily legitimate. Personal data can come from leaks, social media, old forms, scraped directories, compromised accounts or earlier phishing attempts. Under the PDPA, organisations must protect personal data, but individuals should still assume that some personal details may be available to criminals.
Refuse app-installation instructions. CSA Singapore and SPF repeatedly warn against installing apps from unofficial sources or allowing remote access tools on your device. A scammer who gets you to install malware can read messages, steal credentials, alter banking limits, intercept OTPs or hide ScamShield and Singpass-related protections. Use only official app stores and official organisation websites.
For SMEs, create a written call-verification rule. Any request involving banking credentials, payment changes, account freezes, law enforcement, regulatory checks or supplier bank details should trigger a pause. Require staff to verify through a separate known channel and obtain approval from at least two authorised people before transferring funds or changing payment details. This is not bureaucracy for its own sake. It gives employees permission to slow down when a caller is manufacturing urgency.
Use ScamShield and bank controls as layers, not as magic shields. Install ScamShield, report suspicious messages and calls, set lower transfer limits where practical, activate bank notification alerts, and know how your bank's emergency "kill switch" works. MAS's anti-scam efforts and the Shared Responsibility Framework reinforce the importance of financial institutions and telcos acting responsibly, but customers and businesses still need strong verification habits.
What to Do If You Are Targeted
If you are still on the call, hang up. Do not argue, explain, threaten or keep listening "just to check". Scammers are trained to recover control when victims hesitate. Once you end the call, take a breath and verify through official channels.
If no money or credentials were shared, report the suspicious call through ScamShield so the information can help detection and disruption. Warn family members, colleagues or finance staff if the call involved your workplace or someone else's details. For elderly relatives, the fastest protection may be a direct conversation: tell them that government officers will not ask for transfers, banking details or app installations over the phone.
If you transferred money, disclosed credentials, installed an app or handed over valuables, act immediately. Contact your bank's fraud hotline and ask for urgent blocking, account review or transaction recall where possible. Use the bank's official hotline, app or branch, not any number given by the caller. If your phone may be compromised, use another device to contact the bank.
File a police report and provide the caller numbers, bank account details, transaction receipts, screenshots, messages, app names, courier details, and any instructions received. You can call the Police Hotline at 1800-255-0000, submit information through SPF's i-Witness portal, or dial 999 if urgent assistance is needed. For scam-related doubts and guidance, call ScamShield at 1799.
If you installed a suspicious app, disconnect the device from the internet, do not continue using it for banking, and seek technical help. Change passwords from a clean device. Revoke suspicious device sessions in banking, email, social media and Singpass where applicable. SMEs should treat the incident as a security event: preserve logs, inform management, check whether personal data or corporate credentials were exposed, and assess whether PDPA breach notification obligations may be triggered.
Common Mistakes to Avoid
The first mistake is believing that a local-looking number is proof of legitimacy. A number starting with 3 may look ordinary, but SPF's July 2026 advisory shows why Singapore residents should not rely on caller ID alone. Caller identity must be verified independently.
The second mistake is staying on the line because the caller sounds calm, educated or familiar with official language. Scammers are not always crude. The more profitable variants use scripts, staged transfers, official terminology and psychological pressure. A polished caller can still be a criminal.
The third mistake is obeying confidentiality instructions. Real officials do not require you to hide urgent financial instructions from your family, employer, bank or the police. Isolation is a scam tactic. If a caller says you must not tell anyone, that is the moment to tell someone.
The fourth mistake is treating a small first transfer as harmless. Scammers often ask for a modest "verification" transfer, then escalate once the victim complies. The first successful instruction proves obedience. After that, the pressure increases.
The fifth mistake is blaming the victim instead of fixing the process. Families and SMEs need reporting cultures that encourage quick disclosure. A victim who fears humiliation may delay contacting the bank, and delay can reduce the chance of freezing funds. Prevention works better when people know they can speak up early.
FAQ
Are all Singapore phone numbers starting with 3 scam numbers?
No. The warning is not that every number starting with 3 is fraudulent. The point is that SPF identified a scam variant where unknown eight-digit numbers beginning with 3 were used by impersonators. Treat such calls as unverified, especially if the caller mentions crime, banking, government agencies, transfers or secrecy.
Will SPF, MAS or another Singapore Government agency ask me to transfer money by phone?
No. Singapore Government officials, including police and MAS officers, will not ask you to transfer money, hand over valuables, disclose banking login details, install unofficial apps, or move funds into a "safe account" over a phone call. End the call and verify independently.
What should I do if the caller knows my NRIC, address or bank name?
Do not treat that as proof. Personal information can be obtained from data leaks, old records, social media, phishing, compromised accounts or previous scam attempts. Ask yourself what the caller is requesting. If they want money, credentials, secrecy, app installation or remote access, stop and verify through official channels.
How can SMEs protect finance staff from this scam?
SMEs should use written payment controls: no urgent transfer based only on a phone call, no credential disclosure, no payment-limit increase without approval, and no bank-detail change without verification through a known channel. Train staff that they are allowed to pause even when a caller claims to be from a regulator, bank or police unit.
Should I call the number back to check whether it is real?
No. Do not use the number provided by the caller or shown in a suspicious message. Look up the organisation's official contact details yourself through its website, official app or known hotline. For uncertainty about scams, call ScamShield at 1799.
What if I already transferred money?
Contact your bank immediately through its official fraud hotline or app and request urgent assistance. Then file a police report and preserve all evidence, including screenshots, transaction records, phone numbers and messages. Speed matters because banks and SPF's Anti-Scam Command have a better chance of disrupting funds when victims report quickly.
Conclusion
Government official impersonation phone scams work because they borrow the language of compliance, investigation and public authority. The July 2026 warning about calls from numbers starting with 3 should be treated as a practical reminder: caller ID, official-sounding scripts and personal details are not verification.
The safest response is simple and disciplined. Hang up, verify through official channels, refuse transfers and app installations, protect credentials, and contact ScamShield or your bank quickly when something feels wrong. For households and SMEs, the strongest defence is a culture where pausing is normal, verification is expected, and nobody is punished for raising the alarm early.