• Search Company
  • TrustScore
  1. Home
  2. Scam Prevention
  3. iMessage Courier Phishing Scams in Singapore: The Fake Delivery Trap Costing Victims Over S$1.2 Million
Scam Prevention

iMessage Courier Phishing Scams in Singapore: The Fake Delivery Trap Costing Victims Over S$1.2 Million

Admin
10 August 2026
iMessage Courier Phishing Scams in Singapore: The Fake Delivery Trap Costing Victims Over S$1.2 Million

Summarise this page with:

ChatGPTCopilotClaudeGrokPerplexity
Share this article:

Courier phishing scams work because they arrive at exactly the wrong moment: when people are busy, expecting parcels, and used to clicking delivery updates without thinking too hard. In Singapore, where online shopping, same-day delivery, overseas parcels, document couriers and SME fulfilment are routine, a fake missed-delivery message can feel completely ordinary.

The newest variant is not just another suspicious SMS. SPF has warned that scammers are using Apple iMessage, often from foreign phone numbers or random-looking email addresses, to bypass familiar SMS red flags. The message usually says a parcel cannot be delivered because of an invalid address. It then pressures the recipient to reply, click a link, update delivery details and pay a small fee. That fee is bait. The real target is the victim's card details, internet banking credentials, one-time passwords and digital token approvals.

This matters for more than individual consumers. SMEs in Singapore often receive courier notifications for inventory, samples, contracts, returned goods and customer orders. A staff member who enters company card details on a fake courier page can expose a business account, payment card, device or email inbox. The scam also shows how criminals adapt whenever Singapore strengthens one channel. Sender ID controls and SMS filtering have made some traditional spoofing harder, so scammers shift to iMessage, email-style sender identities and fake websites that look close enough to fool someone in a hurry.

How This Scam Works in Singapore

The scam normally begins with an iMessage that appears to come from a recognised courier brand. SPF's 5 August 2026 advisory noted examples involving names such as DHL, Ninja Van, J&T Express and SingPost. The sender may be a foreign number with a country code such as +212, +63 or +44, or an email address made from random letters and numbers. That mismatch is easy to miss because the message body is written to sound operational: parcel pending, address invalid, delivery failed, update before 6pm, respond within 24 hours.

The message includes a link designed to resemble the courier's real website. Some versions include a local helpline number to make the message feel more credible. Victims are told to reply with a simple character such as "Y" or "1" before they can proceed. This is not harmless. SPF assessed that this step is likely meant to get around iMessage protections that make links from unknown senders harder to open until the recipient interacts with the sender.

After the victim replies, the link becomes clickable. The page that opens usually copies the courier's colours, layout and delivery language, but it is controlled by the scammer. The victim is asked to update their name, delivery address, mobile number or email address. Then comes the redelivery fee, often framed as a tiny payment. Because the amount looks small, victims may lower their guard and enter card details or internet banking credentials.

The dangerous moment is the authentication step. Scammers may ask for an OTP, card security code, bank login, digital token approval or other verification. The victim thinks they are confirming a delivery fee. In reality, the scammer may be adding the card to Apple Pay or Google Pay, provisioning a bank digital token on a new device, logging into the victim's bank account, or preparing a larger unauthorised transaction.

Some victims discover the scam only when they see card charges, unfamiliar device logins or bank account activity. By then, the scammer may already have attempted multiple transactions. That is why this scam belongs in the same risk category as other credential-harvesting phishing attacks: the initial story is about a parcel, but the financial harm comes from account takeover.

For SMEs, the same pattern can be more damaging. A shared office phone, admin inbox or operations staff member may handle dozens of delivery messages a day. If a scammer captures a company card or bank credential, the business may face disputed payments, supplier disruption, internal investigation costs and PDPA concerns if personal data in connected systems is exposed. Where unauthorised access, credential misuse or malware is involved, the Computer Misuse Act may also be relevant to criminal investigations.

Real-World Impact and Statistics

SPF's 5 August 2026 advisory is the strongest recent signal: at least 251 courier iMessage phishing cases were reported from 24 June 2026, with more than S$1.2 million lost. An earlier SPF advisory on 15 July 2026 had already flagged at least 43 cases and more than S$259,000 in losses from the same trend. The jump shows how quickly a phishing format can scale once the scripts, domains and payment flows are working.

The broader context is sobering. SPF's Annual Scam and Cybercrime Brief 2025 reported that scam cases fell 27.6 per cent to 37,308 in 2025, while total scam losses fell 17.9 per cent to about S$913.1 million. That decline is welcome, but it does not mean the threat is fading. SPF also reported 6,264 phishing scam cases in 2025, with losses of S$39.9 million. Phishing remains one of Singapore's most common scam categories because it attacks routine behaviour rather than technical ignorance.

ScamShield's public scam trend page also highlights delivery company impersonation, warning that scammers pretend to be firms such as Ninja Van and SingPost and push victims to fake sites that harvest personal details. ScamShield lists major 2025 loss figures across scam types, including S$39.9 million lost to phishing scams, underscoring that the courier version is part of a much larger credential theft problem.

CSA Singapore has warned that phishing is evolving as AI lowers the cost of deception. In its July 2026 update on Singapore's cyber defences, CSA said AI can help threat actors produce more convincing phishing lures at scale, create realistic voice and video impersonations, and develop tools that target multi-factor authentication. Courier phishing does not need sophisticated deepfakes to work, but AI-written messages can reduce obvious spelling mistakes and make fake notices sound more like legitimate operational updates.

MAS's anti-scam work is relevant because the end point of many phishing scams is a financial account. MAS has continued to sharpen its approach to combatting scams, including banking sector measures, fraud detection and shared responsibility expectations. For consumers, the practical meaning is simple: bank security controls help, but they are strongest when users do not approve suspicious token requests, do not share OTPs, and report quickly enough for banks and the Anti-Scam Command to freeze funds.

How to Protect Yourself

Start with the delivery channel. Courier companies in Singapore generally do not use iMessage as their main customer notification channel. SPF noted that legitimate delivery updates are usually sent through registered Sender IDs, direct delivery calls, SMS, WhatsApp or official courier apps and websites. If a message arrives through iMessage from an overseas number or random email address, treat it as suspicious even if you are expecting a parcel.

Do not click courier links in unsolicited messages. Open the courier's official app or type the official website address into your browser. If you have a tracking number, enter it manually on the courier's official site. If you bought from a marketplace, check the order page inside the marketplace app rather than trusting a message link.

Check the sender and domain carefully. A fake link may use extra words, hyphens, unusual endings or a domain that only looks similar at a glance. Do not rely on logos, page colours or layout. Scammers copy visual design easily. A legitimate brand appearance is not proof that the page is safe.

Refuse unnecessary fees. SPF noted that delivery drivers generally will not ask for payment unless the parcel is cash-on-delivery or the shipment requires GST payment before delivery. J&T Express Singapore, according to SPF's advisory, does not charge parcel redelivery fees. When in doubt, confirm through the courier's official customer service channel.

Turn on iMessage protections. SPF advised members of the public to enable "Filter Unknown Senders" and "Filter Spam" in iMessage. These settings are not perfect, but they add friction and make it easier to separate unknown senders from legitimate conversations.

Use ScamShield. The ScamShield app and website can help users check suspicious calls, messages and links, and the 24/7 ScamShield Helpline at 1799 is available when you are unsure. This is especially useful for seniors, busy staff and family members who may not be confident evaluating a delivery link.

Harden your bank controls. Set lower transaction limits for internet banking and PayNow, enable multi-factor authentication, turn on banking alerts, and learn where your bank's emergency card freeze or account lock function is located. SMEs should avoid using a single shared card for routine courier, marketplace and supplier payments. Where possible, use separate payment limits, staff roles and approval workflows.

Train family members and staff on the exact script. A vague warning such as "beware of phishing" is less useful than a concrete rule: do not reply to iMessages about invalid parcel addresses, do not click delivery links from unknown senders, and do not approve bank tokens for a small redelivery fee.

What to Do If You Are Targeted

If you receive a suspicious courier iMessage but have not clicked the link, do not reply. Take a screenshot if you need to report it, use the in-app reporting function, block the sender and check the parcel status through the courier's official site. You can also check the message or link through ScamShield.

If you clicked the link but did not enter details, close the page. Do not continue just to "see what happens". Clear the browser tab, report the message and monitor your accounts. If you downloaded anything, disconnect the device from the internet and seek help because the risk may have moved from phishing to malware.

If you entered card details, bank credentials, OTPs or digital token approvals, act immediately. Call your bank's fraud hotline and ask them to block the card, suspend suspicious digital tokens, freeze online banking access where necessary and review recent transactions. Do this before arguing with the scammer or trying to recover money through the fake site.

Next, file a police report. If urgent police assistance is needed, call 999. For non-urgent information, SPF directs members of the public to the Police Hotline at 1800-255-0000 or i-Witness. If you are unsure whether a message is a scam, call the ScamShield Helpline at 1799.

Preserve evidence. Save screenshots of the iMessage, sender details, link, fake website, payment page, transaction alerts, OTP prompts and bank notifications. Do not edit the screenshots. If this happened at work, inform your manager, finance lead or IT administrator quickly so they can check whether company payment methods, email accounts or customer data were exposed.

For SMEs, review PDPA exposure. If the fake page or compromised account caused personal data to be disclosed, accessed or at risk, the organisation may need to assess whether notification obligations apply. Even when no notification is required, documenting the incident, containment steps and lessons learned is sensible governance.

Common Mistakes to Avoid

The first mistake is assuming that a small fee means small risk. In courier phishing scams, the fee is the doorway. The real damage can come from card enrolment, bank account takeover or digital token compromise.

The second mistake is trusting a familiar brand name in the message. Scammers can write "SingPost", "DHL" or "Ninja Van" without having any connection to those companies. Brand names in text are claims, not verification.

The third mistake is replying to the unknown sender. In this iMessage variant, the request to reply "Y" or "1" is part of the manipulation. It can make the link easier to open and also tells the scammer that the number is active.

The fourth mistake is approving a digital token request because the screen says it is for verification. Always read what the bank prompt is actually authorising. If the prompt mentions a new device, card provisioning, fund transfer, login or payment method, stop immediately.

The fifth mistake is waiting until morning to call the bank. Scam recovery depends heavily on speed. The faster a victim reports suspicious transactions, the better the chance of freezing funds or preventing follow-on transactions.

The sixth mistake is treating courier phishing as only a consumer issue. Businesses that receive frequent deliveries should include it in finance and operations training. Anyone who handles parcels, invoices, company cards or marketplace orders can become the entry point.

FAQ

Are courier iMessages always scams in Singapore?

Not every message about a parcel is automatically fraudulent, but unsolicited iMessages from unknown numbers or random email addresses should be treated as high risk. SPF has specifically warned that courier companies typically do not use iMessage as their usual communication channel with customers.

What should I do if I am expecting a parcel and receive an invalid address message?

Do not use the link in the message. Open the courier's official app, type the official website address into your browser, or check the marketplace order page where you made the purchase. If needed, contact the courier through an official hotline or verified customer service channel.

Why do scammers ask me to reply before clicking the link?

SPF has said this is likely an attempt to circumvent iMessage's built-in protections for unknown senders. Once you interact with the sender, the link may become easier to open. That is why the reply step itself is a red flag.

Is it safe to pay a small redelivery fee online?

Only pay through an official courier or marketplace channel that you accessed independently. A small amount on a fake page can expose your card details, bank login and digital token approvals. If a fee appears unexpectedly, verify it directly with the courier.

Can ScamShield help with iMessage courier scams?

ScamShield can help users check suspicious messages, calls and links, and the ScamShield Helpline at 1799 is available around the clock when you are unsure. You should still avoid clicking unknown delivery links and report suspicious iMessages through the app's reporting function where available.

What if I already gave my OTP or approved a bank token request?

Call your bank immediately and tell them you may have been phished. Ask them to block affected cards, suspend suspicious tokens, check for unfamiliar devices and stop unauthorised transactions. Then file a police report and preserve all evidence.

Do SMEs need a specific policy for courier phishing?

Yes. SMEs should define who may approve delivery fees, which payment method may be used, how staff verify courier notices, and what to do if a company card or bank credential is entered on a suspicious site. A short internal rule can prevent an expensive incident.

Conclusion

The iMessage courier phishing wave is effective because it hides inside daily life. Singapore residents order parcels, SMEs handle deliveries, and everyone has seen a missed-delivery notice before. Scammers are exploiting that familiarity with urgency, fake courier branding and small payment requests that lead to much larger financial exposure.

The best defence is a strict verification habit. Do not reply to unknown courier iMessages. Do not click delivery links from unsolicited messages. Check parcels through official apps and websites. Use ScamShield, keep bank limits tight, and report quickly if anything feels wrong. The scam may look like a delivery problem, but the real objective is your identity, your card and your bank account.


For Consumer

  • Search a Company
  • Company Directory
  • Whitelist Directory
  • Virtual Office Directory
  • Company Location Map
  • Report a Scam
  • Submit a Review
  • Flag a Business
  • E-Commerce Abuse Reports
  • Articles & Community
  • Scam Statistics
  • View Scam Types

For Business

  • Verify Your Business
  • What is TrustScore
  • Claim Your Business
  • Certification Partnership
  • Advertise with Us
  • Submit an Article
  • Work with Us
  • Intelligence Services
  • Singapore Standard Industrial Classification

Platform

  • About Scam.SG
  • Watchlist
  • News & Alerts
  • Data Sources
  • Editorial Standards
  • Media
  • Publications
  • Contact Us
  • Sitemap

About Scam.SG

Scam.SG is Singapore's homegrown business trust and anti-scam platform, with authenticity profiles on over 612,000 Singapore-registered businesses. We verify businesses, educate the public on how scams operate, and detect and disrupt scam activity, helping consumers and business associates reduce the risk of falling into a scam. Our analysis uses proprietary algorithms to assess and score Singapore business entities based on publicly available data signals. A lower score does not mean a business is a scam. Visit scam.sg/terminology for definitions of all platform terms.

Disclaimer

Scam.SG is operated by OnScam (SG) Pte. Ltd. We are not affiliated with, endorsed by, or sponsored by any government agency or department. The information provided on Scam.SG (the “Website”) is sourced from publicly available data, including but not limited to ACRA (Accounting and Corporate Regulatory Authority) data from data.gov.sg and other publicly accessible sources. Whilst we strive to ensure the accuracy and reliability of the data presented, we cannot guarantee its completeness or timeliness. Read more at our disclaimer page.


Privacy Policy
Terms & Conditions
Terminology
Disclaimer
Notice & Take Down
Dispute Resolution
Copyright
Sitemap
Scam.SG
© 2026 Scam.SG, operated by OnScam (SG) Pte. Ltd.