Scam victims in Singapore are not confined to one age group: adults aged 30 to 49 formed the largest share of victims in the Singapore Police Force's 2025 scam data, while seniors aged 65 and above suffered the highest average loss per victim. Prevention works best when it is tailored to how each group is approached, whether through social media, messaging apps, phone calls, e-commerce platforms, fake investment groups or work-related payment requests.
Introduction
The most dangerous myth about scams in Singapore is that only careless or elderly people fall for them. That myth is comfortable, and therefore useless. The latest Singapore scam data shows a broader reality: working adults, young adults, seniors, SME employees, parents, job seekers and online sellers are all being targeted, but in different ways.
According to the Singapore Police Force Annual Scam and Cybercrime Brief 2025, total scam cases fell by 27.6 per cent to 37,308, while total scam losses fell by 17.9 per cent to about S$913.1 million. That decline matters. It suggests that stronger platform controls, bank intervention, ScamShield reporting, public education and enforcement are having some effect. But the same data also shows why Singapore cannot treat scam prevention as a single public message repeated to everyone. The people reporting the most cases are not always the people losing the largest sums. The channel used to reach a student is not necessarily the channel used to manipulate a retiree. The story told to a finance executive will not sound like the story told to a parent on Facebook Marketplace.
Singapore's anti-scam ecosystem is deliberately broad: SPF investigates and coordinates enforcement through the Anti-Scam Command, ScamShield provides a public reporting and checking layer, MAS and IMDA oversee duties for financial institutions and telcos in phishing-scam controls, CSA Singapore promotes cyber hygiene, PDPC reminds organisations and individuals to protect personal data, and banks now offer features such as Money Lock and emergency kill switches. The challenge is behavioural. A person must pause at the right moment, verify through the right channel, and feel confident enough to say no even when the scammer sounds urgent, official, romantic, profitable or familiar.
That is why demographics matter. Not because age determines intelligence, but because life stage shapes exposure. A young adult looking for a side income meets a job scam differently from a senior receiving a call from someone claiming to be a government officer. A 40-year-old parent buying popular items online faces different pressure from an SME accounts executive asked to process a supplier payment. Good scam prevention starts with these differences.
How This Scam Works in Singapore
Scammers segment victims with the same discipline that legitimate marketers use to segment customers. They do not need to know everything about a person. They only need enough context to choose a believable hook.
For youths and young adults, scams often begin in high-traffic digital spaces: TikTok, Instagram, Telegram, WhatsApp, gaming communities, marketplace listings and job chats. The offer may be a flexible remote job, a resale bargain, a concert ticket, a crypto trading group, a paid task, or a small commission for receiving and transferring funds. The financial ask may start low because the scammer is testing compliance. Once the victim pays a fee, completes a task, shares bank access, or joins a group, the pressure escalates.
For adults aged 30 to 49, the attack surface is wider because this group is active across work, family, finance and online commerce. SPF's 2025 profile showed adults in this age band made up 36.1 per cent of scam victims, the largest share among age groups. This does not mean they are less careful. It means they have more daily transactions and more credible contexts for a scammer to exploit: e-commerce purchases, delivery notices, banking alerts, job opportunities, investment pitches, school-related payments, home services, rental enquiries, business email compromise and fake buyer links. A scam message that would look random to one person may arrive at exactly the wrong moment for someone who is already expecting a parcel, payment, invoice or customer enquiry.
For young seniors and seniors, scammers often lean harder on authority, trust and fear. The Singapore Police Force's 2025 brief reported that seniors aged 65 and above made up 14.8 per cent of scam victims, but had the highest average loss at S$37,053 per victim. CNA also reported in 2026 that seniors made up about 15 per cent of victims in 2025 and that many senior victims fell prey to investment or government official impersonation scams. These scams are not crude. A caller may claim to be from SPF, MAS, a bank, a telco, a courier, a court, an overseas police agency, or even a known organisation. The victim may be told that their bank account is compromised, their identity has been misused, or their cooperation is needed in a confidential investigation.
For SMEs, the demographic lens is organisational rather than purely personal. A scammer may target a founder, finance manager, procurement staff member, customer service employee or social media administrator. The mechanics include fake supplier invoices, payment-redirection emails, impersonated directors, malware attachments, deepfake voice instructions, fake corporate account verification, and phishing pages designed to harvest Microsoft 365, Google Workspace, bank or accounting credentials. Under the Personal Data Protection Act, organisations also have duties to protect personal data in their possession or control, which makes staff training and access controls part of scam prevention rather than a nice-to-have cyber policy.
Many scams now move across channels. A victim may see an advertisement on social media, continue the conversation on WhatsApp, receive a payment instruction through Telegram, download an app from outside an official app store, then transfer funds through PayNow or bank transfer. This multi-channel flow helps scammers evade simple warning signs. It also explains why prevention must be layered: ScamShield can filter known scam calls and SMSes, CSA's cyber hygiene guidance reduces device risk, MAS-regulated financial institutions can add transaction friction, and family or workplace verification rules can stop a scam before money moves.
Real-World Impact and Statistics
The headline figure remains severe even after the 2025 decline: about S$913.1 million lost to scams in Singapore in one year, across 37,308 reported cases. ScamShield's public portal highlights major loss categories from 2025, including S$242.9 million lost to government official impersonation scams, S$336.2 million to investment scams, S$123.5 million to job scams and S$39.9 million to phishing scams. These categories are not evenly distributed across the population.
SPF's 2025 victim age profile is especially useful for prevention planning. Youths formed a smaller share of reported victims, but they are heavily exposed to scams that travel through social media, online shopping, games, messaging groups and informal job channels. Young adults face job, investment and marketplace scams at a life stage where side income, first investments and online communities are highly attractive. Adults aged 30 to 49 formed the largest victim group at 36.1 per cent, reflecting their high volume of digital transactions and financial responsibilities. Young seniors and seniors formed a smaller share than the under-65 groups, but the losses per person were much higher.
The senior loss profile deserves special attention. SPF's annual brief reported that seniors aged 65 and above lost an average of S$37,053 per victim, the highest across all age groups. The brief also noted that elderly victims commonly responded to scammers through social media, phone calls and messaging platforms, and that investment scams, government official impersonation scams and phishing were major categories for this group. A single senior victim's loss can represent retirement savings, emergency funds, CPF withdrawals or money set aside for family support. The emotional aftermath is often as damaging as the financial loss: shame, fear, loss of confidence and reluctance to use digital services.
For working adults and SMEs, the losses may spread beyond one person. A business email compromise scam can drain company funds, expose customer data, delay payroll or trigger internal disputes. A staff member who clicks a phishing link may unknowingly hand over credentials that allow criminals to access invoices, supplier details, customer contact lists and confidential files. If personal data is exposed, PDPA obligations may arise. If malware, unauthorised access or credential misuse is involved, the Computer Misuse Act may also be relevant to investigations and enforcement.
The national response has grown because scams are no longer isolated fraud attempts. ScamShield's whole-of-government summary describes a layered strategy across prevention, detection, enforcement and public education. It notes that nearly 390 million potential scam calls were blocked in 2023, scam SMSes fell after the Singapore SMS Sender ID Registry was implemented, and the ScamShield app has been downloaded more than 900,000 times. MAS and IMDA's Shared Responsibility Framework for phishing scams sets out duties for financial institutions and telcos, while bank safeguards such as Money Lock, fraud surveillance and kill switches aim to slow down or stop suspicious transfers.
Statistics tell us where to aim the next prevention message. The message for a teenager should not be a lecture about gullibility; it should focus on fake task jobs, mule recruitment, gaming marketplace fraud and pressure to move conversations off-platform. The message for a senior should not assume helplessness; it should give concrete scripts for ending calls, verifying officials and involving trusted family members before any large transfer. The message for adults and SMEs should focus on workflow design: dual approval, official contact directories, callback rules, secure devices, and no payment changes through email alone.
How to Protect Yourself
Start with a demographic-specific risk map. Write down where money decisions happen in your life: banking apps, PayNow, e-commerce platforms, WhatsApp groups, Telegram channels, workplace email, investment apps, CPF-related decisions, insurance conversations, property rentals, ticket purchases and family caregiving arrangements. Scammers target moments of decision, not abstract "users".
For youths and young adults, treat easy-money offers as high-risk by default. A job that requires upfront payment, a "task" platform that requires deposits to unlock commissions, or a request to receive money on behalf of someone else can become a scam or money mule offence. Never lend your bank account, Singpass, phone line, Telegram account or payment wallet to anyone. If a recruiter refuses to provide a verifiable company identity, local business registration details or a proper employment contract, walk away.
For adults aged 30 to 49, build friction into ordinary transactions. Verify payment changes using a known phone number, not a number provided in the suspicious message. For online purchases, stay on-platform where buyer and seller protections exist. For delivery, bank, LTA or government messages, check the official app or website by typing the address yourself. From 1 July 2024, government SMSes use the gov.sg Sender ID and follow a standard format, but scammers can still move to messaging apps, calls or malicious links. Do not treat a familiar logo, name or partial NRIC as proof.
For seniors and caregivers, agree on a family verification rule before a crisis happens. For example: no transfer above a set amount without a callback to a trusted person; no installation of apps during a phone call; no bank limit increase requested by a stranger; no confidential "police investigation" that forbids telling family. Government officials in Singapore will not ask you to transfer money, disclose bank login details or install apps from unofficial stores over a phone call. If someone claims otherwise, end the call and contact the organisation through its official hotline.
For SMEs, put prevention into process. Require dual authorisation for new payees, large transfers and supplier bank-account changes. Maintain an internal list of verified supplier contacts. Train staff to detect fake login pages, QR-code payment changes, deepfake voice pressure and invoice substitution. Use multi-factor authentication, strong passphrases, endpoint protection and timely software updates, in line with CSA Singapore's cyber hygiene guidance. Limit who can access customer data, payment systems and administrator accounts. A scammer cannot exploit a process that requires independent verification.
Use Singapore's official tools. Install ScamShield to help block known scam calls and filter scam SMSes. Call the 24/7 ScamShield Helpline at 1799 if you are unsure whether something is a scam. Use MAS resources such as the Financial Institutions Directory, Financial Advisers Register and Investor Alert List when checking investment offers. Use CSA's recommended security app guidance if you need malware protection. Use bank Money Lock features to ring-fence savings that should not be digitally transferable.
What to Do If You Are Targeted
If no money or credentials have been shared, stop the conversation, take screenshots, block the contact and report the encounter through ScamShield. Do not argue with the scammer. Scammers are trained to keep victims emotionally engaged, and every extra message gives them a chance to regain control.
If you clicked a link but did not enter details, close the page, clear the browser tab and run a security scan if you are worried about malware. If you installed an app outside official app stores, disconnect the device from the internet, uninstall the app if possible, and contact your bank from another trusted device. Change passwords from a clean device, starting with email, banking, Singpass-linked accounts and messaging apps.
If you entered banking details, Singpass credentials, one-time passwords or card information, call your bank immediately using the official fraud hotline or the number on the back of your card. Activate the bank's kill switch if available. Make a police report and preserve evidence, including phone numbers, chat handles, URLs, transaction references, bank account numbers, screenshots and dates.
If you transferred money, time matters. Call the bank first, then make a police report. The Anti-Scam Command and banks may be able to intervene faster when reports are made quickly, but recovery is never guaranteed. Do not pay a "recovery agent" who claims they can get your money back for a fee. Recovery scams often target people who have already been defrauded once.
If the victim is a senior, a student or an employee, respond without blame. Shame delays reporting. A calm response helps preserve evidence and prevent further loss. For workplaces, trigger the incident response plan: reset credentials, review mailbox rules, inspect payment approvals, notify affected parties where required, and assess whether PDPA data breach obligations apply.
Common Mistakes to Avoid
The first mistake is assuming scams are obvious. Many current scams use correct names, polished English, realistic websites, local phone numbers, spoofed identities, stolen invoices and information from data breaches. A message can be well written and still be criminal.
The second mistake is relying only on age stereotypes. Adults aged 30 to 49 formed the largest share of victims in SPF's 2025 data. Seniors lost more per victim, but working adults, young adults and youths also face serious exposure. Prevention campaigns that speak only to "the elderly" miss the people buying, selling, hiring, investing and approving payments every day.
The third mistake is verifying through the same channel that brought the suspicious request. If a WhatsApp message says your friend changed number, call the old number or check with a mutual contact. If an email says a supplier changed bank account, call the supplier's known office number. If a caller says they are from a bank, hang up and call the bank through the official number.
The fourth mistake is treating small first payments as harmless. Scammers often begin with a small deposit, trial task, delivery fee or verification charge. The first payment proves compliance. After that, they escalate through sunk-cost pressure, fake penalties, frozen balances or claims that a larger payment is needed to release money.
The fifth mistake is hiding the incident. Scammers depend on silence. Tell someone trusted, call 1799 if you are unsure, report through ScamShield, notify the bank and make a police report when money or credentials are involved.
FAQ
Who is most likely to be scammed in Singapore?
SPF's 2025 data showed adults aged 30 to 49 made up the largest share of scam victims at 36.1 per cent. This group is heavily exposed because they transact frequently online, manage family and work payments, use marketplaces, respond to delivery and bank messages, and often have enough savings or credit access to be attractive targets.
Do seniors lose more money to scams in Singapore?
Yes. Seniors aged 65 and above made up 14.8 per cent of scam victims in the SPF 2025 annual brief, but they had the highest average loss at S$37,053 per victim. Investment scams, government official impersonation scams and phishing were major risks for this group.
Are young people safe because they are digitally savvy?
No. Digital confidence does not remove risk. Young people may be exposed to fake job offers, task scams, gaming marketplace fraud, ticket scams, social media investment groups, romance hooks and money mule recruitment. Being comfortable online can sometimes make a scam feel like just another chat, platform or side hustle.
Why do scammers target SMEs in Singapore?
SMEs move money, hold customer and supplier data, and often rely on lean finance processes. A scammer who compromises one mailbox or impersonates one director may be able to redirect invoice payments or obtain credentials. SMEs should use dual approval, verified callback procedures, MFA, least-privilege access and staff training.
What official Singapore resources should I use to check a suspicious message?
Use ScamShield and call the 24/7 ScamShield Helpline at 1799 if you are unsure. For investment offers, check MAS registers and the Investor Alert List. For cyber hygiene, refer to CSA Singapore guidance. For possible personal data issues, refer to PDPC guidance. For emergencies involving money already transferred, call your bank immediately and make a police report.
What should families do to protect elderly relatives without taking away their independence?
Agree on simple verification rules, not surveillance. Set transfer thresholds, identify two trusted contacts for checks, enable Money Lock where suitable, install ScamShield, and practise what to say when a caller claims to be from the police, bank or government. The goal is to create a pause before money moves.
Does the Shared Responsibility Framework mean victims will always be reimbursed?
No. MAS and IMDA's framework sets duties for financial institutions and telcos in phishing scams and expectations for payouts when those duties are breached. It is not a blanket guarantee for every scam loss. Consumers still need to protect credentials, avoid suspicious links, report quickly and follow bank security instructions.
Conclusion
Scam prevention in Singapore has to become more precise. The data does not support a lazy story about one vulnerable group. Adults aged 30 to 49 are the largest reported victim group, seniors lose the most per victim, youths are exposed through fast-moving online communities, and SMEs face process-driven fraud that can damage both finances and data protection obligations.
The practical lesson is simple: match the warning to the person and the moment. Teach young adults to question easy money. Teach working adults to verify payments and links outside the original channel. Give seniors a trusted pause-and-check routine. Give SMEs payment controls that do not depend on one busy employee spotting every red flag.
Singapore already has strong anti-scam infrastructure across SPF, ScamShield, MAS, IMDA, CSA, PDPC, banks, telcos and community educators. The next step is local, personal and operational: know how scammers target your group, build verification into daily habits, and report early when something feels wrong.