Scam.SG
  • Search Company
  • TrustScore
  1. Home
  2. Scam Prevention
  3. Singapore’s New Anti-Scam Platform Rules: What WhatsApp, Telegram, Facebook and TikTok Users Need to Know
Scam Prevention

Singapore’s New Anti-Scam Platform Rules: What WhatsApp, Telegram, Facebook and TikTok Users Need to Know

Admin
21 August 2026
Singapore’s New Anti-Scam Platform Rules: What WhatsApp, Telegram, Facebook and TikTok Users Need to Know

Summarise this page with:

ChatGPTCopilotClaudeGrokPerplexity
Share this article:

Direct Answer

Singapore has issued new anti-scam Codes of Practice requiring major messaging, social media and e-commerce services to make scams harder to run. The rules will add protections such as consent before unknown users add you to groups, advertiser identity checks and restrictions on advertisements for unlicensed financial services, but they do not make every message, listing or advertisement safe.

Introduction

The Singapore Police Force’s Online Criminal Harms Act Office announced the new and enhanced Codes of Practice in August 2026. They cover services many Singapore residents and businesses use every day: WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages, Google Meet, Facebook, Instagram, TikTok, Carousell, Facebook Marketplace and Facebook Business Pages.

The timing matters. According to SPF, messaging services such as WhatsApp and Telegram were involved in about 23% of scam cases in 2025, while social media services such as Facebook, Instagram and TikTok were involved in about 30%. These platforms are not merely places where a scam ends. They are often where the target first sees a fake investment advertisement, receives an unsolicited job offer, joins a fraudulent chat group or is redirected to a phishing site.

Earlier platform safeguards helped. SPF said scam cases reported on designated online services fell by about 37% from 2024 to 2025 after the first set of Codes of Practice took effect. The latest rules address gaps that scammers continued to exploit, including government impersonation in profile names and images, strangers adding people to investment groups, masked links in advertisements, unverified advertisers and unsafe marketplace payment arrangements.

For users, the practical message is simple: welcome the new controls, turn them on when available, and keep verifying claims independently. A platform warning is useful. Its absence is not proof that the person, company or investment is genuine.

How This Scam Works in Singapore

The new rules target several connected stages of the scammer’s playbook.

First comes discovery. A target sees a Facebook, Instagram or TikTok advertisement featuring a supposed investment mentor, government grant, low-priced product or celebrity endorsement. The advertisement may use a shortened or masked web address so the destination is not obvious. Some advertisements lead to a cloned news page or a website designed to resemble a bank, government agency or licensed financial institution.

Next comes migration. The target is invited to WhatsApp or Telegram, where a “mentor”, “customer service officer” or “recruiter” continues the conversation. In investment scams, the target may be added to a group filled with accounts posting fabricated profits and praise. In job scams, the group may offer commissions for simple online tasks before demanding deposits. In government official impersonation scams, a profile name or photograph may imitate SPF, MAS or another public agency.

Then comes payment or credential theft. The target is told to make a PayNow or bank transfer, enter card details on a phishing page, disclose a one-time password, install an application, or move money to a supposed “safe account”. No Singapore government agency or bank will instruct you to transfer savings to a safe account for investigation. A legitimate employer will not require cryptocurrency deposits to unlock work or commissions.

Finally, the scammer creates a second demand. A fake investment platform shows profits but requires a “tax”, “security deposit” or “withdrawal fee”. A marketplace seller requests another payment for customs or delivery. A recovery scammer may later contact the same victim and promise to retrieve the money for an upfront fee.

The Messaging Code is designed to interrupt the migration stage. Designated services must introduce safeguards that can require consent before an unknown contact adds a user to a group or channel, show contextual warnings, and help users silence, filter or block communications from non-contacts. Services must also prevent spoofing of the Singapore Government through profile names or images. SPF set an earlier deadline of 30 September 2026 for the government anti-spoofing measure; the wider messaging requirements are due by 31 January 2027.

The Social Media Code focuses on discovery. Facebook, Instagram and TikTok must verify the identity of advertisers targeting users in Singapore, prevent suspected scam advertisements from being published, act on reported scam advertisements and address techniques such as masked destination links. Advertisements for financial products or services must not be carried unless the advertiser is appropriately licensed by the Monetary Authority of Singapore.

The enhanced E-Commerce Code tackles transaction risk. It strengthens seller verification, payment protection, controls for logins from unrecognised devices and safeguards against scam advertisements on designated marketplace services.

Real-World Impact and Statistics

The scale of platform-enabled scams explains why Singapore is shifting more responsibility towards service providers. SPF’s figures show that messaging and social media services appeared in a substantial share of scam reports in 2025. Because one case can involve several services, the percentages should not be added together; they show how widely scammers use each channel.

Apple iMessage illustrates the problem. In an advisory issued on 20 August 2026, SPF said more than 30,000 iMessage accounts linked to scam campaigns had been detected and disrupted since June. Scammers exploited internet-based messaging to impersonate courier companies and other trusted organisations, directing recipients to phishing sites. This channel did not operate exactly like ordinary SMS, so established controls such as Singapore’s SMS Sender ID Registry did not cover it in the same way.

The harm extends beyond individual financial loss. An SME employee who follows a fake chief executive’s instruction can divert a supplier payment. A compromised social media account can be used to target customers. A fake business page can misuse a company’s name and images, while a fraudulent marketplace listing can damage trust in legitimate sellers.

There are also data-protection and legal consequences. Businesses holding customer data must take reasonable security steps under the Personal Data Protection Act. If an employee account is compromised, the organisation should assess whether personal data was exposed and whether notification duties apply. Installing malware, accessing accounts without authority or using compromised systems to facilitate fraud may also engage the Computer Misuse Act. These laws address organisational duties and criminal conduct; they do not turn a suspicious message into a civil dispute that users should handle alone.

The 37% fall in scam cases reported on designated online services between 2024 and 2025 suggests that platform controls can work. It does not mean scams have fallen evenly across every service or tactic. Scammers move quickly to less regulated channels, new accounts and direct messages, which is why individual checks remain necessary.

How to Protect Yourself

Treat every unsolicited opportunity as unverified, even when it appears inside a familiar app.

For investments, check the firm in the MAS Financial Institutions Directory. Confirm the exact legal name, website and licence status. A company’s ACRA registration alone does not authorise it to provide regulated investment services. Compare the contact details in the advertisement with the details on the institution’s official website, reached independently through your browser.

For messages claiming to be from SPF, MAS, IRAS, CPF Board or another government agency, do not trust the profile picture or display name. Government officers do not ask you to disclose banking credentials, install an unofficial app or transfer funds to a “safe account”. End the conversation and call the agency using the number on its official .gov.sg website.

Use the platform controls as they become available. Block unknown users from adding you to groups where possible. Silence calls from unknown numbers. Review privacy settings that control who can see your profile photo, phone number and group membership. Enable two-factor authentication and login alerts on social media and marketplace accounts.

Do not leave the platform’s protected payment flow merely because a buyer or seller offers a discount. Avoid deposits to personal accounts for goods you have not inspected. On marketplaces, examine account age, reviews and transaction history, but remember that reviews and accounts can be stolen or fabricated.

Before opening a link, look at the full domain. A padlock only shows that the connection is encrypted; it does not prove that the site belongs to a bank, courier or government agency. Do not enter Singpass, card or banking details after following an unsolicited link. Use the official app or type the organisation’s address yourself.

SMEs should add process controls that do not depend on spotting a convincing fake. Require a second person to approve changes to supplier bank details and high-value transfers. Confirm payment instructions through a known telephone number. Separate social media publishing permissions from advertising and billing access. Keep an incident contact list for the bank, IT provider, Data Protection Officer and police.

Install and use ScamShield where supported, and check suspicious messages through ScamShield’s services. ScamShield can reduce exposure and help identify known scam patterns, but it cannot guarantee that every new account, advertisement or link will be caught immediately.

What to Do If You Are Targeted

If you have not transferred money or shared credentials, stop replying. Take screenshots showing the account, phone number, advertisement, group name, link and payment request. Report the account or advertisement through the platform, then submit the details to ScamShield. Blocking the sender without reporting preserves your own safety but may leave the same account free to contact others.

If you entered banking details, disclosed an OTP or transferred money, call your bank’s fraud hotline immediately. Use the number on the back of your card or the bank’s official website. Ask the bank to freeze affected cards or accounts and attempt to stop or trace the transfer. Then call the ScamShield Helpline at 1799 for guidance and make a police report. Speed matters because money may be moved through several mule accounts within minutes.

If you installed an app or software at the scammer’s direction, disconnect the affected device from Wi-Fi and mobile data. Use a different, clean device to change important passwords and contact your bank. Do not factory-reset the affected device before asking the police or your organisation’s incident responder whether evidence needs to be preserved.

For a compromised business account, revoke active sessions, reset credentials, preserve access logs and notify relevant staff. Assess whether customer or employee personal data was exposed. Your Data Protection Officer should consider the PDPA breach-assessment and notification requirements. Warn customers through a verified channel if scammers are impersonating the business.

Common Mistakes to Avoid

Do not assume an advertisement is legitimate because a large platform accepted it. The new verification requirements reduce risk, but stolen identities and compromised accounts can still pass superficial checks.

Do not rely on a blue tick, profile photograph or Singapore telephone number. These signals can be copied, spoofed or obtained through compromised accounts.

Do not move to WhatsApp or Telegram merely because a seller, recruiter or investment promoter says the platform chat is inconvenient. Moving the conversation can remove marketplace protections and make the scam harder to investigate.

Do not pay a fee to recover scam losses. Recovery scammers often approach victims after details have been shared or sold. Police, banks and ScamShield do not require cryptocurrency or gift-card payments to open a case.

Do not blame an employee or family member and delay reporting. Scammers design the interaction to create urgency, authority and social proof. A calm, rapid response gives the bank and SPF the best chance to act.

FAQ

When do Singapore’s new anti-scam platform rules take effect?

The government-profile anti-spoofing requirement for designated messaging services is due by 30 September 2026. The broader Messaging, Social Media and enhanced E-Commerce Code requirements are due by 31 January 2027, according to SPF’s August 2026 announcement.

Which messaging services are covered?

The Messaging Code applies to designated services including WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages and Google Meet. The exact safeguards users see may differ because each service has its own design.

Will every social media advertiser be verified?

The Social Media Code requires designated services to verify advertisers targeting users in Singapore and to strengthen controls against suspected scam advertisements. Verification lowers risk but does not guarantee that every claim, product or destination website is genuine. Check the advertiser independently.

How can I verify whether an investment advertiser is licensed in Singapore?

Search the exact entity name in the MAS Financial Institutions Directory. Match its website and contact details with the advertisement. If you cannot find the firm or the details differ, do not send money or personal information. You can also check Scam.SG for business and complaint information, but MAS remains the authority for financial licensing.

Can the Singapore Government contact me through WhatsApp or another app?

Agencies may use digital channels for some communications, but a display name or logo is not proof of identity. A government officer will not direct you to transfer savings to a safe account, reveal an OTP or install an unofficial app. Verify the request through the agency’s official .gov.sg website and telephone number.

What should I do after clicking a phishing link?

If you only opened the page and entered nothing, close it and report the message. If you entered a password, card number, banking credentials or OTP, contact your bank immediately, change the affected credentials from a clean device, call ScamShield at 1799 and make a police report.

Do the new rules replace ScamShield and personal precautions?

No. Platform safeguards, ScamShield, bank controls and careful verification address different parts of the problem. New scam accounts and websites can appear before automated systems recognise them, so users should still verify requests through official channels.

Conclusion

Singapore’s new Codes of Practice place concrete duties on the services that carry scam advertisements, messages and transactions. Consent controls, advertiser checks, government anti-spoofing measures and safer marketplace processes should remove some of the easiest routes scammers use.

The safest response remains independent verification. Do not treat a familiar app as proof that the person inside it is genuine. Check financial licences with MAS, reach government agencies through .gov.sg, keep marketplace payments on-platform and confirm business payment changes through known contacts. If money or credentials have already been sent, call your bank first, then contact the ScamShield Helpline at 1799 and make a police report.


For Consumer

  • Search a Company
  • Company Directory
  • Whitelist Directory
  • Virtual Office Directory
  • Company Location Map
  • Report a Scam
  • Submit a Review
  • Flag a Business
  • E-Commerce Abuse Reports
  • Articles & Community
  • Scam Statistics
  • View Scam Types

For Business

  • Verify Your Business
  • What is TrustScore
  • Claim Your Business
  • Certification Partnership
  • Advertise with Us
  • Submit an Article
  • Work with Us
  • Intelligence Services
  • Singapore Standard Industrial Classification

Platform

  • About Scam.SG
  • Watchlist
  • News & Alerts
  • Data Sources
  • Editorial Standards
  • Media
  • Publications
  • Contact Us
  • Sitemap

About Scam.SG

Scam.SG is Singapore's homegrown business trust and anti-scam platform, with authenticity profiles on over 612,000 Singapore-registered businesses. We verify businesses, educate the public on how scams operate, and detect and disrupt scam activity, helping consumers and business associates reduce the risk of falling into a scam. Our analysis uses proprietary algorithms to assess and score Singapore business entities based on publicly available data signals. A lower score does not mean a business is a scam. Visit scam.sg/terminology for definitions of all platform terms.

Disclaimer

Scam.SG is operated by OnScam (SG) Pte. Ltd. We are not affiliated with, endorsed by, or sponsored by any government agency or department. The information provided on Scam.SG (the “Website”) is sourced from publicly available data, including but not limited to ACRA (Accounting and Corporate Regulatory Authority) data from data.gov.sg and other publicly accessible sources. Whilst we strive to ensure the accuracy and reliability of the data presented, we cannot guarantee its completeness or timeliness. Read more at our disclaimer page.


Privacy Policy
Terms & Conditions
Terminology
Disclaimer
Notice & Take Down
Dispute Resolution
Copyright
Sitemap
Scam.SG
© 2026 Scam.SG, operated by OnScam (SG) Pte. Ltd.