Checks run through the ScamShield app and website are logging a sharp rise in suspicious URLs that mimic DBS and United Overseas Bank login screens, according to desk tallies compiled for a joint public reminder issued ahead of the Sept 23 morning window. The spike does not mean either bank’s systems were breached; it reflects criminals cloning familiar pages and pushing them through SMS, email and messaging apps to harvest credentials and one-time passwords.
What the cloned pages ask for
In the DBS and POSB variant police flagged in March, victims received emails claiming a digital token had expired and needed “activation.” Embedded links led to pages that visually matched legitimate internet banking, then prompted for usernames, card numbers and OTPs. At least 72 cases tied to that impersonation pattern were reported between mid-January and late March 2026, with losses of at least S$484,000, police said at the time.
UOB has separately warned throughout 2026 about phishing mail that urges password resets or “compliance” clicks. Its security pages stress that verification never happens through emailed links; customers should open the TMRW app or type the bank URL manually. When ScamShield’s link checker flags a URL as unverified, the portal can auto-file a report so authorities can pursue takedowns.
Why ScamShield is seeing more links now
The National Crime Prevention Council-operated checker compares pasted URLs against known scam domains and community reports. Security architects said September’s uptick tracks two mechanics: scammers rotating hosting providers faster than blocklists update, and more users pasting links after police and bank advisories told them to “check before you click.”
A Sept 2 police advisory on iMessage scams impersonating DBS fraud investigators showed how channels keep shifting—fraudulent hotlines in chat threads, then credential theft on follow-up calls. Fake login pages are the quieter sibling of that playbook: no live caller, just a convincing form and a sense that your account will be frozen if you delay.
What CSA and SingCERT want reported
The Cyber Security Agency’s SingCERT channel accepts phishing website reports from Singapore-based victims and IT teams. CSA reminds users that cybercrime investigations sit with police; SingCERT’s role is coordination and takedown support when malicious hosting is identified. ScamShield’s reporting flow feeds the same ecosystem—full URLs matter, copied from browser history rather than shortened previews.
DBS told customers in the March advisory it works with police on phishing takedowns, funds tracing and case escalation. UOB lists a 24-hour fraud hotline at 6255 0160 and encourages Money Lock limits inside TMRW. Neither bank can recover credentials already typed into a criminal page; speed to the fraud desk determines whether outgoing transfers can be frozen.
Household habits that actually help
Enable transaction limits and multi-factor authentication before a link arrives, not after. If a message claims a pending card charge, open the banking app directly—balances and holds appear there without calling a number embedded in chat. ScamShield’s 1799 helpline remains the overnight check for unsure households.
Teach family members to distrust “security alert” pages that appear while browsing unrelated sites; criminals buy ads and compromised sites that redirect to fake logins. Clearing browser tabs does not revoke data already submitted—call the bank first, file a police report second, and keep screenshots with timestamps for investigators.
Shared Responsibility Framework context
Major retail banks participate in Singapore’s Shared Responsibility Framework for phishing scams, which allocates liability among financial institutions, telcos and victims depending on whether prescribed controls were in place. The framework does not make reporting optional; documenting the exact URL and time of entry strengthens both bank disputes and police statistics.
Desk analysts said many September ScamShield submissions mention UOB and DBS in the same household thread—suggesting blast campaigns rather than targeted wealth management clients. Rotating domain names with “secure” or “login” substrings remain the tell when the checker returns “not verified.”
What to do in the next hour
If you pasted a link into ScamShield and received a scam outcome, do not revisit the page. If you already entered credentials, call the bank fraud hotline immediately—DBS lists 1800-339-6963—and ask for card blocks and session resets. File online with police so the case enters national tracking.
Forward suspicious emails to the bank’s published abuse address where available, and delete the message after reporting. The Sept 23 reminder is not alarm for a new bank outage—it is a volume signal that login cloning remains the cheapest path for criminals even as pop-up and impersonation variants grab headlines elsewhere.








