Parliament passed the Scams (Countermeasures) and Other Matters Act on 9 September, giving the Singapore Police Force fresh tools to compel banks, telcos and major online platforms to share scam-related data and disable risky accounts. The law is on the books, but it is not yet in force: commencement still depends on a ministerial notification in the Government Gazette, and service providers say they are mapping compliance teams against orders that could arrive with little runway once the date is fixed.

What changed in the September sitting

Senior Minister of State for Home Affairs Goh Pei Ming told the House the Bill closes gaps between existing anti-scam legislation and what investigators need when syndicates move faster than voluntary information sharing. The Act amends the Protection from Scams Act 2025, the Online Criminal Harms Act 2023 and related statutes so SPF can issue three calibrated orders: a disclosure order for account-related information, an account disabling order for up to 30 days (extendable once), and a service limitation order that can restrict access for up to three years.

MPs from both sides spent more than four hours on 8 and 9 September on safeguards. Goh stressed appeal routes and the need for providers to be consulted on operational details before orders go live. The Workers’ Party supported the thrust of the Bill while pressing for clarity on how quickly a wrongly disabled account can be restored.

Why commencement still matters for households

For readers, the practical shift is upstream of the scam SMS or fake investment chat. Disclosure orders are meant to let investigators trace mule accounts before victims wire life savings. Disabling orders aim to stop accounts that mimic government agencies or influencers, even before a transfer is attempted. None of that works on paper alone: banks must wire new APIs and playbooks, and telcos must align with SIM-registration rules already tightened this year.

The Act also raises penalties for platforms that ignore anti-scam codes. Fines for breaching Online Criminal Harms implementation directives can now reach S$10 million, the highest financial penalty in Singapore’s online safety toolkit. That figure landed the same week Meta and SPF publicly detailed a separate intelligence-sharing push that disrupted millions of scam-linked pages — a reminder that legislation and industry operations are moving on parallel tracks.

What service providers are doing now

Lawyers advising financial institutions say clients are building “order desks” that can authenticate SPF requests within minutes, because disabling the wrong wallet or brokerage account carries reputational risk. Telcos are reviewing how disclosure orders interact with existing duties under the Telecommunications Act. Major platforms already subject to implementation directives are revising user-flow friction for account recovery, anticipating more proactive takedowns.

The Government has not published a commencement date. The Act’s Section 1 follows the standard pattern: it comes into operation on a day the Minister appoints. Until that notice appears, existing police powers under the Protection from Scams Act and voluntary industry fraud feeds remain the front line.

What to watch in October

Home Affairs officials told MPs that subsidiary regulations and operational guidance will follow commencement. Banks listed on the SGX have begun disclosing scam-loss provisions in quarterly risk statements; once orders are live, those numbers will be read against how often accounts were frozen in time. For households, the immediate advice unchanged from SPF stands: verify through official channels, and treat urgency as a red flag.

When the Gazette date lands, expect a short implementation window and a burst of provider announcements on how customers will be notified if an account is temporarily disabled. Parliament has done its part; the calendar for enforcement now sits with the Minister.