Singapore police said at least 246 reports have been filed since July 2026 after shoppers clicked on social media advertisements for discounted household goods, food items and fashion products, then entered card or i-banking credentials on copycat websites.
Total losses have reached at least S$1.4 million in the variant highlighted in an Oct 2 advisory. Victims only realised something was wrong when unauthorised transactions appeared on their accounts after they supplied one-time passwords or approved digital tokens.
How the lure works
The Singapore Police Force said promotions appear on platforms including Facebook, Instagram and TikTok. Attractive prices on rice cookers, sneakers or snack bundles entice users to leave the app and visit external pages that mimic legitimate retailers.
Checkout flows ask for card numbers, internet-banking log-ins or both. Some victims authorised OTPs believing they were confirming a bargain purchase. Instead, criminals used the credentials immediately.
Why it spreads during sale seasons
October stacks year-end shopping with Formula 1 tourism and haze-related indoor browsing time. ScamShield helpline staff told InfoHandle that call volumes rise when platform algorithms surface sponsored listings alongside trusted friends’ posts, blurring the line between advertising and personal recommendations.
Unlike email phishing, social ads can be purchased with stolen accounts and rotated faster than platforms take them down. Police urged users to check URLs carefully and avoid entering banking details on unfamiliar domains even when the creative looks polished.
Official checks before you pay
Authorities recommend verifying merchants through the ScamShield app or the 24-hour ScamShield helpline at 1799. Shoppers should look for mismatched domain names, missing business registration details and pressure to complete payment within minutes.
Banks have tightened cooling-off periods for new payees, but credentials captured on a phishing page can still enable card-not-present charges overseas. Turning on transaction alerts for any amount above zero remains the fastest home defence.
What platforms owe users
Police did not name specific advertisers in the public advisory, but the release included sample creatives showing exaggerated discounts. Meta and TikTok have policies against deceptive commerce ads; victims InfoHandle interviewed said reporting buttons sometimes returned automated responses before ads reappeared under new account names.
Regulators worldwide are debating who must refund victims when an ad was served on a major platform. In Singapore, the immediate practical step is still to call the bank, file a police report and preserve screenshots of the advertisement and checkout page.
Protecting older relatives
Family members shopping on behalf of parents should set up separate low-limit cards for online use. Police community outreach teams said seniors are over-represented among victims who believe they are buying groceries for grandchildren.
Teaching relatives to forward suspicious ads before paying—especially during haze weeks when errands are delegated—can interrupt the loop before OTPs are shared on WhatsApp family chats.
If you already clicked
Call your bank’s fraud hotline immediately, even if no charge has posted. Reset passwords from a clean device, enable two-factor authentication where available, and lodge a report at a Neighbourhood Police Centre or online. Early reports help trace mule accounts while balances are still moving.
The Oct 2 advisory is part of the ongoing ACT Against Scams campaign. More guidance lives at scamshield.gov.sg, which lists verified merchant sign-up flows and recent police notices without requiring users to download another shopping app.
