You will be able to spot phishing messages and suspicious calls that pretend to come from a bank.
Open your SMS inbox and scroll back a few weeks. Somewhere between the delivery updates and the one-time passwords, there's a fair chance you'll find a message that uses your bank's name, mentions a problem with your account, and asks you to tap a link to sort it out. Some of these look almost identical to the real alerts your bank sends.
This lesson covers the three tools scammers use most when they pretend to be your bank: the phishing message, the fake login page it leads to, and the phone call from a number that looks local. Each one has a signal you can check without being an expert.
The simplest rule in this whole module is this one. Banks in Singapore no longer send clickable links by SMS or email to retail customers. Your bank may still message you about a transaction, a one-time password or a change to your account, but it won't send you a link to tap.
That turns a hard judgement into an easy one. You don't need to study the spelling, the logo or the tone of the message. If it claims to be from a bank and it contains a link, treat it as a scam, delete it, and if you're worried about your account, open your banking app or call the number on the back of your card.
Scammers know about this change, so some messages now avoid links and ask you to call a number instead. That number goes to the scammer. The rule from lesson 1.3 still applies: use contact details you found yourself, never the ones in the message.
You may have seen some SMS arrive with a sender shown as "Likely-SCAM". This comes from the SMS Sender ID Registry, a system that lets organisations register the names they send SMS under, such as a bank's or a delivery company's name in place of a phone number. Organisations that send SMS with a sender name have to register it. When a message uses a sender name that isn't registered, it can be labelled Likely-SCAM before it reaches you.
This catches scammers who try to make a message appear under a bank's name. It helps a lot, but it has limits. The label is applied to messages sent under a sender name, so a scam text from an ordinary mobile number won't carry it. A message without the label is not proof the message is genuine. Treat the label as a free warning when you see it, and keep checking everything else the usual way.
Caller ID can be faked, so a call can show a number that looks local, or even your bank's real hotline. Singapore's telcos add a plus sign in front of the number for calls that come in from overseas. If an incoming call shows a number starting with "+", it came from outside Singapore, even when the caller says they're from a local bank or agency.
Pay close attention to "+65" followed by a local-looking number. Many people read +65 as a sign that the call is local, but here it is a warning: an overseas caller is presenting a Singapore number. Check the current guidance on the ScamShield website, which explains how these calls are displayed.
A plus sign isn't proof of a scam, because friends and family do call from abroad. It is a reason to be careful when the caller claims to be a local organisation and asks for anything that triggers the stop-and-check rule.
Phishing is the trick of getting you to hand over login details by pretending to be someone you trust. The message is the bait, and the page behind the link is where the damage happens.
A phishing page copies your bank's login screen closely, with the same colours, the same logo and the same layout. The web address is the giveaway, but on a phone screen it's often cut short or made to look similar to the real one, with a letter changed or an extra word added.
Here is how one typically runs. You enter your username and password, and the page tells you to wait. Behind the scenes, the scammer types those details into your real bank's website. Your bank sends you a one-time password by SMS, because it thinks you're logging in. The fake page then asks you for that code, and when you enter it, the scammer is inside your account. From there they can add themselves as a payee, raise your transfer limit and move money out.
Here is an illustration. Daniel gets an SMS saying his bank account will be suspended unless he updates his details. It has a link, and the page looks exactly like his bank's login. He enters his password, then a one-time password. A few minutes later, a second SMS arrives from his real bank saying a new payee has been added. That message, the one that arrived without a link, is the real one, and it's his chance to call the bank's hotline and freeze his account straight away.
None of these signals needs technical knowledge. A link that claims to come from a bank, a Likely-SCAM label and a plus sign on a call from a "local" company are all visible at a glance.
Your own inbox is the best place to practise. Many people have at least one of these messages sitting there already, unread or half forgotten. Look through your SMS for messages that carry the Likely-SCAM label or that use a bank's name and contain a link.
Check your SMS inbox for any message labelled Likely-SCAM or containing a link from a bank name, and delete or report it.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).