Phishing Simulation for Businesses in Singapore: What to Know Before You Test

In this blog

phishing simulation Singapore

Singapore’s position as a major financial hub and data center center in Asia Pacific makes it an unusually attractive target for phishing and scam operations, and the country’s own police force tracks the resulting losses in painstaking, published detail. Before running a phishing simulation program, Singapore businesses benefit from understanding both the specific threat landscape they face and the regulatory expectations, PDPA and MAS chief among them, that shape how a testing program should be run.

This guide covers the current state of phishing and scams in Singapore, what local regulation expects from businesses, and what to know before testing your own team.

In Short: Singapore recorded S$913.1 million in scam losses in 2025, and government official impersonation scams more than doubled year over year. Businesses running phishing simulation need to account for PDPA’s data protection requirements and MAS’s cybersecurity expectations for regulated sectors specifically.

The Current Scam Landscape in Singapore

Singapore publishes some of the most detailed official scam and cybercrime data of any country, making it possible to track the threat landscape with real precision. According to the Singapore Police Force’s Mid-Year Scam and Cybercrime Brief 2026, Singapore recorded 913.1 million Singapore dollars in scam losses in 2025, a 17.9 percent decrease from the 1.1 billion dollars lost the year before, with case numbers falling by a similar margin. The first half of 2026 continued this improving trend, with losses declining further to 410.6 million dollars.

One category moved sharply in the opposite direction. Government official impersonation scams, where attackers pose as police, tax officials, or other public authorities, more than doubled, from 1,504 cases in 2024 to 3,363 cases in 2025, with losses reaching 242.9 million dollars, the second-highest loss total of any scam category tracked. Phishing itself remained the second most common scam type by case count, generating 39.9 million dollars in losses even as overall case numbers declined slightly.

A detail worth noting for any business running its own testing program: in over 80 percent of reported cases, victims transferred funds themselves after being manipulated through deception and social engineering, rather than having their accounts directly compromised through a technical exploit. This confirms what phishing simulation is specifically designed to address: the human decision-making step, not just technical vulnerability.

What Singapore’s Regulatory Environment Expects

Singapore businesses operate under a regulatory framework that treats data protection and cybersecurity as board-level governance concerns, not purely IT matters. According to Maxthon’s overview of Singapore’s cybersecurity exposure, the Personal Data Protection Act allows penalties of up to 1 million Singapore dollars for violations, and the Monetary Authority of Singapore has introduced stricter Technology Risk Management requirements for financial institutions specifically, while the Cybersecurity Act mandates specific protections for operators of Critical Information Infrastructure.

The same analysis found that 17 percent of Singapore employees clicked a phishing link within a two-week testing window, and that the information services sector faces the highest volume of phishing attempts of any industry, at nearly 40 percent of recorded incidents, ahead of financial services. For regulated financial institutions specifically, MAS’s Technology Risk Management framework increasingly expects formal, documented evidence of security testing, including simulated phishing exercises, as part of ongoing compliance, not just a one-time assessment.

A Distinctly Singapore Pattern: Government Impersonation and Regulatory Response

The sharp rise in government official impersonation scams has prompted a specific, notable regulatory response. In June 2026, MAS worked directly with the Association of Banks in Singapore to discontinue the PayNow nickname feature for retail customers, specifically to prevent scammers from exploiting the feature to masquerade as legitimate individuals or organizations. Separately, authorities introduced restrictions limiting individuals to ten postpaid SIM cards, with a public self-service checker tool, specifically to reduce the illicit SIM card supply scammers rely on for impersonation campaigns.

This kind of rapid, specific regulatory intervention is a distinctly Singaporean feature of the threat landscape, and it reflects a broader theme: authorities and financial institutions are moving quickly to close the exact channels scammers exploit, which in turn means the specific tactics attackers use shift correspondingly fast. Our guide on government agencies and phishing covers why impersonation of official institutions represents a distinct training challenge more broadly, a pattern clearly visible in Singapore’s own data.

What This Means for Testing Your Team

A few practical considerations follow specifically from Singapore’s current landscape:

  • Test for government and authority impersonation scenarios specifically, given how sharply this category has grown, rather than relying only on generic corporate phishing templates.
  • Financial services and information services organizations should expect closer scrutiny. Both sectors face disproportionate targeting according to recent data, and MAS-regulated entities specifically should expect testing evidence to factor into ongoing compliance reviews.
  • Voice-based social engineering deserves explicit coverage. With the vast majority of losses coming from victims transferring funds themselves after manipulation, testing needs to reflect real-time, adaptive social engineering, not just static email templates. Our guide on pretexting and vishing simulation platforms cover this pattern in more depth.
  • Document testing evidence with MAS and PDPA expectations in mind. Regulated businesses in particular benefit from treating simulation results as ongoing compliance documentation, not a one-time internal exercise.
phishing simulation Singapore

Building a Testing Program

Given how much of Singapore’s reported scam activity relies on social engineering rather than technical compromise, testing needs to reflect that reality directly. Running a phishing test for employees using scenarios modeled on government impersonation and urgent authority-driven requests gives Singapore businesses a far more accurate picture of readiness than generic templates built for a different market.

Tracking results over successive campaigns through an employee phishing risk score also helps identify whether risk concentrates in specific departments, information considerably more useful for regulated Singapore businesses building an ongoing compliance record than a single company-wide click rate.

Final Thoughts

Singapore’s scam landscape is well documented, closely regulated, and shifting quickly, with authorities actively closing specific channels scammers exploit as fast as they identify them. Businesses testing their own teams benefit from reflecting that same specificity: training and simulation built around the actual patterns Singapore’s own police data reveals, government impersonation chief among them, rather than a generic template imported from elsewhere.

FAQ

How much have scams cost Singapore recently?

Singapore recorded 913.1 million Singapore dollars in scam losses in 2025, according to the Singapore Police Force, a 17.9 percent decrease from the previous year, with the declining trend continuing into the first half of 2026.

What is the fastest-growing scam category in Singapore?

Government official impersonation scams more than doubled between 2024 and 2025, rising from 1,504 to 3,363 cases, with losses reaching 242.9 million Singapore dollars, the second-highest loss total of any scam category tracked.

What regulations should Singapore businesses consider when running phishing simulation?

The Personal Data Protection Act governs how personal data is handled, with penalties up to 1 million Singapore dollars for violations, while the Monetary Authority of Singapore’s Technology Risk Management framework sets specific cybersecurity expectations for financial institutions, increasingly including documented security testing evidence.

Why did MAS discontinue the PayNow nickname feature?

MAS worked with the Association of Banks in Singapore to discontinue the feature for retail customers in June 2026 specifically because scammers were exploiting it to masquerade as legitimate individuals or organizations during impersonation scams.

Which industries in Singapore face the highest phishing risk?

Information services and financial services face the highest volume of phishing attempts according to recent data, with information services alone accounting for close to 40 percent of recorded phishing incidents.

Content Reviewed By

Mohammed Nawaz Sajjad, Sr. Security Analyst at PhishCare
Mohammed Nawaz Sajjad
Sr. Security Analyst at CyberSapiens | Phishing Simulation | Ethical Hacker | Bug Hunter | Red Team

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.

He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.

View LinkedIn Profile