Posted on Leave a comment

Singapore disrupts 30,000 iMessage accounts as scam losses hit US$1.7M

Singapore’s fight against scams is moving deeper into the messaging apps people use every day, after police disrupted more than 30,000 Apple iMessage accounts linked to a campaign that has already caused about SGD2.2 million (US$1.7 million) in losses.

The Singapore Police Force said its Cyber Command has been detecting and disabling accounts tied to the scam since June 2026. The loss figure has climbed quickly: on August 5, police had put the damage at SGD1.2 million (~US$940,000). In other words, reported losses rose by nearly US$800,000 in a matter of weeks.

Also Read: Almost got “digitally arrested.” India needs Singapore’s playbook before the next scam call

The case underlines a problem that is becoming familiar across Southeast Asia: scammers are not relying only on old-fashioned SMS blasts or suspicious phone calls. They are moving across encrypted messaging apps, social platforms, marketplaces and ad networks, looking for whichever channel has the least friction and the most trust.

In this campaign, fraudsters sent iMessages pretending to be courier companies such as NinjaVan, J&T Express and SPX Express, as well as government agencies and financial institutions. The messages directed recipients to spoofed websites designed to look like the real thing. Victims were then asked to make a small payment or settle a fine, often by entering card or banking details.

The amounts requested may have seemed minor, but the information handed over was valuable. According to police, some victims who entered one-time passwords later discovered that their cards had been added to mobile wallets, bank security tokens had been registered on unfamiliar devices, or their accounts had been accessed without permission. Many only realised what had happened after seeing unauthorised transactions.

Why iMessage is a harder target

The campaign also exposes a regulatory and technical gap. In Singapore, SMS scams have been targeted through network-level filters and a sender ID registry, which helps prevent fraudsters from impersonating trusted organisations through text message headers.

Also Read: Phishing threats: Protecting your online shopping and banking

But iMessage runs on Apple’s own system, outside the traditional telecoms layer. That means it is not covered by the same filters and registry used for SMS. For a scammer, that difference matters. A message delivered in Apple’s blue bubble can appear familiar and personal, especially to users who do not think of iMessage as a risky channel.

Police stressed that government agencies and courier companies do not use iMessage to communicate with the public. That simple point is important because many delivery-related scams rely on timing and plausibility. In a city where online shopping, food delivery and parcel tracking are part of daily life, a message about a failed delivery or unpaid fee can feel routine enough to click.

Singapore is not alone in facing this shift. Across Southeast Asia, fraud groups have become more sophisticated in blending social engineering with real consumer habits. Delivery scams, fake toll or tax notices, investment fraud and phishing links often travel through the same apps people use to speak with family, sellers, banks and colleagues. The more commerce moves into chat, the more attractive these channels become.

New codes put pressure on platforms

The iMessage disruption comes shortly after Singapore issued new Codes of Practice under the Online Criminal Harms Act. Announced on August 17, the codes apply to seven services assessed as posing the highest scam risk: WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Message and Google Meet.

The services must comply by January 31, 2027, with anti-impersonation measures due earlier, by September 30, 2026.

Also Read: Inside the dark economy of crypto scams: 2024’s most lucrative fraud tactics

Messaging platforms are a major part of the scam landscape. Police said services such as WhatsApp and Telegram accounted for about 23 per cent of scam cases in 2025. That figure is significant because messaging apps are no longer just communications tools. They are customer service channels, sales channels, community spaces and, increasingly, the first point of contact between businesses and users.

For regulators, the challenge is to impose safeguards without breaking the usefulness of these platforms. Identity checks, faster takedowns and impersonation controls may help, but scammers adapt quickly. If one route becomes harder, they often move to another, whether that is an ad, a marketplace listing, a fake account or a compromised device.

This is why Singapore’s approach is widening beyond a single channel. Earlier in the week, police announced a separate Social Media Code covering Facebook, Instagram and TikTok. Together, the three platforms accounted for about 30 per cent of scam cases in 2025, with Facebook alone making up about 18 per cent.

The Social Media Code focuses on scam advertisements, a common gateway for fraud. Platforms will be required to block and promptly remove suspected scam ads, verify advertisers’ identities against government records, and prevent advertisements offering financial products or services unless the advertiser is licensed by the Monetary Authority of Singapore.

That last requirement is particularly relevant in a region where fake investment schemes remain a persistent threat. Scammers often use paid ads to create the impression of legitimacy, sometimes borrowing the faces of public figures, media brands or financial institutions. By the time an ad is reported and removed, victims may already have been funnelled into private chats or fraudulent websites.

Marketplaces also under scrutiny

Singapore is also tightening rules for e-commerce platforms. An enhanced E-Commerce Code covering Carousell, Facebook Marketplace and Facebook Business Pages will introduce stronger controls on logins from unrecognised devices.

Marketplaces have long been vulnerable because they combine informal peer-to-peer transactions with a high volume of listings. Scams can range from fake concert tickets and rental listings to non-delivery of goods and phishing links disguised as payment or delivery pages. Stronger login controls may help limit account takeovers, where criminals use legitimate-looking profiles to trick buyers or sellers.

Also Read: AI phishing is turning trust into APAC cybersecurity’s weakest link

Police said scam cases on services already covered by earlier codes fell by about 37 per cent between 2024 and 2025. That suggests platform rules can have an impact, although the latest iMessage case also shows that fraudsters keep searching for gaps.

The stakes are set to rise further. The government has proposed increasing the maximum penalty for non-compliance to S$10 million (US$7.8 million) per breach. More details are expected when the Scams (Countermeasures) and Other Matters Bill is debated in Parliament in September.

For startups and digital platforms in Southeast Asia, Singapore’s direction of travel is worth watching. The city-state often acts as a regulatory reference point for the region, especially in fintech, digital identity and online safety. Measures introduced there can influence how other markets think about platform responsibility.

For consumers, however, the immediate lesson is more basic: the channel does not guarantee the sender. A message arriving through iMessage, WhatsApp, Telegram, Facebook or TikTok may still lead to the same spoofed payment page. In the current scam economy, trust is no longer attached to the app. It has to be earned at every click.

The post Singapore disrupts 30,000 iMessage accounts as scam losses hit US$1.7M appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *