Scammers can use publicly available names, designations, work contact details and organisational information to make a false identity appear plausible. The Singapore Government Directory previously listed information such as public officers’ names, job titles, e-mail addresses and office numbers. Singapore has since pared back many officers’ contact details to reduce the material available for impersonation and social engineering.
Directory information is useful for making a story sound authentic, but it is not an identity check. Information copied before the change may still circulate, and other public or leaked information can help scammers fill in the gaps.
The caller may claim that the target is connected to money laundering, an investigation, an immigration or employment issue, or another official matter. A common pattern is to create fear of arrest, account suspension or legal consequences, then offer a supposed solution that requires immediate action.
Scammers may also transfer the victim between people posing as officers from different agencies, supervisors, police officers or banks. This staged organisational chain can make the interaction feel procedural even though every participant is part of the same deception. ScamShield has specifically warned about unsolicited phone calls and in-app calls, including WhatsApp video calls, allegedly from agencies such as the Singapore Police Force or the Monetary Authority of Singapore.
A scammer may send a falsified official-looking document or a doctored staff pass after a call. In one advisory, the Ministry of Law described a variant in which a purported officer requested images of a victim’s NRIC and then used falsified documents and a doctored staff-pass image to increase credibility.
Other signals may include a spoofed caller ID, official branding, a familiar-looking profile name or image, and knowledge of how agencies work together. These are presentation techniques, not reliable authentication.
Once the victim accepts the false identity, the scammer may ask for identification details, banking information, SingPass or CPF-related information, social-media details or one-time passwords. Other requests can include transferring money to a supposed “safe account,” clicking a link, opening a file, installing software or handing over valuables.
The harm is not limited to an immediate financial transfer. A person who shares confidential work documents, credentials or internal correspondence may create a security incident even if no money is lost. The published scam statistics do not separately quantify document-exfiltration or corporate-espionage losses, so the scale of that risk cannot be inferred from the figures below.
| Measure | 2024 | 2025 | Change |
|---|---|---|---|
| Government-official impersonation scam cases | 1,504 | 3,363 | +123.6% |
| Losses from that category | S$151.3 million | About S$242.9 million | +60.5% |
| All scam cases | 51,501 | 37,308 | −27.6% |
| All scam losses | About S$1.1124 billion | About S$913.1 million | −17.9% |
Government-official impersonation scams were therefore an outlier in 2025: cases more than doubled and losses increased by more than half while the overall scam totals declined. The category recorded the second-highest losses among scam types that year.
From 1 July 2026, the Singapore Government Directory was streamlined, with contact information mainly retained for political office-holders, judicial appointment holders, senior management and selected direct contact points. The stated objective was to reduce the risk that publicly available officer details would be used in scams.
This reduces exposure; it does not retroactively remove copied information or authenticate every person who claims to be a public officer.
Singapore telcos have blocked commonly spoofed trusted local numbers, including government agencies and emergency hotlines, since 2019. Incoming international calls have carried a + prefix since April 2020, giving recipients a signal that a call is coming from overseas. Telcos also began blocking international calls that spoof local Singapore numbers in December 2022.
These controls can reduce some phone-based abuse, but a warning signal is not proof that an unflagged call is legitimate. Messaging-app calls and profiles do not necessarily pass through the same telephone-network controls.
ScamShield provides a 24/7 helpline at 1799, an app, a website and reporting or checking channels. Its tools can help users identify, filter and report suspicious calls, messages, websites and links, but users should not treat a clean result as a guarantee that a caller is genuine.
Government SMSes should use the gov.sg sender ID rather than an ordinary mobile number. That check is useful for SMS, but it does not authenticate a WhatsApp account, phone call or document received through another channel.
A WhatsApp profile can present a convincing name and image, and an in-app voice or video call can feel more personal than a text message. But the visual identity remains controlled by the account holder, not verified by the government agency. ScamShield includes in-app impersonation calls in its warnings.
A scammer does not need to impersonate only one official. By claiming to transfer a call between agencies or departments, the scammer can manufacture the appearance of a coordinated investigation. That makes it especially important not to verify one unsolicited contact using another contact supplied by the same conversation.
Removing directory entries lowers the amount of information available for targeting, but it cannot establish that a caller, profile or document is genuine. Identity must be checked through a separate channel controlled by the agency.
Use this sequence whenever an unsolicited contact claims to be from a government agency:
For agencies and employers, the same principle should apply to document requests: use authenticated portals or access-controlled channels for sensitive files, and require a second-person check for unusual requests from an unfamiliar or unexpected contact.
Singapore’s directory changes and telco controls reduce opportunities for impersonation, but they cannot make a caller’s appearance, title or profile trustworthy by default. The durable defence is procedural: pause, refuse requests for money or secrets, and verify independently through an official channel.
If the contact is genuine, an agency can survive a callback. If it is a scam, the callback breaks the staged chain of trust.