On 4 August 2026, Singapore’s Ministry of Home Affairs (MHA) introduced the Scams (Countermeasures) and Other Matters Bill for its first reading in Parliament. The Bill is the next step in a national campaign against a fraud problem that has proved stubbornly resilient, and it reaches well beyond the police station: it rewires the obligations of banks, payment firms and online platforms that sit, often unwittingly, in the path of stolen money.
Rather than create a single new statute, the Bill amends several existing laws at once: the Protection from Scams Act, the Online Criminal Harms Act (OCHA), the Banking Act and the Police Force Act. The through-line is speed: giving enforcement agencies faster access to information and quicker levers to cut off the accounts and services that scammers rely on. It builds on the Protection from Scams Act, which came into force in early 2025 and first allowed the police to restrict the banking transactions of people being actively defrauded.
A wider net around the scam economy
Singapore’s difficulty is not a shortage of laws but the industrial scale of the mule networks that launder scam proceeds. As of 30 June 2026, the authorities were dealing with roughly 1,423 money mules and 1,439 SIM card mules, the disposable accounts and phone lines that let syndicates move funds and messages while staying a step ahead of investigators. The same pattern runs through cases our newsroom has examined, from the Fun Coffee crypto scam to the sprawling, cross-border operations run by Chen Zhi’s lieutenants: money and identities move faster than any single institution can react.
The Bill’s answer is to make information move faster too, and to let the state intervene at the account and service level before losses mount.
New duties for banks and service providers
The measures that matter most to compliance teams fall into three groups.
- Compelled information-sharing. The police will be able to issue Disclosure Orders requiring service providers to hand over scam-related account information, feeding a National Scams List so that intelligence can be pooled across institutions rather than siloed inside each one.
- Account and facility restrictions. The Bill introduces Account Disabling Orders, which can suspend an account for up to 60 days in total, and Service Limitation Orders, which can restrict the financial and telecommunications services available to an identified person for up to three years.
- New offences for account misuse. It creates offences for the unlawful provision of personal information and for the possession, supply and receipt of online accounts used in criminal activity, aimed squarely at the mule market that keeps the scam economy liquid.
Crucially for banks, the Bill also amends the Protection from Scams Act so that officers can request information about account holders subject to Restriction Orders, working around the confidentiality obligations that the Banking Act would otherwise impose. It is a deliberate carve-out: a signal that the Government views anti-scam intelligence as a case where secrecy must yield to speed.
Penalties with real weight
The Bill puts financial force behind the new duties. Online service providers that fail to comply with obligations under the strengthened OCHA regime can face penalties of up to S$10 million per instance, and non-compliance with a rectification order can attract penalties of up to S$10 million plus a further S$300,000 for every day the breach continues. For platforms and institutions operating at Singapore scale, those numbers are large enough to make compliance a board-level concern rather than a back-office one.
What it means for compliance teams
For MLROs, fraud teams and platform-integrity functions operating in Singapore, the Bill reads as a set of near-term operational expectations rather than distant policy:
- Stand up rapid-response processes for Disclosure Orders, Account Disabling Orders and Service Limitation Orders, with clear internal ownership and audit trails, so that lawful requests can be actioned within tight windows.
- Revisit mule-account detection. With new offences targeting the supply and receipt of accounts, expect supervisors to scrutinise onboarding controls more closely and how quickly suspected mule accounts are identified and frozen.
- Map the information-sharing framework against your data-governance and privacy controls, given the deliberate override of Banking Act confidentiality for accounts under Restriction Orders.
- Treat scam controls as enforcement risk. The scale of the penalties, alongside Singapore’s broader tightening of financial-crime obligations, makes this a compliance exposure, not just a customer-protection nicety.
The Bill is led by the Ministry of Home Affairs rather than the Monetary Authority of Singapore, a reminder that scam defence in Singapore is now a whole-of-government effort that pulls policing, telecoms and financial regulation into the same frame. It still has to pass through Parliament, and the detailed subsidiary rules will shape how the new orders operate in practice. But the direction is unmistakable: institutions in the payment and communications chain are being enlisted, with legal force, on the front line of Singapore’s fight against scams.
Read the MHA announcement and the Bill text here.
