The Singapore Police Force (SPF) has detected and disrupted more than 30,000 Apple iMessage accounts used in a phishing campaign, according to an advisory issued on 20 August 2026. The force's Cyber Command has been acting against the accounts since June 2026, and reported losses have reached about S$2.2 million, up from the S$1.2 million and at least 251 cases cited in an earlier advisory on 5 August 2026.
How the scam works
A typical message claims a delivery has failed over an "invalid" address and pushes the recipient to reply "Y" or "1" to sort it out. That reply is the pivot: once a user responds, iMessage stops treating the sender as unknown, and the phishing link that was previously blocked from being tapped becomes clickable. Victims are then routed to sites mimicking courier or bank pages, where they enter card numbers and banking log-ins. In a number of cases the operators loaded the stolen cards into digital wallets or provisioned tokens to unfamiliar devices after intercepting one-time passwords, allowing them to push through unauthorised transactions.
The texts impersonated courier firms including NinjaVan, J&T Express and SPX Express, and at times government agencies or banks. A giveaway, SPF said, is where the message originates: rather than a local line, it typically comes from an overseas number, with codes like +212, +63 or +44 seen in the campaign, or from a throwaway email address that is little more than a jumble of letters and digits.
Why scammers turned to iMessage
SPF noted that "Government agencies and courier companies do not use iMessage in their communications with the public." The choice of channel is deliberate. Legitimate business texts in Singapore must use registered alphanumeric Sender IDs under the Full SMS Sender ID Registry, mandatory since January 2023, with unregistered IDs flagged as "Likely-SCAM." iMessage is an internet-based service that sits outside that registry, so it sidesteps the Sender ID safeguard that has pushed fraud off conventional SMS.
The wider anti-scam response
The campaign lands against a tightening enforcement backdrop. Under the Protection from Scams Act 2025, in force since 1 July 2025, police can issue Restriction Orders directing banks to temporarily suspend a target's transfers and withdrawals while the person is being manipulated. On the prevention side, the Shared Responsibility Framework that MAS and IMDA brought into effect on 16 December 2024 makes banks and telcos financially liable for phishing losses where they fall short of set duties: telcos must block texts from unauthorised Sender IDs and filter messages carrying malicious links, while banks must run real-time surveillance for the rapid draining of accounts.
This scam also targets the exact control that regulators have been reinforcing. Since 2024, major banks have phased out SMS one-time passwords for customers with digital tokens, requiring the token to approve logins and transactions, which is why the phishing sites press victims to authorise token requests rather than simply hand over an OTP.
SPF advised iMessage users to reduce their exposure by enabling the app's built-in controls, specifically:
- the "Filter Unknown Senders" setting, which separates messages from people not in a user's contacts; and
- the "Filter Spam" setting, which screens messages flagged as spam.
Suspicious messages can be reported through the in-app tools or the ScamShield Helpline on 1799, and scams flagged to the police at 1800-255-0000.
Why it matters: the takedown shows fraud migrating to over-the-top messaging that sits outside Singapore's SMS Sender ID controls, and the near-doubling of reported losses in weeks underlines how fast messaging-based phishing can scale. For banks and compliance teams, the campaign's focus on hijacking digital-token approvals is a direct test of the fraud-surveillance and shared-liability duties that recent frameworks now impose.
