Singapore Beat the Sprint. The Scammers Switched to a Marathon.

Singapore's scam losses fell 17.9% in the first half of 2026, to S$410.6 million. Police disrupted over 47,000 scam-related mobile lines. On paper, the system is winning.
Then look at what actually made news this week. 52 Singaporeans arrested in Guangxi over suspected pyramid scheme activities, linked to an operation that has allegedly run in various forms for years. Police flagging 21 "pump and dump" stock scams since July, built on WhatsApp trading groups and manufactured credibility. A sextortion advisory covering 52 cases where contact was established, moved to private messaging, and only later turned into a threat. None of these look anything like the scam Singapore has spent the last two years getting good at stopping.
That is the scam the Shared Responsibility Framework was designed around: fast, unauthorised account draining following phishing. Cooling-off periods after new device logins, real-time transfer alerts, kill switches — every one of these defences assumes the attack looks sudden, because for years, it was.
The Nanning pyramid scheme, the pump-and-dump chat groups, and the sextortion wave share exactly one trait: nothing about them looks sudden.
The system was built to catch a sprint. These scams win by never running.
What a slow scam actually looks like
A first-time investor doesn't wire S$650,000 to a stranger. In one recent case, a couple did it after weeks of a "professor" sending detailed lessons on reading bullish markets before ever naming a stock. By the time the ask comes, it doesn't feel like a decision — it feels like the logical next step in something they've already invested weeks into.
A Singaporean doesn't fly to Nanning and hand over S$75,000 on day one either. She's invited by a friend, shown a room full of people who look like her, given time to watch others describe how well it's worked out for them. The recruitment pitch isn't the transfer — the transfer is what happens after weeks of manufactured normalcy have done the actual convincing.
And sextortion rarely opens with the threat. Contact starts on a dating app, moves to private messaging, and only turns into a demand once the "relationship" feels established enough that the ask seems like a betrayal rather than a warning sign.
The detection isn't the problem — the override is
Banks already have systems and frontline controls that can identify many suspicious transactions. That's exactly how Bank of China staff stopped a 70-year-old customer from handing over S$355,000 last year — flagging his insistence on a large cash withdrawal, his visible impatience, and verifying his story with his daughter before releasing a cent. It's also how a joint police-bank operation flagged over 4,100 potential scam cases in a single two-month stretch and averted S$54.6 million before it left customers' accounts. The system sees plenty of this.
The harder problem is what happens when the system sees the risk, raises the warning — and the customer overrides it, because a scammer has spent weeks building a trust that five minutes of bank intervention cannot undo. One UOB customer was warned by staff that her online "husband" had never once asked to meet her in person. She agreed not to transfer the money — then came back days later to try again, and turned on the staff who froze her account when they wouldn't let her.
The system doesn't always fail to see these scams. Sometimes it sees them, says something — and gets overruled by a trust the victim spent weeks building with someone else.
The shift nobody is measuring
The real distinction here isn't fast versus slow. It's unauthorised fraud versus authorised fraud — and Singapore's own numbers say which way this is trending. Police have said that even as overall losses fall, eight in 10 victims are still being manipulated into handing money over voluntarily, rather than having it taken from an account they didn't touch.
Unauthorised fraud is a transaction-monitoring problem: something moved that the customer didn't approve, and the job is to catch it fast. Authorised fraud is a persuasion problem: the customer approved it, understood they were sending money, and did it anyway — because the story they'd been told made it feel correct. Singapore has built genuinely strong infrastructure for the first kind. The pyramid scheme, the pump-and-dump groups, and the sextortion cases all sit in the second.
Why the numbers still say Singapore is winning
They're not wrong — they're measuring the fight that's easier to win. Phishing is disruptable at the infrastructure level: block the sender ID, flag the fast withdrawal, and the scam simply can't execute.
But investment scams still posted the highest dollar loss of any category in H1 2026 — S$169.8 million across 2,256 cases, or roughly S$75,000 per case — and social media impersonation losses jumped 71.3% year-on-year. These numbers don't prove slow scams are replacing fast ones. They show something more specific: the losses that remain are increasingly concentrated in scams where the victim participates rather than simply gets tricked into a click.
What banks need to do differently
If a five-minute warning consistently loses to weeks of grooming, the fix isn't a louder warning — it's rethinking what happens after a customer says "I understand, proceed anyway." Three layers worth separating:
Detect — the part Singapore's banks are already reasonably good at, per the BOC and Anti-Scam Centre examples above.
Interrupt — a risk-based cooling-off period for selected high-risk transfers (large, first-time, to a newly added payee) buys time without treating every big transaction like a crime in progress. Legitimate property purchases and business payments still need to move; this only needs to slow the ones that match a known risk profile.
Challenge the override — this is the layer largely missing today. When a customer insists on proceeding despite a flag, "customer confirmed" shouldn't be the end of the process for the highest-risk cases. Independent verification — through a separately established contact or trusted party, with the customer's consent — adds a second person to a decision the scammer worked hard to keep private.
The harder conversation is scope. MAS has acknowledged how difficult it is to separate a bad trade from a manipulated one, and that's fair. But the SRF's current fraud-surveillance duty is written for drains, not for a correctly flagged transaction the customer pushes through anyway. Extending some accountability to what a bank does after a legitimate flag — not just whether it flags at all — would close a gap that's currently invisible in the statistics, precisely because the system technically did its job.
Takeaways
For businesses — especially financial institutions and platforms handling customer transactions: the priority isn't better detection, it's better protection at the point a customer is about to override a warning. Build controls that don't rely on the customer agreeing with you — risk-based cooling-off periods, independent verification for high-risk transfers, and holds that require more than a customer's insistence to lift. A flagged transaction that still goes through isn't a compliance success; make sure your customer-facing controls, not just your internal metrics, reflect that.
For individuals: the feeling of trust you have right before a scam lands wasn't earned — it was built, on a schedule, for a reason. If a relationship, an investment tip, or a business opportunity only started feeling safe after weeks of careful pacing, that pacing was the pitch. And if your bank pushes back on a transfer, that friction isn't the inconvenience — it's the last checkpoint between you and someone who's been working toward this exact moment for weeks. The next generation of scams won't necessarily try to beat the bank's controls. They'll spend enough time convincing you to beat them yourself.




Comments