The Police have arrested a 25-year-old man and two women, aged 29 and 38, for their suspected involvement in a coordinated scheme that compromised the Singpass accounts of work permit holders. Since early August 2026, at least 23 work permit holders have reported that their Singpass accounts were locked after being approached and offered an $80 cash incentive in exchange for access to their Singpass accounts. Some of these work permit holders were told that their Singpass accounts would be used to purchase National Day Parade (NDP) tickets at a discounted price of $500.
After agreeing to participate in the scheme, these work permit holders were instructed to meet the perpetrators at locations including MRT stations, HDB residential areas, and construction sites. They would then either meet the perpetrators directly or be driven to nearby locations where the perpetrators would scan their work permits and obtain their Singpass passwords. Using the compromised Singpass accounts, the perpetrators were able to apply for telco or financial accounts.
Between 5 and 6 August 2026, officers from the Cyber Command and Clementi Division, with strong support from the Singpass Trust & Safety team at the Government Technology Agency of Singapore (GovTech), launched an operation to establish the identities of the syndicate members and take enforcement action against them. The operation resulted in the arrest of the three individuals for their involvement in obtaining the work permit holders’ Singpass login credentials.
Further investigations identified another 136 foreign workers whose accounts were linked to the same activity. The fraudulently obtained Singpass accounts were used to register for more than 30 LiquidPay accounts and over 1200 phone lines without the work permit holders’ knowledge. All affected LiquidPay accounts have been frozen and the fraudulent phone lines have since been terminated.
The three individuals will be charged in court on 8 August 2026 with the offence of obtaining the Singpass credential of another person under Section 8B(1)(a) of the Computer Misuse Act 1993. The offence carries a fine not exceeding $10,000 or to an imprisonment for a term not exceeding 3 years or to both.
Police investigations into work permit holders who voluntarily relinquished their Singpass credentials are ongoing. Under Section 8A(1) of the Computer Misuse Act, disclosing one’s Singpass credentials to facilitate an offence carries a fine not exceeding $10,000 or to an imprisonment for a term not exceeding 3 years or to both.
The Police urge the public not to accept offers of quick monetary gains in exchange for their Singpass accounts or credentials. Members of the public should never disclose their Singpass passwords or Two-Factor Authentication (2FA) details to unknown persons, as these may be misused to access various digital services, including the opening of bank accounts, e-wallets, crypto accounts, and mobile phone lines for illegal activities. Individuals found to be linked to such crimes will be held accountable.
NDP tickets are strictly not for sale. If you are offered discounted tickets or any financial incentive that requires you to provide personal login details, verify the offer directly with the official organising body through recognised channels.
You are also encouraged to check the number of postpaid SIM cards you hold, by visiting SIMCardHowMany (Beta). If you spot discrepancies or suspect that your postpaid SIM cards were fraudulently registered, please report to your telcos and the Police.
If you have any information relating to such crimes, please call the Police Hotline at 1800-255-0000, or submit information online at www.police.gov.sg/i-witness. For more information on scams, members of public can visit www.scamshield.gov.sg, or call the ScamShield Helpline at 1799. If you require urgent Police assistance, please dial ‘999’. All information will be kept strictly confidential.
PUBLIC AFFAIRS DEPARTMENT
SINGAPORE POLICE FORCE
07 August 2026 @ 10:10 PM
