In the fortnight to 10 September 2026 the Singapore Police Force published two operations back to back. The first, run with five banks over two months, disrupted more than 400 scam attempts before the money left. The second, run across the island for two weeks, ended with 254 people assisting with investigations as scammers or money mules. Read as a business, the two releases describe two different exposures landing on the same company at once. Your business is a target: business email compromise is the scam series aimed at the people who pay your suppliers, and its losses nearly tripled while total scam losses fell. And your business is now inside the net: the money-laundering offences that catch mules were written, in the Ministry of Home Affairs' words, to apply to directors and corporate accounts, and the bank framework that makes good a phishing loss does not extend to a company account.

The Answer in 60 Seconds On 8 September 2026 SPF reported that its Anti-Scam Centre had "partnered with five banks - DBS, UOB, OCBC, SCB and GXS" in "a two-month joint operation, successfully disrupting over 400 scam attempts", sending "over 3,300 SMS alerts to more than 2,700 bank customers" between 1 July and 31 August and averting "over $46 million in potential losses" (SPF, 8 September 2026). Two days later it reported a two-week islandwide operation in which "151 men and 103 women, aged between 15 and 79, are assisting with investigations for their suspected involvement in scams as scammers or money mules", linked to more than 652 cases and around $7.5 million lost (SPF, 10 September 2026). Behind both sits the mid-year brief: scam losses fell 17.9 percent to about S$410.6 million in the first half of 2026, while business email compromise losses "recorded a significant increase of 193.1% in the amount lost to S$57.3 million" on 262 reported cases (SPF Mid-Year Scam and Cybercrime Brief 2026).

Two facts decide what a company carries. First, the Shared Responsibility Framework, under which a bank or telco that breaches a stated duty is expected to bear a phishing loss, applies to a "protected account", defined as a payment account "held in the name of one or more persons, all of whom are individuals", and its guidelines add that once the bank and the telco have met their duties "the account holder of a protected account should bear any loss" (MAS, Guidelines on Shared Responsibility Framework). A company account is outside it. Second, the rash and negligent money-laundering offences in force since 8 February 2024 apply, in MHA's words, "to persons acting as directors of companies and operating corporate accounts" (MHA, 7 February 2024), and 53 corporate entities were under facility restrictions as mule accounts at 30 June 2026 (SPF Mid-Year Brief 2026, Annex F). Of two published cyber wordings, one covers impersonation fraud only where the instruction was verified before the loss, by a defined call-back or, for an e-mail, by confirming the genuine requestor's work e-mail address was used, and the other has no first-party social-engineering cover at all. The documents you hold, and the payment procedure you can prove, decide the rest.

The Sourced Detail

Two operations in one fortnight

The 8 September release describes prevention at the bank. The Anti-Scam Centre and the five banks used robotic process automation to identify customers making the incremental transfers that mark an investment or job scam in progress, and SPF states that "a large proportion of these detections were attributed to investment and job scams, in which victims were deceived into making multiple incremental transfers to scammers' bank accounts" (SPF, 8 September 2026). Its advice in the same release is the plainest control a business can copy: "Transaction limits for internet banking, including PayNow, could also be set up to limit the amount of funds that can be lost in the event of a scam."

The 10 September release describes enforcement at the other end of the pipe. Cyber Command and the seven land divisions ran "a two-week operation between 27 August 2026 and 9 September 2026", and the 254 people assisting with investigations "are believed to be involved in more than 652 cases of scams, comprising mainly e-commerce scams, phishing scams, job scams, government official impersonation scams, investment scams and lucky draw scams" (SPF, 10 September 2026). The release then lists the offences as SPF states them: cheating under section 420 of the Penal Code 1871 "carries an imprisonment term of up to 10 years and a fine"; money laundering under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 "carries an imprisonment term of up to 10 years, a fine of up to $500,000, or both"; and "scam mules who enable scammers by laundering scam proceeds, providing SIM cards and providing Singpass credentials will face discretionary caning of up to 12 strokes."

The two releases are one system. The first stops the transfer that the second prosecutes, and the second names the three instruments a mule supplies: a payment account, a SIM card, a Singpass. A company holds the first two, and its officers hold the Singpass and the Corppass that operate its accounts. A company holds all three.

The scam that arrives as a job offer

On 14 August 2026 SPF and the Cyber Security Agency issued a joint advisory that reads, on its face, as a warning about fake job offers, and reads on a second pass as an intrusion report. A scammer posing as a recruiter approached the victim on LinkedIn, ran video interviews with the camera off, and had him "complete a technical coding assessment on his company-issued device" on a spoofed website (SPF-CSA joint advisory AD-2026-010, 14 August 2026). The assessment installed malware which, in the advisory's words, "enabled the scammer to bypass authentication controls to harvest internal company credentials, and used them to carry out cryptocurrency transfers", with losses of USD 11.8 million (the joint news release linked from the advisory).

The measures SPF and CSA put to businesses in that release are not the usual list. "Businesses should implement transaction limits, approval workflows, and other safeguards at the API level that cannot be bypassed by direct API calls"; "while multi-factor authentication (MFA) is an important safeguard, individuals and businesses should be aware that session token harvesting can bypass MFA"; and "changes to deployment instructions should be subject to multi-party review and approval" (SPF-CSA joint news release, 14 August 2026). The employee was the door; the company's systems were the room. ScamShield's job-scam page names the other version of the same scam, in which the "job" is the transfer itself: "another 'job' offered to victims entails transfer of funds to bank accounts provided by the scammers, for a small commission", and a job is likely a scam if it requires you to "use your personal bank account as part of the job" or "disclose your Singpass credentials" (ScamShield, job scams). The recruit is being hired as a mule.

The business-facing series moving against the trend

The three headline totals in the mid-year brief fell. Scam cases were down 14.4 percent to 16,821, losses down 17.9 percent to about S$410.6 million, and cases with losses of S$100,000 or more down 24.5 percent (SPF Mid-Year Scam and Cybercrime Brief 2026). Business email compromise went the other way: the amount lost rose 193.1 percent to S$57.3 million from S$19.5 million, and the case count rose 67.9 percent to 262 from 156. SPF's own description of the scam is the description of an accounts-payable process: scammers "impersonate business entities (e.g. suppliers, vendors, clients) or individuals within organisations (e.g. senior executives, management, staff), and deceive victims into diverting payments to fraudulent bank accounts or fulfilling monetary requests." Annex C names the prominent variant, emails "informing or requesting a change in bank account details for payment", sometimes carrying "fraudulent invoices with actual company details (e.g. address, letterhead, signature, company stamp)".

The brief also records how the money leaves. "The percentage of reported scams involving self-effected transfers rose to 80.8% in the first half of 2026, from 78.8%", and "in most cases, scammers did not gain direct control of victims' accounts, but manipulated victims into making monetary transactions through deception and social engineering" (SPF Mid-Year Brief 2026, paragraph 8). That distinction matters for every document that follows: a payment your own staff released on a false instruction is not a "seemingly authorised transaction" in the MAS framework's definition, because no credential was stolen and used for a transfer you did not intend, and the published wordings treat it differently from a hacked account.

SPF had already flagged the vendor-bank-details variant on 20 May 2026: "since 1 January 2026, at least 66 cases were reported, with total losses amounting to at least $19 million", by scammers who "impersonate the victims' colleagues or business vendors using spoofed email addresses or by compromising the vendors' email accounts" (SPF advisory, 20 May 2026). Three of the eight measures it puts to businesses: "verify with the email sender through a different medium (i.e., phone call, text message or enterprise communication channels) before proceeding with any change in payment instructions", enable two-factor authentication on email, and "implement Domain-based Message Authentication, Reporting, and Conformance (DMARC) on your organisation's email domain".

One case shows the recovery side and its dependence on speed. On 29 April 2026 a Singapore commodity trading firm transferred USD 6.6 million to a fraudulent account in Oman after receiving payment instructions from a domain in which "the domain name had been subtly altered by transposing two letters"; the fraud surfaced on 30 April when the genuine supplier said it had not changed its account, and the full sum was recovered through HSBC Singapore, the Dubai Police Anti-Fraud Centre and the Royal Oman Police (SPF, 5 May 2026). SPF's instruction in that release: verify "by calling your supplier or counterparty on a trusted number that has been independently verified, and never rely solely on contact details provided in the same email chain".

Your account, your Corppass, your directors

The second exposure is the one no accounts-payable control touches, because it concerns what your company's own accounts are used for. Section 51(1) of the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 makes it an offence to be "concerned in an arrangement, knowing or having reasonable grounds to believe" that it facilitates another person's "benefits from criminal conduct", with a fine of up to $500,000 or ten years' imprisonment or both (CDSA 1992, section 51). Since 8 February 2024, section 51(1A) adds two lower thresholds, "rashly" (up to $250,000 and five years) and "negligently" (up to $150,000 and three years), and section 51(7) addresses the company itself: a person "who is not an individual" is liable "to a fine not exceeding $1 million or twice the value of the benefits from criminal conduct in respect of which the offence was committed, whichever is higher."

MHA's commencement release puts those provisions in a business owner's terms. Rash means "carrying out a transaction to deal with property for someone else while he had some suspicions that he could be dealing with benefits of crime, but did not make further enquiries"; negligent means "continuing with a transaction despite obvious red flags noticeable by any reasonable person"; and then the sentence that moves this from a consumer warning to a corporate one: "This applies to persons acting as directors of companies and operating corporate accounts" (MHA, 7 February 2024). The same release states the duty in the affirmative: "Owners as well as operators of payment accounts, including personal and corporate bank accounts, must use their accounts responsibly. They will be held accountable for any transaction that takes place through their accounts." MHA also records what the offences are not for: the Singpass provision is "not intended to penalise persons who were genuinely tricked", and the Act carries the defences at sections 51(4) and 55A(3) and (4).

Section 55A supplies a third route that needs no proof of what you knew: the prosecution must still show the arrangement handled another person's criminal benefits, but the offence turns on the circumstances, not on your state of mind. An arrangement is caught where, among other circumstances, a person "enables B or any other person to access, operate or control a payment account which A is able to access, operate or control" and "fails to take reasonable steps to ascertain the purpose", or where money moves through such an account and the person "fails to take reasonable steps to ascertain the source or destination of the money" (CDSA 1992, section 55A). The individual penalty is up to $50,000 or three years; a non-individual faces its own fine under section 55A(6). A director who lets a business partner, an agent or a "client" route funds through the company account has supplied the first half of circumstance (ii); the second half is a failure to take reasonable steps to ascertain the purpose, and section 55A(3) adds the defence of proving no knowledge and no reasonable ground to believe the money was criminal benefits.

The Computer Misuse Act 1993 covers the third instrument. Section 8A makes it an offence for a Singpass user to disclose a password or access code "knowing, or having reasonable grounds to believe" that it is for any person to commit or facilitate an offence, and presumes those grounds where the user "does the act for any gain" or "fails to take reasonable steps to ascertain the identity and physical location of the person" receiving it (CMA 1993, section 8A); section 8B catches anyone who obtains, retains or supplies another person's credential (CMA 1993, section 8B). Since 30 December 2025 discretionary caning attaches to these offences where a scam is involved, and SPF states one of its conditions as the enabler having been "used to commit or facilitate scams and the accused is unable to prove to the satisfaction of the court that he had taken reasonable steps to prevent such a result" (SPF, Caning for Scams and Scams-related Offences).

Enforcement is running through those provisions, and it has reached companies. In 2025 SPF charged "more than 940 scammers and money mules", "including more than 530 of them under the amended laws" of the CDSA and the CMA (SPF Annual Scam and Cybercrime Brief 2025). The Facility Restriction Framework, operational from 1 October 2025, had placed "1,423 money mules, 1,439 telco mules, and 53 corporate mules" under restrictions by 30 June 2026, and was extended on 1 July 2026 to "restrictions on the use of Singpass to register for high-risk services that could be exploited for scams such as bank accounts, mobile lines and corporate entities" (SPF Mid-Year Brief 2026, Annex F). When the framework was announced, SPF, MAS, IMDA and GovTech said plainly that "the Police have also observed an increase in scam lines that are registered by corporate entities", and listed among the restrictions "access to existing Corppass accounts (if any)" (SPF, MAS, IMDA and GovTech, 17 September 2025). A restriction can be imposed on persons "under investigation for mule-related offences and are assessed to be at risk of further facilitating scams", before any charge. For a company, the facility named is its Corppass.

What the bank owes you, and what it does not

The Shared Responsibility Framework is the published basis on which a phishing loss is made good. Read its scope. The guidelines apply to a "seemingly authorised transaction" perpetrated through impersonation of a legitimate business or government entity, where the scammer obtained the account user's credentials through a digital messaging platform and used them for transactions the user did not intend (MAS, Guidelines on Shared Responsibility Framework). They protect a "protected account", meaning a payment account that "is held in the name of one or more persons, all of whom are individuals", and the footnote defines that as an account "opened with the retail business unit of the responsible FI, or cannot be used for transactions in the course of business". The duties it imposes on banks (a 12-hour cooling-off period on a new digital token, real-time alerts, a kill switch, real-time fraud surveillance) are owed on protected accounts, and paragraph 6.7 closes the loop for everyone: where the bank has met its duties and the telco has met its duties, "the account holder of a protected account should bear any loss arising from a seemingly authorised transaction". MAS's implementation release adds that "beyond the SRF, banks also have their respective discretionary goodwill frameworks to support scam victims" (MAS and IMDA, 24 October 2024). A company account is outside the framework by definition, and a business email compromise payment is outside it by mechanism, because your staff authorised it.

The Protection from Scams Act 2025, in force from 1 July 2025, lets a police officer issue a Restriction Order to a bank where he has "reasonable belief" that "the individual will execute a money transfer to a scammer", restricting outward transfers, ATM facilities and credit facilities for up to 30 days at a time; 18 had been issued by 30 June 2026 (Protection from Scams Act 2025; MHA, 30 June 2025; SPF Mid-Year Brief 2026, Annex F). It is written for the individual about to pay, and it reimburses nobody.

What the published wordings say

Two published cyber wordings, one issued for Singapore and one for the Asia Pacific region, do not agree on crime cover. AIG Asia Pacific Insurance's CyberEdge wording for Singapore carries a Cyber Crime coverage section whose Impersonation Fraud cover is "subject to the condition that the Fraudulent Instruction was Verified prior to the Impersonation Fraud Loss" (AIG Asia Pacific Insurance, CyberEdge policy wording, Singapore). A Fraudulent Instruction is a payment instruction from someone purporting to be your own authorised associate, or your vendor's or client's, but "in fact fraudulently transmitted by someone else"; Verified means confirmation "verified independently from the person who communicated the Fraudulent Instruction", by a call-back to a number "held on file by the Insured", in its internal directory or "verifiable into the public domain", or for an e-mail "by verifying and ensuring that the genuine requestors' work e-mail address has been used". Exclusion 3.3 removes loss from "theft or any other fraudulent, dishonest or criminal act by a Client or Vendor" or their employees; condition 4.1 requires "a written, detailed and affirmed proof of loss within sixty (60) days after the Discovery"; the costs of proving the loss are not covered; and where the schedule specifies a sub-limit for the section, payment is capped at it and the sub-limit sits inside the aggregate limit.

QBE's published Asia Pacific Cyber and Data Security wording contains no impersonation fraud, funds transfer fraud or social engineering cover. Its crime-shaped clause, 1.3.4 "Hacker financial crime cover", indemnifies "all sums which the insured shall become legally liable to pay" as a result of "a third party's good faith reliance on a hacker's fraudulent use of information and communication assets", within a sub-limit inclusive of defence costs (QBE, Cyber and Data Security policy wording). That is a liability cover for what a third party lost by relying on a hacker who used your systems, not a cover for your own funds sent on a false instruction.

Two other published Singapore documents show what the market asks before it writes the cover. MSIG Insurance (Singapore)'s social-engineering addendum to its cyber proposal form asks whether "all requests to change customer and supplier details (particularly bank details)" are "independently verified", whether "all payments (including cheque signing and fund transfers) above SGD10,000" are "subject to authorisation by 2 authorised employees", and whether staff receive training that includes "social engineering fraud, phishing, phreaking and cyber fraud" (MSIG Insurance (Singapore), Addendum for Cyber Insurance and Data Protection - Social Engineering). Chubb Insurance Singapore's SME Pre-Priced Program 2025 proposal form for its Cyber ERM policy lists cyber crime and telecommunications fraud as extensions with their own stated sub-limits (Chubb Insurance Singapore, Cyber ERM SME proposal form). The underwriting questions and SPF's advisories ask for the same two things, independent verification of a changed bank detail and trained staff, and the SPF-CSA release adds approval workflows and multi-party review where the company moves funds. The answers you give on the form are facts the insurer holds, and the addendum's own notice says a failure to disclose "fully and faithfully" means "the Policy issued hereunder may be void".

When the scam also takes personal data, a fourth clock starts. Where the compromised device or mailbox held customers' or employees' personal data, the Personal Data Protection Act requires an assessment of whether the breach is notifiable and, if it is, notification to the Commission "as soon as is practicable, but in any case no later than 3 calendar days after the day the organisation makes that assessment" (PDPA 2012, Part 6A); a breach affecting 500 or more individuals is deemed to be of significant scale (Notification of Data Breaches Regulations 2021). The job-scam intrusion described above harvested company credentials from a company-issued device; whether it also reached personal data is the question that starts or stops that clock.

Common Mistakes

  1. Assuming the Shared Responsibility Framework covers the company account. A protected account is one held by individuals, which the guidelines' footnote describes as an account "opened with the retail business unit of the responsible FI, or cannot be used for transactions in the course of business" (MAS, SRF guidelines). The framework's duties and its loss waterfall stop at the retail account.
  2. Confirming a changed bank detail through the email chain that asked for it. SPF's instruction is to call "a trusted number that has been independently verified, and never rely solely on contact details provided in the same email chain" (SPF, 5 May 2026). The published wording that covers impersonation fraud defines its call-back the same way, and pays only if the instruction was verified before the loss, by that call-back or, for an e-mail, by confirming the genuine requestor's work e-mail address was used.
  3. Letting one person change a vendor's details and release the payment. The SPF-CSA advisory asks for "approval workflows" and "multi-party review", and the published proposal addendum asks whether payments above a threshold carry two authorisations (SPF-CSA, 14 August 2026). A "no" on the form is a fact the insurer holds at the claim.
  4. Routing a partner's, agent's or customer's money through the company account. Section 55A is met where an arrangement handles another person's criminal benefits and you enabled that person to operate an account you control without taking "reasonable steps to ascertain the purpose" (CDSA 1992, section 55A); MHA states the rash and negligent offences apply to directors operating corporate accounts.
  5. Treating multi-factor authentication as the end of the matter. SPF and CSA state that "session token harvesting can bypass MFA" (SPF-CSA, 14 August 2026). A coding test on a company laptop was the intrusion.
  6. Reading a cyber policy as crime cover. Of two published wordings, one covers impersonation fraud on a verification condition and one has no first-party social-engineering cover. The section, the condition and the sub-limit are in your own wording, not in the word "cyber".

What This Means for Your Business

The scam wave has two edges for a company, and the controls for one are the evidence for the other.

For a business that pays suppliers. Write down the call-back rule SPF and the published wording both describe: a changed bank detail is confirmed by telephone to a number your business already holds, never to one in the email. Put two people on any payment above a threshold you set, and keep the record of who verified what. Those two records are what a cyber crime section asks for at a claim, and what a proposal form asks for at inception.

For a director. The rash and negligent offences reach corporate accounts, and a restriction on Corppass access reaches the company before any charge. Know who can operate your accounts and your Singpass and Corppass, and refuse every arrangement in which someone else's money passes through them, however plausible the business reason. Reasonable steps to check purpose, source and destination are what section 55A turns on, and what an individual must prove under section 51(8) to avoid caning (CDSA 1992, section 51).

For a business that hires. The 14 August advisory shows a recruitment process turned into an intrusion. Treat a technical assessment, a plug-in or a download requested during hiring as an untrusted install on a company device, and hold API-level transaction limits and multi-party approval where the company moves funds or digital assets.

For all of the above. Read the cyber wording you hold for the words "impersonation", "fraudulent instruction", "funds transfer" and "social engineering". If none appears, the cover for a payment your own staff released is not in that document. If they appear, read the condition that sits beside them and make your procedure match it, because the insurer will. Then bring the wording and the procedure to your adviser together.

Questions to Ask Your Adviser

  1. Does my cyber policy carry an impersonation fraud or social engineering section, and what exactly does its verification condition require of my staff before a payment is released?
  2. Where is the cover for a payment my own staff authorised on a false instruction: in the cyber wording, in a commercial crime or fidelity policy, or nowhere?
  3. What sub-limit applies to the crime section, and does it sit inside or beside the main limit?
  4. If a vendor's mailbox, not mine, was compromised, does the vendor-and-client exclusion remove the loss?
  5. What does the wording require of me within sixty days of discovering the loss, and are the costs of proving the loss covered?
  6. If a company-issued device was compromised through a recruitment scam and personal data was reached, which cover responds to the assessment and the notification the PDPA requires?
  7. Which of the proposal form's questions on payment verification, dual authorisation and staff training did we answer, and does our written procedure match the answers?

Related Information

Published 12 September 2026. Source verified 12 September 2026.