Phishing scams are growing more costly in Singapore, and that pressure is forcing clearer answers to a hard question: who pays when a customer is deceived into handing over credentials? In 2024, the total number of scam cases in Singapore increased by 10.6% to 51,501 cases, up from 46,563 in 2023. Total losses surged by 70.6% to at least SGD 1.1 billion in 2024, compared to at least SGD 651.8 million in 2023. Even as overall losses rose, the average loss per victim dropped by 40%, from SGD 5,300 in 2023 to SGD 3,200 in 2024, pointing to a problem that is scaling in volume.
Against that backdrop, Singapore’s Shared Responsibility Framework (SRF) took effect from 16 December 2024, after being published for public consultation in October 2023. The SRF focuses on a defined set of phishing scams where scammers impersonate a legitimate business or government entity (based in Singapore or overseas but offering services to Singapore residents) and victims enter credentials into a fake digital platform such as a website or app, leading to unauthorised transactions. It does not cover other scam types like malware scams, authorised transactions, or phishing via non-digital means. The core shift is enforceable accountability: if a party fails its SRF duties, it pays; if both comply, the consumer may still bear losses.
What Banks and Telcos Must Do Under the SRF
For financial institutions, the SRF sets operational controls that aim to slow down fast-moving phishing losses and improve detection. Banks must impose a 12-hour cooling-off period after activation of a digital security token or a login on a new device, during which high-risk activities cannot be performed. They must also provide real-time notifications for token activations or new-device logins, as well as for high-risk activities and outgoing transactions. They must provide a 24/7 reporting channel and a customer self-service “kill switch” to report and block unauthorised access. In addition, banks must have real-time fraud surveillance for fast-draining scams, including cases where an account with a balance of SGD 50,000 or more is drained by more than half within 24 hours; this duty came after consultation, with a six-month transition period to comply.
Telcos also have explicit duties because phishing often arrives by SMS. Under the SRF, telcos that are mobile network operators must connect only to authorised aggregators for Sender ID SMS delivery, block Sender ID SMS messages that are not from authorised aggregators, and implement an anti-scam filter to block SMS with malicious links. The aim is to reduce spoofed or unverified Sender ID messages that push victims to fake sites. The SRF’s approach echoes earlier debate about goodwill payouts. For example, MAS’ announcement on scam-loss sharing followed an incident where OCBC made goodwill payouts after customers collectively lost approximately US$14 million to SMS spoofing that carried phishing links; MAS highlighted that loss allocation depends on whether and how each party fell short of responsibilities.
For consumers navigating Singapore Shared Responsibility Framework scams 2026, the practical process matters as much as the headline policy. MAS explains that victims should contact their financial institution immediately and report to the Police, and the financial institution coordinates the investigation and follows up, including advising whether the case is a phishing scam within the SRF. The SRF workflow includes a claim stage where the consumer must furnish a valid email address and supporting information such as a police report and digital communication trails. During investigation, financial institutions are the main contact point and may bring in the telco for telco-specific queries. The outcome is communicated by the financial institution (or the telco in specific situations), with existing avenues for dispute resolution available.
What phishing scams fall under Singapore’s Shared Responsibility Framework?
What must banks do under the SRF before losses are allocated?
When do telcos have to pay under the SRF?
How do victims file an SRF claim and what information is required?
How is liability changing for Singapore Shared Responsibility Framework scams in 2026 discussions?