The email looked perfect. It carried your lawyer's letterhead, the right matter reference, and a polite instruction: the firm's bank account had been updated, and the deposit for your new condominium should be transferred to a new account number. The signature was correct, the tone was professional. So you transferred S$180,000. It was only when your lawyer called a week later to ask why the payment was late that the truth surfaced: that email had never come from your lawyer.
That scenario is not hypothetical. With online property transactions on the rise, phishing scams have become one of the most dangerous threats facing homebuyers, sellers, and investors in Singapore. The property market moves fast — prices rise, units sell within days, and buyers are conditioned to act quickly. Scammers exploit exactly that urgency. From fake listing e-mails to fraudulent payment requests, phishing attacks now sit squarely in the middle of one of the largest financial decisions most of us will ever make.
Here is what you need to know about the phishing tactics targeting property transactions — and the practical steps to protect your deal, your identity, and your savings.
Why Property Transactions Are a Honeypot for Phishing Scams
Let's first understand why scammers love the property market so much. There are three core reasons: size, complexity, and emotion.
The money is enormous. A typical HDB resale transaction in Singapore now involves hundreds of thousands of dollars. Condominium purchases push well past S$1 million, and landed property deals go higher still. A single successful phishing attack on one property transaction can net criminals more than a year's worth of phishing attacks on ordinary consumers. For scammers, one successful property deal is a jackpot.
The process is crowded. A property transaction involves the seller, the buyer, at least two lawyers, property agents, banks, the HDB or Singapore Land Authority, CPF Board, IRAS, and often multiple family members. That means dozens of emails, WhatsApp messages, phone calls, and portal notifications. It is genuinely difficult to keep track of who is supposed to contact you, from what number, and about what. Scammers love density — it gives them room to hide.
The pressure is emotional. Buying a home is stressful. Deadlines, option-to-purchase dates, loan approvals, and the fear of losing the unit to another buyer all combine to make people act faster than they usually would. When an email says "urgent", your brain naturally shifts into response mode. Scammers are counting on that.
Singapore has also seen a structural surge in reported scams. According to the Singapore Police Force's annual scam statistics briefings, total reported scam cases rose sharply in recent years, from roughly 23,900 cases in 2021 to over 50,000 in 2023. Media reports suggest the numbers stayed elevated in 2024.
Reported Scam Cases in Singapore (All Types, Approx.)
Now, not every scam case is a phishing attack on a property deal. But the trend is unmistakable, and phishing is consistently named by the authorities as one of the top scam typologies in Singapore. The more transactions move online — virtual viewings, electronic signatures, digital payment instructions — the more entry points scammers gain.
Let's look at the specific phishing playbook used against property buyers and sellers.
Common Phishing Attacks Targeting Property Transactions
Phishing, at its core, is the act of impersonating a trusted party to trick you into revealing information or transferring money. In the property world, the impersonation usually targets trust in five familiar names: the lawyer, the bank, the property agent, HDB, and the seller.
Fake Listing E-mails and Clone Portals
This is often the first contact a victim has with a scammer. The attacker scrapes photos and descriptions from real property listings on portals like PropertyGuru or 99.co, then re-posts them on a fake website or sends them directly to buyers via email or WhatsApp. The unit is always priced just slightly below market — attractive enough to catch your eye, not so low as to seem impossible.
When a buyer expresses interest, the scammer insists on a "reservation fee" or "deposit" paid via bank transfer to secure the unit before other buyers can view it. That is not how legitimate property transactions work in Singapore. Deposits are paid through legally recognised channels, usually after an Option to Purchase (OTP) is issued. Any request for an immediate deposit before you have physically viewed the property, verified ownership, and met a legitimate agent should be treated as a red flag.
Impersonating the Lawyer or Law Firm
This is the most dangerous phishing attack in a property transaction — and the hardest to spot. Scammers hack the email account of a real lawyer, conveyancing paralegal, or property agent, or they create a lookalike domain that differs from the real one by a single character (e.g., law-firm.com instead of lawfirm.com). They then monitor the real conversation between buyer and lawyer, waiting for the moment just before a payment is due.
At that precise moment, the fake email arrives. It says the firm's bank account details have been updated, or there has been an administrative error, and the deposit or balance should be transferred to a different account. The attacker may even send a revised invoice with the law firm's letterhead. This is known in cybersecurity circles as business email compromise (BEC), and it is responsible for some of the largest property-related losses reported in Singapore.
Phishing E-mails Pretending to Be from HDB, IRAS, or CPF Board
Authorities are also impersonated. A buyer waiting for their HDB resale approval, a CPF housing grant, or an IRAS tax assessment is highly receptive to official-looking messages. Scammers exploit this with emails that say "Your CPF housing refund is pending" or "Your property tax statement requires verification", complete with logos lifted straight from government websites.
These emails typically ask you to click a link to "verify your account" or "re-attach your documents". The link leads to a fake government portal that looks convincing enough to make you enter your Singpass credentials, banking details, or NRIC number. Once the scammer has those, they can attempt to intercept your actual property-related correspondence, take over your internet banking session, or use your identity to apply for loans and credit lines in your name.
Fraudulent Payment Requests from Fake Agents or Sellers
For those selling property, the attack vector is often a fake buyer. The scammer expresses interest, negotiates, and then claims their bank requires "verification" of the seller's account. They send a link to a fake banking portal and ask the seller to log in to "confirm receipt of the deposit". The seller enters their banking credentials, and the scammer immediately tries to drain the account.
QR Code Phishing (Quishing)
A growing variation is phishing via QR codes. A scammer sends an email or WhatsApp message that looks like a payment reminder from a law firm, bank, or property service provider, with a QR code to "authorise the payment" or "view the loan statement". Scanning the QR code may open a fake login page, or it may trigger a payment-authorisation prompt on your banking app. QR codes are dangerous because they bypass your natural suspicion of long, misspelt links. QR codes should be used only when you have deliberately accessed the legitimate source yourself — never from an unsolicited message.
Let's trace the full anatomy of a payment-redirection phishing attack, because it is the one most likely to destroy a property deal.
Notice how nothing in this chain looks obviously broken to the buyer. The email is logical, the story is plausible, and the moment of attack is perfectly timed. The only defence is verification outside the compromised channel.
Phishing Red Flags: What To Look For In Every Property E-mail
You don't need to be a cybersecurity expert to spot most phishing attempts. You just need to slow down and look at the message as a stranger would. Here are the red flags that should trigger suspicion.
| Red Flag | Why It Matters |
|---|---|
| The sender address doesn't exactly match | "Marlon. Tan@lаwfirm.com" with a Cyrillic "a", or @lawfirm-secure.com are not legitimate |
| The message creates false urgency | Scammers use deadlines and threats to stop you applying critical thinking |
| Bank account details "changed" | Legitimate law firms rarely change accounts mid-transaction, and never by email alone |
| The email asks you to "verify" personal data | HDB, CPF, IRAS, and banks do not request passwords or OTPs via email links |
| The tone is slightly off | Formal-but-odd phrasing, unusual greetings, inconsistencies with previous emails |
| A link asks for Singpass login | Singpass should only ever be used on the official app or singpass.gov.sg |
| The message arrives outside normal hours | Late-night emails are a common scammer pattern |
| A QR code appears in an unsolicited email | You cannot see where a QR code leads before scanning it |
Look-Alike Domains Are the New Mask
Scammers know we check domain names now, so they create domains that look authentic. A fake portal might be hdb-resale.gov.sg — note the hyphen — or irass.gov.sg — note the extra "s". The safest habit is to never access government or banking services through links in an email. Type the official URL yourself, or use the official mobile application.
The same discipline applies to law firms. Search the firm's name independently, visit its verified website, and call the number you find there — not the number on the email or the invoice.
How to Protect Your Property Transaction from Scammers: A Practical Checklist
Let's move from theory to action. The single most effective principle in protecting your property transaction is this: separate the instruction from the channel. If a payment instruction arrives by email, verify it by phone. If a phone call requests a payment, verify it through the official portal. Any instruction that comes to you on one channel and is confirmed on the same channel gives the scammer control of both ends.
Here is the checklist to follow at every stage of a property transaction.
1. Verify the Lawyer's Bank Details Twice — Once In Person or by Official Call
Before you make any deposit or balance payment, independently confirm the law firm's bank account. Use the phone number published on the Law Society of Singapore's official directory or on the firm's own verified website. Do not call the number left on the email, the invoice, or a voicemail. Ask specifically: "Has this firm changed its bank account details in the last two weeks? Is the account number being used for my transaction publicly known?"
2. Insist That Payment Instructions Come Through a Contract, Not an E-mail
In a properly run conveyancing, the bank account for each payment is stated in the contract or the official letterhead already in your possession. If a change is proposed, it must be made through a signed variation, not an email. Any emailed change that did not go through your lawyer's other verified communication line should be treated as fraudulent until proven otherwise.
3. Set a Personal "Verification Threshold"
Decide in advance that any payment above a certain amount — say S$10,000 — requires a phone call to the recipient using a number you have dialled yourself. Make this a rule you never break, no matter how rushed the transaction becomes. That one habit would neutralise the majority of payment-redirection attacks in Singapore.
4. Use Two-Factor Authentication Everywhere It Matters
Enable two-factor authentication (2FA) on your internet banking, your email, Singpass, and any portal used in the transaction, such as the HDB Resale Portal. A scammer who steals your password on one site should not be able to reuse it on another. Further, by the time you need to make a payment, you should have already received a Singapore Police Force "Verify Your Sender" advisory? No — you should already know why 2FA blocks takeovers.
5. Never Share Your OTP — Not Even with Someone Who "Knows" You
No bank, HDB officer, lawyer, or government agency will ever ask for your One-Time Password via phone, email, or WhatsApp. If someone asks for it, the call is a scam. The moment you reveal an OTP, the attacker can take over your banking session and authorise transfers in your name.
6. Separate Funds from Impulses
If you receive an email about your CPF housing grant or tax refund, open your CPF or IRAS app directly. Do not click the link. A legitimate grant will appear in your own official account. If it is not there, the email is fake.
7. Meet the Agent and the Seller Face-to-Face
For anyone buying or renting through an online listing, insist on at least one in-person or live video meeting with the agent and, where reasonably possible, the seller. Ask to see the agent's CEHA registration number and the seller's identification documents. Scammers avoid verified face-to-face contact.
Here is a decision flow you can run through every time a payment request enters your inbox.
The beauty of this flow is that it does not depend on your ability to detect a spoofed email. It depends on something far more reliable: a rule. Follow the rule, and the scam collapses.
Phishing Beyond E-mail: Vishing, Smishing, and Fake Banking Apps
Phishing is not limited to email. In fact, scammers increasingly combine channels in what cybersecurity professionals call "multi-vector attacks". Smishing is phishing via SMS, and vishing is phishing via voice calls.
SMS Phishing (Smishing)
You might receive a text that looks like it comes from a bank's fraud department: "Your card was used in an unusual transaction. Block the charge by logging in here." The link in the SMS is fake. In the property context, you may receive messages pretending to be from your lawyer's mobile, asking you to "confirm the deposit details" via a link. If the SMS is truly from your lawyer, you should be able to confirm it through an official contact channel you already have.
Voice Phishing (Vishing)
Vishing usually involves a call from someone claiming to be from "MAS", "HDB", or "your bank's anti-fraud team". In property transactions, the story often involves a "failed CPF refund", a "suspicious transaction on your mortgage account", or a "criminal investigation into your property purchase". The caller — sometimes using AI voice cloning — urges you to "transfer your money to a safe account" while the issue is resolved. No government body or bank will ever ask you to move money to a "safe account". That instruction alone is the scam.
Fake Banking Apps
Another recent pattern involves scammers sending buyers a link to "download the updated DBS/UOB/OCBC app" to authorise a property payment. The app is fake. It harvests your banking credentials. Always download banking apps from the official App Store or Google Play, and never from a link in an email, SMS, or WhatsApp message.
Cybersecurity Measures for the Entire Transaction Chain
Protecting your property transaction is a team effort. The weakest email account in the chain — your agent's, your lawyer's, or your own — can become the entry point. Here is a broader map of what should be secured.
| Party | Most Likely Attack | Key Defence |
|---|---|---|
| Buyer | Payment redirection; banking OTP theft | Strict verification threshold; never share OTP |
| Seller | Fake "buyer" portal; account takeover | Confirm bank details only via official apps |
| Law firm | Email compromise leading to fake invoices | Law firms should enable MFA on all firm mailboxes |
| Agent | WhatsApp impersonation; fake listing cloning | Confirm agent registration on CEHA |
| Family members | Vishing calls about CPF/grant disbursements | Slow down; call the agency using official numbers |
A Note on NRIC and Document Handling
One of the quieter dangers in property phishing is identity theft. Buyers submit their NRIC, income documents, and bank statements multiple times over the course of a transaction. Scammers who obtain these can apply for loans, open accounts, or target you again with highly personalised phishing.
- Never send a copy of your NRIC, bank statements, or payslips to an email address unless you have independently confirmed it belongs to the receiving law firm.
- Mask your NRIC number where practical when sharing documents over unsecured channels.
- Do not forward property documents from your personal email to family members without checking the recipients carefully.
- Clear temporary files and screenshots on shared devices before and after a transaction.
What To Do If You Have Been Phished
If you suspect your property payment, singpass credentials, or banking details have been compromised, time is the scarcest resource. Act in this order.
1. Contact your bank immediately. If the fraudulent transfer was made via FAST or telegraphic transfer, ask the bank to file a recall with the recipient bank. Success is not guaranteed, but a fast request is your only chance of freezing funds that have not yet been withdrawn.
2. Do not delete the phishing email or messages. Preserve them as evidence. Take screenshots of the sender address, the message content, and any links (without clicking them).
3. Report the case to the police and to ScamShield. Make a police report online or at a neighbourhood police centre, and report the number, email, or website through the ScamShield app so that others can be warned.
4. Change the compromised credentials immediately. Using a clean device, change your banking password, email password, and Singpass password. Enable 2FA if it was not already on.
5. Alert your lawyer, agent, and the seller. If one party's email was compromised, all parties need to switch to a verified alternative communication channel — ideally a face-to-face meeting or a phone call from a number confirmed in person.
6. Monitor your credit. Keep an eye on your bank accounts, credit card statements, and any notifications from financial institutions. If you believe your NRIC has been misused, you may wish to place a credit report alert with the relevant credit bureau.
| Step | Who to Contact | When |
|---|---|---|
| Stop the transfer | Your bank | Within minutes of discovery |
| Evidence preservation | You | Immediately, before making changes |
| Official report | Singapore Police Force | Within 24 hours |
| Community warning | ScamShield | Within 24 hours |
| Credential reset | Your bank, Singpass, e-mail provider | Same day |
| Transaction safe restart | Your lawyer | Same day, via verified contact |
Time matters in every one of these steps. A payment that takes seconds to send can take weeks to recover — if it is recovered at all.
Food for Thought
Before we wrap up, here are some questions worth reflecting on. Property phishing works because we are human: we trust the familiar, we fear missing out, and we respond to urgency.
- If you could adopt only one verification habit — calling back on a number you dial yourself — which financial moments in your property journey would it protect first?
- How would a fake listing change the way you compare property prices online? Should you trust the "market rate" from an unsolicited email, or benchmark against independent transaction data?
- Would you complete a property deal with a lawyer who communicated only through WhatsApp and refused a face-to-face meeting?
- How would you explain the "safe account" scam to your parents without them feeling embarrassed or insulted?
- If your identity documents are worth more than your cash, should you be as careful sharing your NRIC as you are sharing your PIN?
The best time to form these answers is not during a transaction. It is now.
Conclusion: The Asset You're Protecting Is Bigger Than the Down Payment
Phishing attacks on property transactions are not just about the money you might lose. They are about the identity behind the transaction — your credit history, your CPF, your ability to complete a purchase, and the trust that underpins the entire Singapore property market. The good news is that the defence is not complicated: slow down, verify independently, create rules for large payments, and secure every account that touches the deal.
