Download Privacy Needle App

Type to search

Editorials

Your Personal Data Could Be Making Singapore Scams More Dangerous Than Ever

Share
Singapore Scams

Your Name, NRIC and Phone Number May Be Worth More to Scammers Than You Think: The Hidden Data Threat Facing Singapore

  1. Scammers May Know More About You Than You Think: Here’s How Your Data Gets Used
  2. Your Name, Phone Number and NRIC Could Be a Goldmine for Scammers
  3. Singaporeans Are Losing Millions, And Your Personal Data Could Be Helping Scammers
  4. A Data Leak Could Turn You Into the Perfect Scam Target
  5. Why Knowing Your Name Is All a Scammer May Need to Start

Imagine receiving a WhatsApp message from someone claiming to be your bank.

They know your full name.

They know your mobile number.

They know which service you recently used.

They may even know your address, email address or the last four digits of information connected to an account.

The message looks professional. The caller sounds convincing. And when they mention information that appears to be private, you naturally begin to wonder:

“How did they know this about me?”

That question is becoming increasingly important in Singapore.

A stolen password can sometimes be changed. A compromised credit card can be cancelled. But personal information such as your name, date of birth, phone number, address and identification details can potentially remain useful to criminals for years.

The biggest danger facing consumers may no longer be a random scammer sending thousands of obviously suspicious messages.

It may be the highly personalised scam.

And in an increasingly connected Singapore, where people use digital banking, PayNow, Singpass-linked services, e-commerce platforms, food delivery apps, ride-hailing services and messaging applications every day, personal information has become one of the most valuable assets criminals can obtain.

Singapore’s scam problem may be improving — but the threat remains enormous

Singapore saw a decline in scam and cybercrime cases in 2025, but the scale of the problem remains significant.

According to Singapore Police Force figures, there were 41,974 scam and cybercrime cases in 2025, including 37,308 scam cases. Total scam losses reached approximately S$913.1 million.

That means thousands of people were still being targeted every month.

The most common scams included e-commerce scams, phishing scams, job scams, investment scams and government official impersonation scams.

But the numbers tell only part of the story.

The real question is:

Why are scams becoming so convincing?

One major reason is data.

A scammer who knows nothing about you has to guess.

A scammer who has your name, phone number and email address can personalise a message.

A scammer who has information from multiple sources can potentially build a much more detailed profile.

This is where a data breach becomes more than just a cybersecurity problem.

It can become the beginning of a much larger personal security problem.

The dangerous journey of your personal data

Your information may pass through dozens of organisations during your lifetime.

Think about how many companies potentially hold information about you.

Organisation or ServiceInformation That May Be Held
BankName, contact information, financial records
E-commerce platformName, phone number, delivery address
Mobile operatorPhone number and account information
Hospital or clinicPersonal and appointment information
HotelPassport or identification information
Delivery companyName, phone number and address
EmployerIdentification and employment records
SchoolPersonal and academic information
Loyalty programmeContact details and purchasing patterns
Airport or travel serviceIdentity and travel information

You may trust every organisation on that list.

But cybersecurity is not just about whether you trust a company.

It is also about whether every system, employee, contractor, software provider and third-party partner involved in handling your information has adequate protection.

A single mistake can potentially expose information belonging to hundreds, thousands or even millions of people.

Singapore’s Personal Data Protection Commission has repeatedly warned organisations about weaknesses that can lead to major breaches.

In one major case, personal data belonging to more than 665,000 individuals was accessed and later offered for sale online following security failures connected to a software migration.

For consumers, incidents like this raise an uncomfortable question:

What happens after your information leaves the company’s system?

Scenario 1: The “bank employee” who already knows your name

Let’s imagine a Singaporean professional named Daniel.

Daniel receives a call on his mobile phone.

The caller introduces himself as a representative from Daniel’s bank.

“Mr Daniel Tan, we noticed suspicious activity involving your account.”

Daniel immediately becomes concerned.

The caller knows his name.

The caller knows his mobile number.

The caller sounds professional.

The caller then tells Daniel that someone has attempted to access his account.

Daniel is instructed to “secure” his money.

The caller sends him a link.

At this point, Daniel may believe the call is genuine because of one simple psychological factor:

The caller knew his name.

But knowing someone’s name is not proof that a caller is legitimate.

If criminals obtain leaked contact information, they can use those details to make an attack appear more credible.

Instead of sending a generic message saying:

Dear Customer

They can say:

Hi Daniel, we noticed unusual activity associated with your account.

That small change can dramatically increase the emotional impact of a scam.

Scenario 2: Your WhatsApp account becomes the weapon

Imagine receiving a message from someone you know.

It could be a friend.

A colleague.

A relative.

The message looks normal.

They ask you to help them vote in an online competition.

Or they tell you that a verification code was accidentally sent to your phone.

You trust them because you know them.

But what if their account has already been compromised?

Singapore Police have issued repeated warnings about scammers taking control of WhatsApp accounts by tricking users into sharing one-time passwords or authorising unknown devices. Once an account is compromised, criminals can impersonate the real owner and target people in their contact list.

This is what makes personal data so dangerous.

The scammer does not always need to impersonate a bank.

Sometimes, they can impersonate someone you already trust.

Scenario 3: The data breach you forgot about years ago

Here is another possible situation.

You created an account on an online platform five years ago.

You stopped using the service.

You forgot about it.

Then one day, the company suffers a breach.

Your old email address and password combination becomes available to criminals.

Years later, someone attempts to use the same password on another account.

Why?

Because many people reuse passwords.

The attacker does not need to know whether the password will work.

They can simply try.

This is why an old data breach can remain relevant years after it happens.

Your data does not necessarily expire when you stop using a service.

And criminals may combine old information with newer leaks.

One database may contain your old email address.

Another may contain your phone number.

Another may contain your home address.

Individually, each piece of information may appear harmless.

Together, they can create a much more complete picture.

The rise of the “data-rich scammer”

The traditional scammer had very little information.

They sent thousands of identical messages and waited for someone to respond.

The modern criminal can potentially work differently.

Instead of:

Congratulations, you have won a prize!

A personalised scam could say:

Hi James, your delivery to [address area] could not be completed. Please update your information.

The more accurate the information appears, the more difficult it can be for the victim to immediately identify the message as fraudulent.

This is sometimes called social engineering.

The attacker is not necessarily breaking into your phone.

They may simply be manipulating you into giving them access.

And personal data can make that manipulation significantly more effective.

Why a phone number can be more valuable than you think

Many people think:

“I only gave them my phone number. That is not a big deal.”

But your phone number can be connected to many parts of your digital life.

You may use it for:

  • Banking alerts
  • One-time passwords
  • WhatsApp
  • Telegram
  • Food delivery
  • E-commerce
  • Ride-hailing
  • Social media
  • Government services
  • Account recovery

A phone number can also become the starting point for impersonation attempts.

Singapore Police have warned about scams involving attempts to obtain WhatsApp verification codes and compromise accounts. The lesson is simple:

An OTP is not just a random number. It can be the key to an account.

“But I never gave the scammer my information”

You may not have.

Someone else may have lost it.

This is one of the most important realities of data protection.

You can personally follow good security practices.

You can use strong passwords.

You can avoid suspicious websites.

You can refuse to click dangerous links.

But you cannot personally control every organisation that stores your information.

You may have given your details to a company years ago.

That company may have changed its software.

Moved information to a new cloud provider.

Worked with a contractor.

Integrated a third-party service.

Or experienced a cybersecurity incident.

The Singapore data breach landscape has shown that cyber incidents remain a major cause of significant breaches, with ransomware also featuring prominently in enforcement cases involving inadequate security measures.

That means data protection is not simply a consumer responsibility.

It is also an organisational responsibility.

What personal information should worry you most?

Not all leaked information creates the same level of risk.

Here is a practical guide.

Data ExposedPotential RiskWhat You Should Do
Email addressPhishing attemptsWatch for suspicious emails
Phone numberSMS and messaging scamsBe cautious with OTP requests
PasswordAccount takeoverChange password immediately
Home addressTargeted scamsVerify unexpected deliveries
Date of birthIdentity fraudMonitor suspicious account activity
NRIC or identification detailsSerious identity riskFollow official guidance immediately
Banking informationFinancial fraudContact your bank
Login credentialsAccount takeoverChange passwords and enable MFA
Device informationTargeted cyberattacksKeep software updated

The most dangerous breaches often involve a combination of information.

A name alone may not be extremely useful.

But a name, phone number, email address and physical address together can provide criminals with significantly more material for targeted scams.

The NRIC problem: Why identity information is different

Passwords can be replaced.

Your identity cannot.

This is why identification information requires particularly strong protection.

Once criminals obtain sensitive identity information, victims may face a long-term risk of impersonation or fraudulent activity.

The risk does not necessarily disappear after a company announces that a breach has been resolved.

The company’s systems may be fixed.

But copies of stolen data may still exist elsewhere.

This is why data breaches should not be treated as a temporary inconvenience.

For affected individuals, the consequences can continue long after the headlines disappear.

The “small information” myth

One of the biggest mistakes people make is assuming that individual pieces of information are harmless.

For example:

“My email address is public.”

“My phone number is not secret.”

“My postcode is easy to find.”

That may be true.

But cybercriminals do not always need one highly sensitive piece of information.

They can combine information.

Think of your personal information as puzzle pieces.

One piece may not reveal much.

Ten pieces can reveal a picture.

And artificial intelligence could make this problem even more concerning.

AI tools can help criminals write convincing messages, translate scams into different languages and create personalised communication at scale.

Singapore authorities have already highlighted growing concerns around AI-enabled scam tactics, while cybersecurity agencies continue to warn about an evolving digital threat environment.

A realistic phishing scenario

Imagine this message arrives on your phone:

Hi Sarah, this is regarding your recent order. We were unable to process the delivery because the address information appears incomplete. Please update your details within 24 hours.

Sarah recently ordered something online.

So she clicks.

The website looks professional.

It asks her to log in.

She enters her credentials.

The website immediately forwards those details to criminals.

The real danger was not sophisticated hacking.

The attacker simply created a believable situation.

And the more information an attacker knows about a target, the easier it can be to make the situation believable.

How to protect yourself after a data breach

If you receive a notification that your information has been involved in a breach, do not panic.

But do not ignore it.

Take action.

1. Change your password immediately

If the breached service uses a password you have reused elsewhere, change those passwords as well.

Use a different password for every important account.

2. Turn on two-factor authentication

Where available, enable two-factor or multi-factor authentication.

This can provide an additional layer of protection if your password is compromised.

3. Watch for personalised scams

Be particularly cautious when someone contacts you using information that appears to be private.

Remember:

Knowing your name does not prove someone is legitimate.

4. Never share an OTP

Banks, messaging platforms and legitimate services may send OTPs for authentication.

Treat those codes as highly sensitive.

Do not provide them to someone who contacts you unexpectedly.

5. Verify independently

If someone calls claiming to be from your bank, government agency or service provider:

Hang up.

Find the official contact number independently.

Then contact the organisation yourself.

Do not simply call the number provided by the suspicious caller.

6. Review your important accounts

Check for:

  • Unknown logins
  • Password reset requests
  • Unexpected transactions
  • New devices
  • Changes to your account information

7. Remove old accounts

If you no longer use an online service, consider whether you can delete or deactivate the account.

The less personal information stored across unnecessary services, the smaller your potential exposure.

Data protection is becoming a personal survival skill

For years, cybersecurity was viewed primarily as an IT department problem.

That is changing.

Today, data protection is a personal skill.

Just as people learn how to protect their physical wallets, they increasingly need to understand how to protect their digital identities.

Your digital identity may include:

  • Your phone number
  • Your email address
  • Your passwords
  • Your identification details
  • Your financial accounts
  • Your messaging accounts
  • Your social media profiles

Losing control of one of these may affect the others.

For example, a compromised email account could potentially be used to reset passwords for other services.

A compromised messaging account could be used to target your friends.

A stolen phone number could become part of a larger impersonation attempt.

Digital security is interconnected.

Frequently Asked Questions

Can someone steal money from me just because they know my phone number?

Not automatically.

However, criminals can use your phone number to send phishing messages, impersonate organisations or attempt to trick you into revealing sensitive information.

Never assume a message is legitimate simply because it was sent to your personal number.

What should I do if my data is involved in a breach?

Change relevant passwords, monitor important accounts and remain alert for phishing attempts.

If highly sensitive financial or identification information is exposed, follow guidance provided by the affected organisation and relevant authorities.

Can a scammer hack my WhatsApp just by sending me a message?

Receiving a message alone does not normally give someone control of your account.

However, scammers may attempt to trick you into sharing an OTP, scanning a QR code or authorising an unknown device.

Never share verification codes with another person.

Why do scammers know my name?

Your information may have been publicly available, collected through social media, exposed in a breach or obtained through other sources.

Knowing your name does not mean a caller is legitimate.

Should I change all my passwords after every data breach?

Change passwords for affected accounts immediately.

If you reused the same password on other services, change those passwords as well.

Using unique passwords is one of the best ways to reduce the damage caused by a breach.

Is two-factor authentication worth using?

Yes.

Two-factor authentication can add an additional layer of protection beyond your password.

However, you should still protect verification codes and be cautious about approving unexpected login requests.

Can deleted information still be exposed?

Potentially.

If information was copied or stolen before deletion, deleting an account later may not remove copies already obtained by another party.

This is why prevention and minimising unnecessary data collection are important.

The biggest question Singaporeans should ask

The next time an organisation asks for your information, consider asking:

Why do they need this?

Do they really need your full date of birth?

Do they need your identification number?

Do they need your home address?

How long will they keep the information?

Who else will have access to it?

Most people do not ask these questions.

They simply click “Agree.”

But in the modern digital economy, every piece of personal information has value.

To legitimate companies, it may help provide a service.

To advertisers, it may help build a consumer profile.

To criminals, it may help build a target profile.

That is why data protection is no longer only about privacy.

It is increasingly about personal security.

The bottom line

The next major scam targeting Singapore may not begin with a suspicious email.

It may begin with information you gave to a legitimate organisation years ago.

A name.

A phone number.

An email address.

An old password.

A delivery address.

On their own, these details may appear ordinary.

In the hands of criminals, they can become the foundation of a highly convincing attack.

Singapore has made progress in reducing scam numbers, but hundreds of millions of dollars are still being lost every year.

The lesson is becoming increasingly clear:

Your personal data may not look valuable to you. But to the wrong person, it can be the first step toward stealing something far more valuable.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.