Singapore Police issues alerts on rising Browser Popup based financial scam
The Singapore Police Force has warned of a renewed phishing scam that uses fake SPF-branded browser pop-ups to claim devices are locked for illegal browsing, then pressure victims into paying purported fines and handing over bank card details.
Singapore: The Singapore Police Force (SPF) has issued a public advisory on the re-emergence of phishing scams that use fraudulent browser pop-up alerts impersonating the force to extract bank card payments from victims.
According to the Public Affairs Department advisory dated 20 September 2026, victims encounter fake pop-ups bearing the SPF logo that claim their personal devices have been “locked” for repeatedly accessing websites containing illegal content.
The alerts instruct victims to pay purported outstanding fines within hours to unlock their devices, threaten permanent lockdown and prosecution if they fail to pay, and display a countdown timer to heighten urgency.
Victims are then pressured to provide bank card details to make the payment.
Many only realise they have been scammed when unauthorised foreign-currency transactions, often larger than the purported fines, appear on their cards.
Official clarification
SPF stressed that such pop-up alerts are fraudulent and are not issued by the Police.
The force does not remotely lock personal devices such as computers or laptops, and does not demand payment through pop-up alerts.
Technical Modus Operandi
Fraudulent “locked device” alerts of this kind are often delivered through a Browser-in-the-Browser (BitB) style technique.
In a BitB attack, malicious code on a compromised or lure page draws a fake window that looks like a genuine browser pop-up or system dialog, complete with a false address bar, logos and buttons, while the victim never leaves the attacker-controlled page.
The overlay can display countdown timers, official-looking branding (such as a police logo) and payment forms that harvest bank card details.
Because the fake window sits inside the real browser tab, it can feel more convincing than a simple phishing site, especially when urgency and fear of prosecution are used to rush the victim into paying.
Precautionary measures
Members of the public are advised to:
- Add the ScamShield app and enable banking security features such as transaction limits, two-factor authentication and multifactor authentication
- Check suspicious messages, numbers and links via ScamShield or www.scamshield.gov.sg
- Tell banks immediately about fraudulent transactions, and report phishing sites to browser providers
Anyone in doubt can call the 24/7 ScamShield Helpline at 1799.
SPF reiterated that fighting scams is a community effort under its “ACT Against Scams” message.