Singapore iMessage Courier Phishing Scam

Singapore Police Warn of iMessage Phishing Scam Costing $1.2M+

HIGH
August 5, 2026
4m read
PhishingMobile Security

Impact Scope

People Affected

251+

Industries Affected

Other

Geographic Impact

Singapore (national)

Related Entities

Products & Tech

Apple iMessage

Other

DHLNinjaVanJ&T ExpressSingPost

Full Report

Executive Summary

On August 5, 2026, the Singapore Police Force (SPF) issued a public advisory about a prolific phishing campaign targeting users of Apple iMessage. The scam has resulted in at least 251 reported cases and over S$1.2 million in losses since late June 2026. Threat actors are impersonating major courier services to trick victims into divulging their financial information. The campaign uses social engineering to create a sense of urgency around a failed parcel delivery, directing victims to a fraudulent website to steal their credit card numbers and banking credentials under the guise of paying a small re-delivery fee.


Threat Overview

The attack is a classic phishing scheme adapted for the iMessage platform. It leverages the public's reliance on package delivery services.

  1. Initial Contact: Victims receive an iMessage from an unknown sender, often a foreign phone number (e.g., from Morocco, Philippines, UK) or a random email address. The message claims to be from a well-known courier company like DHL, NinjaVan, or SingPost.
  2. The Lure: The message states that a parcel delivery has failed due to an 'invalid' address and provides a link to update the details. This is a form of T1566.002 - Phishing: Spearphishing Link.
  3. Bypassing Security: Attackers often send a follow-up message to start a 'conversation'. This is a tactic to circumvent an iMessage feature that may prevent links from being clickable if they come from a completely unknown sender with no reply.
  4. Credential Harvesting: The link directs the victim to a professionally designed, spoofed website that mimics the legitimate courier's site. The victim is prompted to pay a small re-delivery fee (e.g., $1-2). To do so, they must enter their full credit card details and/or internet banking login credentials.
  5. Financial Theft: After harvesting the credentials, the scammers use them to make large, unauthorized transactions from the victim's bank account. In some cases, victims are also tricked into approving these transactions via their digital banking tokens.

Technical Analysis

This campaign relies almost entirely on social engineering rather than technical exploits. The attackers' methods are simple but effective:

  • Impersonation: Abusing the brand recognition and trust associated with major courier companies.
  • Platform Abuse: Using iMessage, which is perceived by many as a secure, personal messaging app, to deliver the phishing lure. The use of foreign numbers and random email addresses makes blocking difficult.
  • Urgency and Scarcity: The 'failed delivery' lure creates a sense of urgency, prompting the victim to act quickly without thinking critically.
  • Low-Cost Lure: Asking for a very small fee for re-delivery makes the request seem reasonable and lowers the victim's guard, obscuring the true goal of harvesting their primary financial credentials.

Impact Assessment

The direct impact is financial loss for the victims, with the SPF reporting an average loss of nearly S$4,800 per victim. The total reported losses of S$1.2 million are likely an underestimation, as many victims may not report the crime. Beyond the financial cost, victims also suffer from the compromise of their personal and financial data, which can be used for future identity theft. The campaign also erodes public trust in both courier services and digital communication platforms.


IOCs — Directly from Articles

No specific malicious URLs or domains were provided in the source articles. The main indicators are the source phone numbers.

Type
Phone Number Prefix
Value
+212
Description
Country code for Morocco, used by scammers.
Type
Phone Number Prefix
Value
+63
Description
Country code for the Philippines, used by scammers.
Type
Phone Number Prefix
Value
+44
Description
Country code for the United Kingdom, used by scammers.

Cyber Observables — Hunting Hints

This threat is targeted at individuals, making enterprise-level hunting difficult. However, for personal defense:

  • Message Source: Be highly suspicious of iMessages from unknown phone numbers, especially those with foreign country codes, or from nonsensical email addresses (e.g., asdf89gh@domain.com).
  • URL Analysis: Before clicking, inspect any links. Look for misspellings or unusual domains that are close to, but not identical to, the official courier's domain.
  • Website Content: On the linked website, look for poor grammar, low-resolution logos, and any requests for sensitive information (like banking passwords) that are inappropriate for paying a small fee.

Detection & Response

For individuals:

  1. Do Not Click: Never click on links in unsolicited messages from unknown senders.
  2. Verify Independently: If you receive a delivery notification, do not use the provided link. Instead, go directly to the official website of the courier company or use their official app and enter your tracking number to check the status.
  3. Report and Block: Use the 'Report Junk' feature in iMessage to report the scam message to Apple. Then, block the sender's number or email address.
  4. Monitor Accounts: If you believe you have fallen victim, immediately contact your bank to block your cards and report the fraud. Change your banking passwords and monitor your accounts closely for unauthorized transactions.

Mitigation

  1. Public Awareness: The advisory from the Singapore Police Force is a key mitigation step, raising public awareness about the specific tactics used in this scam.
  2. Enable iMessage Filtering: In iOS settings, users can enable 'Filter Unknown Senders', which organizes iMessages from people who aren't in your contacts into a separate list and disables link previews from them.
  3. MFA on Banking: Always use multi-factor authentication for banking services. This provides a crucial layer of protection even if your password is stolen.
  4. Skepticism as a Default: Treat all unsolicited messages containing links or requests for information with a high degree of skepticism, regardless of the platform.

Timeline of Events

1
June 24, 2026
Start date from which the Singapore Police Force began tracking this specific scam campaign.
2
August 5, 2026
Singapore Police Force issues a public advisory after 251 cases and S$1.2 million in losses are reported.
3
August 5, 2026
This article was published

MITRE ATT&CK Mitigations

Educating the public to recognize and report such scams is the primary defense. Users should be taught to verify delivery statuses independently on official websites.

Using MFA on banking accounts can prevent fraudulent transactions even if the attacker successfully steals the user's password.

Mapped D3FEND Techniques:

While difficult for individuals, mobile device management (MDM) solutions in corporate environments can use web filtering to block access to known phishing sites.

Mapped D3FEND Techniques:

Timeline of Events

1
June 24, 2026

Start date from which the Singapore Police Force began tracking this specific scam campaign.

2
August 5, 2026

Singapore Police Force issues a public advisory after 251 cases and S$1.2 million in losses are reported.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

phishingsmishingiMessagescamSingaporecourier

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.