SINGAPORE: Losses from Apple iMessage scams impersonating courier firms have risen to roughly S$2.2 million because the Cyber Command has detected and disrupted greater than 30,000 Apple iMessage accounts linked to the continued rip-off marketing campaign since June 2026.
That is an replace to a narrative beforehand reported by The Unbiased Singapore, when the Police first issued an advisory on Aug 5 in regards to the iMessage courier rip-off variant with losses then standing at S$1.2 million throughout 251 circumstances.
The surge comes as scammers have expanded their impersonation targets past courier firms like NinjaVan, J&T Categorical, and SPX Categorical to incorporate authorities companies and monetary establishments, broadening the pool of potential victims.
How the rip-off works
The mechanics of the rip-off stay in step with the sooner advisory. Victims obtain iMessages from international numbers, bearing nation codes together with +212 (Morocco), +63 (Philippines), and +44 (United Kingdom), or from e mail addresses made up of random alphanumeric strings.
Messages direct recipients to click on hyperlinks intently resembling these of professional couriers, authorities companies, or monetary establishments.
In some circumstances, recipients are instructed to answer “Y” or “1” to activate the embedded hyperlink. This transfer exploits Apple iMessage’s built-in safety, which prevents hyperlinks in messages from unknown senders from being clickable till the recipient interacts with the sender. As soon as the recipient responds, the hyperlink turns into lively.
Clicking by means of results in spoofed web sites the place victims are prompted to enter card particulars, web banking credentials, or OTPs, supposedly to pay a small redelivery price or advantageous. In a number of circumstances, victims’ bank cards have been subsequently added to Google Pay or Apple Pay, or their financial institution digital tokens have been provisioned to unfamiliar units.
Unauthorised logins to financial institution accounts from unknown units have additionally been reported.
Why iMessage is a specific vulnerability
The Police famous a vital hole in iMessage’s construction: in contrast to SMS, which is protected by means of network-level anti-scam filters and the Singapore SMS Sender ID registry, iMessage operates on Apple’s separate ecosystem and isn’t lined by these protections. This makes it a most popular channel for scammers seeking to bypass Singapore’s current anti-scam infrastructure.
Authorities companies and courier firms don’t use iMessage to speak with the general public.
What to do now
iPhone customers ought to instantly confirm that “Filter Unknown Senders” and “Filter Spam” are enabled of their iMessage settings, and report suspicious messages utilizing the in-app reporting perform.
The Police’s ACT framework applies:
A-dd the ScamShield app, allow Two-Issue Authentication, set transaction limits, and activate the Cash Lock characteristic for financial institution accounts.
C-heck the authenticity of any supply or fee notification by means of official web sites somewhat than clicking hyperlinks in unsolicited messages, even if you’re anticipating a parcel.
T-ell household, associates, and authorities about rip-off makes an attempt, and report fraudulent transactions to your financial institution instantly.
For extra data, go to www.scamshield.gov.sg or name the ScamShield Helpline at 1799. To report scam-related data, name the Police Hotline at 1800-255-0000 or submit at www.police.gov.sg/i-witness. For pressing help, dial 999.
Learn additionally: Singapore introduces harder anti-scam guidelines for on-line platforms, with fines of as much as S$10 million