Singapore

Phishing simulation for Singapore’s
login, bank and mule lures.

In Singapore, employees see fake government-login alerts, bank impersonation by text and phone, and job offers that recruit money mules over messaging apps.

Regulators & frameworks
MAS TRM Guidelines (18 January 2021), MAS deepfake paper (2025), CSA Cyber Essentials, ISO/IEC 27001:2022
Channels to rehearse
SMS, voice calls, messaging apps, email, Teams and Slack
Local lure patterns
Government-login alerts, bank impersonation, job and mule recruitment
KeenSec evidence
Training records for all staff, simulation results, policy acknowledgements

Simulated Singapore lures

Logins, banks and “easy jobs”:
the pretexts to rehearse.

Simulated examples of the login, bank and job-scam patterns that circulate in Singapore.

Simulated example
SMS

Your bank

Card temporarily blocked

Unusual activity detected on your card. Call our fraud team immediately on the number below to restore access.

  • Callback to an unknown number
  • Urgency around card access
The callback leads into a simulated voice call.
Simulated example
WhatsApp

“Recruiter” · unknown number

Part-time role, paid daily

Earn from home in your spare time. We just need to route client payments through your bank account. Interested?

  • Pay for “using” your account
  • Unsolicited job offer
Money-mule recruitment, rehearsed as awareness.

Why multi-channel matters in Singapore

Scams here start with a text
and finish on a call.

Bank and government impersonation in Singapore often moves across channels: a text creates the scare, and a phone call does the persuading. Job-scam recruiters work through messaging apps, and regional teams live in Teams and Slack.

What is callback phishing?

SAMPLE CAMPAIGN

Bank impersonation chain

  • Day 1: SMS “card blocked” lure
  • Callback: agentic AI voice caller asks for a code
  • Report: who flagged it, and how fast
  • Lesson: just-in-time page on verified numbers
  • Evidence: results added to MAS TRM training records

Illustrative multi-channel campaign.

Questions buyers ask

Frequently asked questions.

Does MAS TRM require phishing simulation?

MAS TRM expects an IT security awareness training programme for all staff; it doesn’t say you must run simulations. Simulation results, training completions and policy acknowledgements are strong evidence of that programme. Your auditor decides compliance.

Can we simulate government-login and bank impersonation?

Yes. KeenSec runs government-login and bank scenarios with generic senders over email, SMS and voice, including the callback step.

Can you train staff on money-mule recruitment?

Yes. Simulate a job-offer lure on WhatsApp and follow it with a short just-in-time lesson on why lending your bank account is a crime risk.

Let’s connect the dots

Rehearse the whole scam chain.
Prove it to MAS.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo