Singapore is moving to close legal gaps in its fight against online fraud by criminalising the creation and trade of scam-enabling accounts on major digital platforms. Legislation introduced in Parliament on Tuesday (Aug 4) targets the mechanics of scam operations that have plagued the city-state, proposing new offences against those who supply personal information to establish fake accounts on Facebook, Instagram, WhatsApp, Telegram, TikTok and Carousell. The Scams (Countermeasures) and Other Matters Bill represents a significant escalation in Singapore's regulatory approach, extending existing protections for financial systems to encompass the broader digital ecosystem exploited by fraudsters.

While Singapore already prosecutes traditional money mules and those trafficking in SIM cards or Singpass credentials, the legislative framework contained a blind spot regarding online account mules who facilitate crime through social media and e-commerce platforms. The new bill closes this enforcement gap by making it illegal to supply, receive, possess or provide personal details for creating accounts intended for criminal purposes. Those convicted face substantial penalties: fines reaching S$10,000, imprisonment for up to three years, and corporal punishment of 12 strokes of the cane. The severity of these penalties reflects policymakers' assessment of the scale and sophistication of organised scam networks.

The legislation also represents a dramatic recalibration of how Singapore regulates technology companies. Platforms that fail to comply with government codes of practice and implementation directives now face maximum fines escalating from S$1 million to S$10 million, with daily penalties for continuing violations increasing from S$100,000 to S$300,000. This tenfold increase in financial consequences signals that Singapore views persistent non-compliance by major tech corporations as requiring enforcement teeth comparable to serious corporate misconduct. Meta, which received implementation directives in September 2025 and January 2026, already experienced reduced impersonation scams following such requirements, providing evidence that regulatory pressure yields measurable results.

The scale of Singapore's scam problem underscores the urgency of these measures. Fraud accounted for three of every five police reports filed in Singapore during 2025, whilst victims lost a staggering S$913.1 million that year alone. Since 2019, cumulative scam losses have exceeded S$4 billion, making this a persistent drain on household wealth and economic confidence. Government impersonation scams exemplify how rapidly the landscape has evolved: cases nearly doubled from 1,504 in 2024 to 3,363 in 2025, making this particular scam type the fifth most prevalent category. These figures suggest that criminals have successfully adapted their tactics and are deploying increasingly credible deception techniques.

Criminals have adopted automation and artificial intelligence to overwhelm detection systems. Scam syndicates now generate large volumes of fraudulent sites, accounts and advertisements within compressed timeframes, outpacing manual review capabilities that platforms rely upon. By incorporating AI into their operations, fraudsters have achieved unprecedented scale and speed. In response, Singapore's new legislation empowers authorities to issue anti-scam directives through computer programmes, including AI-driven systems, enabling detection and disruption at machine speed. Police have committed to implementing safeguards ensuring such automated systems remain accurate and equitable, though operationalising this balance remains technically and legally complex.

A central innovation in the bill involves three new police orders designed to mobilise the private sector in combating scams. Disclosure orders will compel service providers including banks, telecommunications companies and online platforms to furnish information about specified accounts and scam-related activity. Account disabling orders will authorise police to require platforms to suspend suspect accounts for up to 30 days, renewable for an additional month. These mechanisms feed into Singapore's developing National Scams List, which will enable real-time automated information-sharing between government agencies and private sector partners. The system promises to allow banks to intercept fund transfers and freeze accounts associated with known scam perpetrators before stolen money circulates through the financial system.

During Parliamentary budget deliberations in February, Minister of State for Home Affairs Goh Pei Ming outlined the scope of information that will populate these shared databases: culprits' identities, bank account details, phone numbers and online account credentials. This comprehensive intelligence-sharing architecture represents a significant integration of government and corporate surveillance capabilities, enabling stakeholders to preemptively restrict accounts flagged as potential scam infrastructure. Such coordination requires unprecedented cooperation between traditionally separate institutional domains and raises questions about data protection, accuracy and the appeal mechanisms available to individuals incorrectly flagged.

The legislation introduces a third enforcement mechanism through service limitation orders, permitting police to instruct service providers to restrict access to financial, telecommunications and identity verification services for individuals suspected of involvement in scam activities. These restrictions can remain in effect for up to three years, creating substantial collateral consequences for those subject to such orders. Singapore has already pilot-tested this approach through a facility restriction framework launched in October 2025, which has placed 1,423 money mules, 1,439 SIM card mules and 53 corporate mules under monitoring as of June 30. Historically, compliance with such frameworks has operated on a voluntary or sector-specific basis, but the new legislation will formalise police powers to mandate cooperation.

For Malaysia and other Southeast Asian nations observing Singapore's regulatory evolution, these developments offer both a cautionary tale and a potential policy template. Singapore's experience demonstrates that scam problems scale rapidly when criminal networks harness digital tools and artificial intelligence, and that traditional legal frameworks designed for physical fraud or financial crimes prove inadequate. The emphasis on targeting account mule networks addresses a transnational vulnerability, as fraudsters often recruit mules across borders to obscure money trails. However, the aggressive expansion of police powers to disable accounts, restrict services and deploy AI-driven detection systems also raises governance questions about due process, appeals and the potential for mission creep as authorities expand definitions of scam-related activity.

The integration of public and private surveillance through shared databases represents a fundamental shift in how Singapore approaches crime prevention, moving from reactive prosecution toward predictive restriction. Banks, platforms and telecommunications providers become enforcers of police-issued directives, creating a distributed surveillance architecture with minimal individual recourse. For Malaysian stakeholders, this raises questions about whether similar approaches would be compatible with domestic data protection frameworks and judicial oversight mechanisms. The focus on online platforms also reflects how scam ecosystems depend entirely on digital infrastructure, meaning that regulatory pressure concentrated on a handful of major technology companies could theoretically disrupt vast criminal networks.

Singapore's willingness to impose S$10 million penalties on platforms represents a calculated judgment that reputational concerns and existing legal obligations have failed to motivate adequate compliance. By raising financial consequences to levels that materially impact corporate performance, regulators effectively shift the cost-benefit analysis for technology companies. However, the approach also assumes that platforms possess the technical and operational capacity to implement such directives effectively, an assumption that may not hold for all companies or jurisdictions. The bill's reference to AI-driven anti-scam directives suggests regulators believe artificial intelligence can operate reliably in this domain, though the technology's susceptibility to adversarial manipulation and false positives remains incompletely understood.

The legislation's approach to criminalising account mules reflects recognition that scam supply chains require multiple intermediaries, and that disrupting recruitment and retention of mules reduces operational capacity. By making it illegal to supply personal information for account creation, rather than merely punishing those who operate fake accounts, the law targets upstream enablers. This represents a shift toward supply-chain accountability that may prove more effective than pursuing individual scammers who can easily relocate or rebrand. For Malaysian policymakers considering similar measures, the question becomes whether equivalent penalties and enforcement capabilities exist to make such legal frameworks meaningful rather than merely symbolic.

As scams continue expanding across Southeast Asia, Singapore's comprehensive legislative response offers valuable lessons about integrating technology regulation, criminal law, and private sector cooperation. Yet the approach also illustrates the tension between security and liberty inherent in deploying automated detection systems and restricted service frameworks. The success of these measures will ultimately depend on implementation rigour, adequate judicial oversight, and whether technological tools can indeed distinguish guilty behaviour from innocent conduct with sufficient accuracy. For the region, Singapore's experience suggests that combating sophisticated, automated scam networks requires equally sophisticated regulatory tools—but also demands careful attention to the governance safeguards necessary when government and corporate power concentrate on identifying and restricting individuals' access to financial and digital services.