Singapore’s Cyber Command has disrupted over 30,000 Apple iMessage accounts tied to a courier impersonation scam campaign, with estimated losses climbing to S$2.2 million as of August 20, 2026. The scam, which began in June 2026, exploits a gap in Singapore’s messaging fraud safeguards by circumventing an iMessage feature designed to block links from unknown senders.
Key Facts At A Glance
- More than 30,000 Apple iMessage accounts disrupted since June 2026
- Estimated losses reached S$2.2 million as of August 20, 2026, up from S$1.2 million reported on August 5
- Losses rose by more than 80 percent within roughly two weeks
- Scammers impersonate courier firms including Ninja Van, J&T Express and SPX Express, as well as government agencies and financial institutions
- Messages typically originate from foreign number prefixes such as +212, +63 and +44, or from randomized alphanumeric email addresses
- Victims are directed to spoofed websites requesting card details or online banking credentials
- iMessage falls outside Singapore’s network-level SMS anti-scam filters and the SMS Sender ID Registry
- Police issued new Codes of Practice under the Online Criminal Harms Act on August 17, covering seven messaging and calling services
How The Scam Operates
The campaign relies on a workaround to one of Apple’s built-in anti-phishing protections. iMessage normally renders links unclickable when they arrive from an unknown sender, only activating them once the recipient responds. Scammers have adapted to this by prompting victims to reply “Y” or “1” to a message claiming a delivery issue or unpaid fine, which reclassifies the sender as known and unlocks the embedded link. Recipients are then routed to websites closely mimicking those of legitimate courier companies, government bodies or banks, where they are asked to make a small payment or settle a supposed fine using card or internet banking details.
The Singapore Police Force said some victims who entered one-time passwords on these fraudulent sites later discovered their cards had been added to mobile wallets without authorization, their bank security tokens registered on unfamiliar devices, or unauthorized logins made to their accounts.
Regulatory Gap And Response
Unlike SMS traffic, which is covered by network-level anti-scam filtering and Singapore’s SMS Sender ID Registry, iMessage operates on Apple’s own closed ecosystem and currently sits outside these safeguards, according to police. This has made it a growing vector for impersonation fraud even as scam losses on channels already covered by existing codes fell by about 37 percent between 2024 and 2025.
To close part of this gap, police issued new Codes of Practice under the Online Criminal Harms Act on August 17, covering seven platforms including WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages and Google Meet. Separately, the government has proposed raising the maximum penalty for non-compliance with anti-scam codes to S$10 million per breach, with further detail expected when the Scams (Countermeasures) and Other Matters Bill is debated in Parliament in September.
Police have advised iPhone users to enable the “Filter Unknown Senders” and “Filter Spam” settings, avoid clicking unsolicited links, and verify delivery or payment requests directly through official channels rather than links sent via message. Anyone who notices an unauthorized transaction has been urged to contact their bank immediately.
