Inside the Fake Bank Security Call Scam in Singapore
How scammers posing as bank officers from DBS, OCBC, or UOB steal one-time passwords and life savings, and how to stop them.
Summarize this article with
Your phone shows your bank's name on the caller ID. The caller knows the last digits of your card and speaks with the calm urgency of a real officer: a suspicious transfer is processing right now, and they need to verify you to stop it. This fake bank security call is one of the most damaging scams in Singapore, and it works because every detail, from the spoofed number to the plausible transaction, is engineered to make you obey first and think later. Learn the script and the whole performance falls apart.
The script, step by step
Bank impersonation calls follow a reliable playbook:
- The hook. An automated message or live caller warns of suspicious activity, such as an overseas transfer or a login from another device. The details sound close enough to real life to feel plausible.
- The reassurance. The caller reads back your name or card digits, information often bought from earlier data breaches, to prove they are genuine. It proves nothing.
- The urgency. The transfer is processing now and only immediate action can stop it. Fear is the engine of the entire scam.
- The extraction. Now comes the ask: read back the one-time password just sent to you, approve a login request, install a screen-sharing app, or transfer money to a so-called safe account.
The instant a bank caller asks for a one-time password, the call is a scam. Full stop.
Why real banks never ask for OTPs or transfers
This rule comes straight from every major bank in Singapore, including DBS, POSB, OCBC, and UOB: a real bank officer will never ask for your one-time password, never ask you to approve a login you did not start, and never instruct you to move money to keep it safe. One-time passwords exist specifically to prove that the person holding your phone is you, so reading one aloud hands over the last factor of authentication. The safe-account story is equally fraudulent: no fraud process in any banking system requires a customer to move their own money. Screen-sharing requests are a third hard line; no legitimate officer needs to see your screen.
The verification callback: your strongest move
If a caller claims to be from your bank, hang up and call the number on the back of your card or in your banking app. This verification callback defeats spoofing entirely. Scammers can make any number appear on your caller ID, including your bank's real customer service line, but they cannot intercept a call you place yourself to the genuine number. Never trust the inbound number, never use a callback number the caller gives you, and say nothing about your accounts until you have hung up and called back. When you reach your real bank, mention the impersonation attempt so it can be flagged.
Red flags in the first minute
Most fake bank calls reveal themselves fast if you know what to listen for. Pressure to stay on the line and not hang up, warnings not to tell anyone because the case is confidential, and threats that your account will be frozen within hours are all script markers. Requests for Singpass logins, card PINs, or remote-access apps have no place in any genuine bank call. Poor call quality, slight delays suggesting a relayed overseas call, and callers who get aggressive when questioned are further tells. A real officer will never object to you hanging up and calling back; a scammer cannot afford to let you.
If you already shared an OTP or sent money
Speed matters more than embarrassment. Call your bank's official fraud line immediately and ask to freeze your accounts, dispute the transactions, and reissue compromised cards and credentials. Change your online banking password and any password shared with it, and review recent transactions for anything unfamiliar. File a police report with the Singapore Police Force, bringing screenshots, numbers, and transaction records. Report the number through ScamShield at scamshield.gov.sg. And watch for follow-up recovery scams, where new callers promise to retrieve your money for a fee; victims' details get recirculated, and round two is always another scam.
Make the call never reach you
Carrier spam labelling from Singtel, StarHub, and M1 catches some impersonation calls at the network level, and the ScamShield app flags or blocks numbers in the shared scam database before you pick up. Keep both active. But habits matter most: hang up on unsolicited security alerts, call your bank back on the card's number, and treat any request for a code as the scam it is. No real bank will ever be upset that you verified, and the fake ones cannot survive being verified.
Sources and review
Reviewed:
Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.
Article details
Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.
Received a suspicious call?
Look up the number in NoCall before sharing data, calling back, or clicking any link.
Search a phone number or a company name (DBS, Singtel and StarHub...) to check if it has been reported as spam.

