VishingGuides

Inside the Fake Bank Security Call Scam in Singapore

How scammers posing as bank officers from DBS, OCBC, or UOB steal one-time passwords and life savings, and how to stop them.

N
By NoCall team
NoCall Editorial
4 min read
#bank scam#vishing#bank impersonation#OTP scam#DBS#OCBC

Summarize this article with

Your phone shows your bank's name on the caller ID. The caller knows the last digits of your card and speaks with the calm urgency of a real officer: a suspicious transfer is processing right now, and they need to verify you to stop it. This fake bank security call is one of the most damaging scams in Singapore, and it works because every detail, from the spoofed number to the plausible transaction, is engineered to make you obey first and think later. Learn the script and the whole performance falls apart.

The script, step by step

Bank impersonation calls follow a reliable playbook:

  1. The hook. An automated message or live caller warns of suspicious activity, such as an overseas transfer or a login from another device. The details sound close enough to real life to feel plausible.
  2. The reassurance. The caller reads back your name or card digits, information often bought from earlier data breaches, to prove they are genuine. It proves nothing.
  3. The urgency. The transfer is processing now and only immediate action can stop it. Fear is the engine of the entire scam.
  4. The extraction. Now comes the ask: read back the one-time password just sent to you, approve a login request, install a screen-sharing app, or transfer money to a so-called safe account.

The instant a bank caller asks for a one-time password, the call is a scam. Full stop.

Why real banks never ask for OTPs or transfers

This rule comes straight from every major bank in Singapore, including DBS, POSB, OCBC, and UOB: a real bank officer will never ask for your one-time password, never ask you to approve a login you did not start, and never instruct you to move money to keep it safe. One-time passwords exist specifically to prove that the person holding your phone is you, so reading one aloud hands over the last factor of authentication. The safe-account story is equally fraudulent: no fraud process in any banking system requires a customer to move their own money. Screen-sharing requests are a third hard line; no legitimate officer needs to see your screen.

The verification callback: your strongest move

If a caller claims to be from your bank, hang up and call the number on the back of your card or in your banking app. This verification callback defeats spoofing entirely. Scammers can make any number appear on your caller ID, including your bank's real customer service line, but they cannot intercept a call you place yourself to the genuine number. Never trust the inbound number, never use a callback number the caller gives you, and say nothing about your accounts until you have hung up and called back. When you reach your real bank, mention the impersonation attempt so it can be flagged.

Red flags in the first minute

Most fake bank calls reveal themselves fast if you know what to listen for. Pressure to stay on the line and not hang up, warnings not to tell anyone because the case is confidential, and threats that your account will be frozen within hours are all script markers. Requests for Singpass logins, card PINs, or remote-access apps have no place in any genuine bank call. Poor call quality, slight delays suggesting a relayed overseas call, and callers who get aggressive when questioned are further tells. A real officer will never object to you hanging up and calling back; a scammer cannot afford to let you.

If you already shared an OTP or sent money

Speed matters more than embarrassment. Call your bank's official fraud line immediately and ask to freeze your accounts, dispute the transactions, and reissue compromised cards and credentials. Change your online banking password and any password shared with it, and review recent transactions for anything unfamiliar. File a police report with the Singapore Police Force, bringing screenshots, numbers, and transaction records. Report the number through ScamShield at scamshield.gov.sg. And watch for follow-up recovery scams, where new callers promise to retrieve your money for a fee; victims' details get recirculated, and round two is always another scam.

Make the call never reach you

Carrier spam labelling from Singtel, StarHub, and M1 catches some impersonation calls at the network level, and the ScamShield app flags or blocks numbers in the shared scam database before you pick up. Keep both active. But habits matter most: hang up on unsolicited security alerts, call your bank back on the card's number, and treat any request for a code as the scam it is. No real bank will ever be upset that you verified, and the fake ones cannot survive being verified.

Sources and review

Reviewed:

Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.

Article details

Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.

Author: NoCall team4 min read

Received a suspicious call?

Look up the number in NoCall before sharing data, calling back, or clicking any link.

Search a phone number or a company name (DBS, Singtel and StarHub...) to check if it has been reported as spam.