30 September 2026

On 29 September 2026, the Scams (Countermeasures) and Other Matters Act 2026 (“Act”) was gazetted. It is not yet in force and will come in operation on a date to be appointed by notification in the Gazette. The Act will amend the Protection from Scams Act 2025 (“PSA”), the Online Criminal Harms Act 2023 (“OCHA”), and other legislation to strengthen Singapore’s levers to detect, disrupt, and deter scams.

Among other measures, the Act introduces account disabling orders (“ADOs”), disclosure orders (“DOs”), and service limitation orders (“SLOs”) into the PSA to enable the Police to intervene before a scam takes place, establishes a legal framework for scam-related information exchange between the Police and service providers, and increases the maximum administrative penalty for non-compliance with codes of practice (“COPs”) or implementation directives (“IDs”) under the OCHA from S$1 million to S$10 million.

The Scams (Countermeasures) and Other Matters Bill (“Bill”) was passed in Parliament on 9 September 2026. At the second reading of the Bill, Senior Minister of State for Home Affairs and Senior Minister of State for Social and Family Development Goh Pei Ming (“SMS Goh”) provided further details on the new measures.

Supporting scam-related information exchange between the Police and service providers

The Police and the Home Team Science and Technology Agency are developing the National Scams List (“NSL”), a platform to facilitate the exchange of information on suspicious scam accounts between the Government and service providers at speed and at scale. The Act provides the legal framework to enable and safeguard such information exchange through the NSL and other platforms.

The Act introduces ADOs and DOs. An ADO may be issued where the Police suspect or have reason to believe that an account has been, or will be, used preparatory to or in furtherance of a scam-related offence. This threshold is lower than the existing threshold for disruption under the Criminal Procedure Code 2010, enabling the Police to intervene before a scam takes place. The Police may issue a DO directing service providers to disclose information relating to an account provided by the service provider. The Police will need to be satisfied that the disclosure is necessary or expedient to prevent the commission of a scam-related offence, and believe on reasonable grounds that the service provider is capable of disclosing the information.

The Act also protects service providers from civil and criminal liability for acts or omissions done in good faith and with reasonable care in complying with an ADO or DO. Prescribed service providers will additionally be protected when, subject to specified conditions, they voluntarily disclose information for scam prevention notwithstanding confidentiality obligations under legislation such as the Personal Data Protection Act 2012 and the Banking Act 1970 or voluntarily prevent the use of a suspected scam account for up to 30 days.

To protect the confidentiality of shared information, unauthorised disclosure or use of information obtained through an ADO or DO will be an offence, and service providers will be required to implement prescribed confidentiality safeguards.

Enhancing OCHA

Currently, the Police are using the OCHA to fight scams in two main ways:

  • Issuing ex-post directions to online service providers to take down scam-related content; and
  • Issuing ex-ante COPs or IDs to require designated online service providers to impose preventive anti-scam measures on their platforms.

The Act will enhance the penalty regime for COPs and IDs, allow directions under the OCHA to be issued by a computer program, and support a more comprehensive approach to scam prevention.

Enhancing the penalty regime for COPs and IDs

At present, platforms that fail to comply with a COP requirement may be issued with a rectification notice (“RN”). Non-compliance with an RN or ID is an offence punishable with a fine not exceeding S$1 million, and a further fine of S$100,000 for every day or part of a day during which the offence continues after conviction. These fines are imposed by the courts upon conviction.

The Act will amend the OCHA to empower the competent authority to impose an administrative financial penalty of up to S$10 million for each instance of non-compliance with a COP, as an alternative to issuing an RN. Where the non-compliance relates to an ID, the competent authority may similarly impose a penalty of up to S$10 million or issue a compliance order in relation to the ID. Failure to comply with an RN or compliance order is a criminal offence. The courts may impose a fine not exceeding S$10 million and, for a continuing offence, a further fine not exceeding S$300,000 for every day or part of a day during which the offence continues after conviction.

Issuing OCHA directions using a computer program

The Act will allow OCHA directions to be given by the operation of a computer program, including those leveraging artificial intelligence or machine learning. SMS Goh stated that human assessment may be used for lower-confidence decisions and regular audit checks will be conducted. The head of the agency using the program will remain responsible for its use, and existing appeal mechanisms will continue to apply.

Supporting a more comprehensive approach to scam prevention

The Act will amend the OCHA to support a more comprehensive approach to scam prevention. Among other things, the competent authority may require designated online service providers to implement measures that indirectly counter scams or malicious cyber activity, such as public education initiatives. The Act also clarifies that measures imposed by an ID are to be implemented until the ID is cancelled or substituted, and that the competent authority can require information to assess compliance with a COP or ID or whether one should be issued.

Deterring misuse of online accounts

The Act introduces offences targeting the supply, receipt, and misuse of accounts offered by designated online services, such as accounts sold or transferred for use by scammers.

SMS Goh explained that evidential presumptions will apply in specified circumstances to address difficulties in proving criminal intent. For example, a person may be presumed to know that an online account will be used for an unlawful purpose where the account or personal information used to open it is supplied for any gain, or where the person fails to take reasonable steps to ascertain the recipient’s identity, physical location, or purpose.

Individuals convicted of the new offences may face a fine not exceeding S$10,000, imprisonment not exceeding three years, or both. For the new offences regarding the supply or receipt of designated online accounts, or retention of control of designated online accounts opened using the personal information of others, the prescribed penalty for a second or subsequent conviction in respect of an individual is a fine not exceeding S$20,000, or imprisonment for a term not exceeding five years, or both. Discretionary caning of not more than 12 strokes may apply where the individual knew or intended that the designated online account would be used to commit or facilitate a scam offence.

The new offences will also apply to corporations and unincorporated associations. The maximum fines for entities will be double that of the maximum fines applicable to individuals.

The offences will also apply extraterritorially where there is a proven link to harm in Singapore.

Service limitation orders

The Act will empower the Police to issue SLOs, requiring service providers to restrict the provision of specified services to an identified person for up to three years where the Police suspect, or have reason to believe, that the person will use the specified service to commit or facilitate a scam-related offence. SLOs will be used only against mules under investigation who are assessed to be at risk of further facilitating scams, and mules who have been warned, issued composition fines, prosecuted, or convicted. The Police will independently assess each case before issuing an SLO.

New COPs for designated online services

Separately, the Singapore Police Force issued the following COPs for designated online services under the OCHA on 17 August 2026 to strengthen safeguards against evolving scam threats:

  • New COP for Online Messaging and Conferencing Services (“Messaging Code”), which is applicable to seven designated online messaging and conferencing services: WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Message, and Google Meet. The seven designated online messaging and conferencing services will be required to implement the necessary systems, processes, and measures to comply with the Messaging Code by 31 January 2027, with the exception of requirements relating to spoofing of the Singapore Government, which must be complied with by 30 September 2026.
  • New COP for Social Media Services (“Social Media Code”), which replaces the existing COP for Online Communication Services and is applicable to three social media services: Facebook, Instagram, and TikTok. The three social media services will be required to implement the appropriate systems, processes, or measures to comply with the Social Media Code by 31 January 2027.
  • Enhanced COP for E-Commerce Services (“E-Commerce Code”), which continues to apply to the same two designated e-commerce platforms: Facebook Marketplace and Facebook Business Pages. The two designated e-commerce platforms will be required to implement the appropriate systems, processes, or measures to comply with the E-Commerce Code by 31 January 2027.

More information on COP requirements is available on the Singapore Police Force’s Online Criminal Harms webpage.

Reference materials

The following materials are available on the Government Gazette website www.egazette.gov.sg, the Ministry of Home Affairs website www.mha.gov.sg, and the Singapore Police Force website www.police.gov.sg:

More