KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
Singapore’s decision to reduce the amount of public officer information available through an online government directory reflects a wider cybersecurity problem: information does not need to be confidential to become dangerous. Names, job titles, agencies, email addresses and telephone numbers may be legitimate public information, yet combined together, they can give scammers exactly what they need to build a convincing impersonation.
The issue has become increasingly costly. According to the Singapore Police Force’s Annual Scam and Cybercrime Brief 2025, reported government official impersonation scams more than doubled from 1,504 cases in 2024 to 3,363 in 2025. Losses climbed from 151.3 million SGD to approximately 242.9 million SGD. The government impersonation scam problem therefore raises a question that extends well beyond public directories: how should organisations balance legitimate transparency against the risk that publicly available information will be weaponised?
A directory containing an officer’s name and designation may appear harmless because none of the information is secret. The security problem emerges when several legitimate pieces of information are combined.
A scammer who knows an officer’s exact title, department and contact details can construct a far more credible story than someone making a generic call. A victim who searches the officer’s name online may even find an exact match, creating a false sense that independent verification has taken place.
This distinction was highlighted by Privacy Ninja founder and CEO Andy Prakash, who told The Straits Times that victims “have only verified that the officer exists”. The crucial unanswered question is whether the person contacting them is actually that officer. That observation gets to the heart of modern government impersonation scams: verifying identity information is not the same as verifying the live interaction.
Government impersonation scams often work because they borrow authority from institutions people already trust. A caller may claim to represent the police, immigration authorities or another government agency, then allege that the victim is linked to an unauthorised account, unpaid obligation or criminal investigation.
The technical sophistication can vary enormously. Some scams involve number spoofing, messaging applications or realistic profile photographs. Others need little more than accurate information and a persuasive script. The common mechanism is psychological. The scammer creates urgency, establishes authority and then pressures the victim to act before there is time for independent verification.
Singapore has already introduced technical measures against telephone spoofing. Overseas calls carry a “+” prefix, while telcos block overseas calls that spoof local fixed or mobile numbers. Yet scammers adapt. Messaging services such as WhatsApp sit outside traditional telecommunications controls, giving fraudsters another environment in which to imitate official identities.
The danger of publishing directories goes beyond scams targeting members of the public. Detailed employee information can also support social engineering against the organisation itself.
Knowing who reports to whom, who oversees procurement and who manages grants or licensing gives attackers a picture of organisational relationships. A fraudster could pose as a senior official using a lookalike email address and contact a junior employee with an apparently plausible request. Because the names, positions and relationships are genuine, the message passes an important psychological test before the recipient has even examined the sender address.
Private-sector organisations should pay attention to this aspect of government impersonation scams. Corporate websites routinely publish leadership teams, employee biographies and direct email formats. LinkedIn adds another layer of organisational intelligence. None of this necessarily needs to disappear, but organisations should understand how easily separate pieces of public information can be assembled into an attacker’s reconnaissance file.
Reducing directory information will not eliminate government impersonation scams. Information already harvested may remain in databases, cached webpages or criminal datasets, and senior officials will inevitably remain publicly identifiable.
What the change can do is increase the attacker’s cost. Social engineering benefits from accuracy. If an attacker has to work harder to identify the correct officer, current job title and direct contact channel, scalable impersonation becomes less efficient. Old data also loses value as employees move roles and contact details change.
That is an important cybersecurity principle. Defence does not always require making an attack impossible. Sometimes the goal is to remove easy advantages and force attackers to spend more time, money and effort constructing something believable.
Andy Prakash also proposed a stronger approach: verifying the interaction itself rather than relying on static directory information. Under such a model, an authorised government officer could generate a short-lived code during a conversation. The member of the public could enter that code on an official government website and receive confirmation that it had just been generated by the stated officer.
The distinction is significant. A static directory answers: “Does this person exist?” A dynamic system answers: “Is this person genuinely interacting with me right now?”
That principle has applications beyond government impersonation scams. Banks, insurers, healthcare providers and other trusted organisations could explore stronger ways to authenticate outbound communications. As synthetic voices, AI-generated video and sophisticated phishing become more accessible, recognising someone by appearance, voice or knowledge of personal details will become an increasingly weak form of verification.
ScamShield guidance states that government officials will never ask people to transfer money or disclose banking login details over a phone call. It also warns that scammers may cite personal information to appear legitimate. These are useful rules because they shift verification away from whether the caller “knows enough” and towards whether the requested behaviour is consistent with legitimate government practice.
This behavioural approach is increasingly important. People should not interpret possession of accurate information as proof of identity. The same principle applies to businesses. Employees receiving unusual payment instructions, confidential document requests or account changes should verify them using a separate, trusted channel rather than relying on the information contained in the original request.
Government impersonation scams demonstrate how cybersecurity and data protection can intersect even when the underlying information is publicly available. Organisations need to consider not only whether information may legally be disclosed, but also whether publishing unnecessary details creates avoidable security and social engineering exposure.
Privacy Ninja helps organisations strengthen that broader resilience. Our DPO-as-a-Service supports organisations in maintaining appropriate data protection policies and practices, handling data protection matters consistently and keeping PDPA compliance on track. Our cybersecurity services, including vulnerability assessment and penetration testing, help identify weaknesses that attackers may exploit alongside social engineering, while cyber hygiene awareness can help employees recognise when legitimate-looking information is being used to manufacture trust.
The rise of government impersonation scams shows why verification needs to evolve. Static information such as a name, title or telephone number can confirm that an officer exists, but it cannot prove who is on the other side of a call or message.
Singapore’s decision to reduce publicly available officer details can remove useful material from the scammer’s toolkit, but the longer-term answer lies in changing how trust is established. Stronger live verification, restrained publication of unnecessary information and better public awareness can make impersonation harder to sustain. As scammers gain increasingly sophisticated tools, cybersecurity must focus not only on protecting systems, but also on protecting the trust people place in the identities behind them.