Privacy Ninja



        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

On bank phishing scams: What banking institutions do to reduce them

bank phishing scams
Bank phishing scams are rampant nowadays. This is why Singapore is tightening up security steps to reinforce the local banking and communications infrastructures.

On bank phishing scams: What banking institutions do to reduce them

Singapore is tightening security steps to reinforce the local banking and communications infrastructures, including the need for SMS service providers to check against a registry before sending messages. Banks are also expected to develop “more adaptable” artificial intelligence (AI) programs to detect illicit transactions.

The enhanced precautions come on the heels of a recent series of SMS phishing attacks, which wiped out SG$13.7 million ($10.17 million) from the accounts of 790 OCBC Bank clients. Scammers had modified SMS Sender ID details to push out messages that appeared to be from OCBC, pushing the victims to rectify difficulties with their bank accounts. They then were routed to phishing websites and asked to key in their bank login data, including username, PIN, and One-Time Password (OTP).

According to Lawrence Wong, the finance minister and deputy chairman of the Monetary Authority of Singapore (MAS), banks need to expand their fraud detection skills. They must also strengthen their ability to rapidly stop suspicious activity and reach out to clients to check transactions before they’re processed.

DPOs ensure that the organization and its systems are secured from any vulnerabilities that scammers can exploit.

Authorities are also considering whether clients should be able to freeze their accounts without first contacting their financial institution if they believe their accounts have been compromised.

Currently, lenders are looking into expanding the use of biometric technology and accelerating the use of mobile banking apps for customer authentication, authorization, and the delivery of bank notifications, which, according to Wong, could make it more difficult for scammers.

In response to the OCBC scams, the MAS mandated new security measures, including mandating banks to delete hyperlinks from email or SMS messages delivered to consumers and implementing a 12-hour delay in activating mobile software tokens. 

Also Read: Cybersecurity in 2022: What businesses should know

Banks also are expected to develop “more adaptable” artificial intelligence (AI) programs to detect illicit transactions.

Wiped out

Many clients told their stories to the local media about how their life savings had been completely wiped out, and many expressed anger with the bank’s poor response time when they attempted to phone its 24-hour hotline. The event also prompted concerns about protections in the context of Singapore’s efforts to portray itself as a global center for technology and digital finance. 

“This is by far the most serious phishing scam we have seen involving spoofed SMSes impersonating banks,” Wong said to lawmakers who put forward 39 questions about the incident. “I should add that this was not a cyber attack on OCBC, but a phishing scam on OCBC’s customers who were deceived into providing their banking credentials and OTPs at scam websites set up by the scammers. At no time was the bank’s systems breached.”

As a result, OCBC has provided full goodwill repayments to all impacted customers and enhanced its security measures, including beginning transaction notifications for fund transfers through PayNow and inter-bank payments for sums as small as one penny, among other things.

How a DPO can help against bank phishing scams

Data Protection Officer (DPO) oversees data protection responsibilities and ensures that organizations comply with the Personal Data Protection Act (PDPA). Every Organization’s DPO should be able to curb any instances of Phishing scams as it is the officer responsible for maintaining the positive posture of an organization’s cybersecurity. 

For instance, at Privacy Ninja, we randomly conduct simulated email phishing to clients to see if there are any vulnerabilities present that a bad actor can exploit and patch them to ensure that the client will never be a victim of such a scam. 

DPOs complement the efforts of financial institutions in battling scams as DPOs ensure that when there is an instance of a cyberattack, a protocol for dealing with it has been established and can be employed to protect clients’ personal data.

DPOs play a crucial role when an organization is hit with phishing attacks, similar to the recent incidents with the OCBC. This is because they ensure safeguards are put in place to combat it when it happens.

Bank phishing scams: Measures to bolster digital banking security

DPOs ensure that the organization and its systems are secured from any vulnerabilities that scammers can exploit. It is important to have a rigid system free of any loopholes to ensure that security is at its peak. 

On 19 January 2022, the MAS and the ABS announced the impending implementation of a set of additional measures aimed at enhancing the security of digital banking. Among the steps being considered by Singapore’s banks in consultation with the MAS are the following:

  1. Delete clickable links from emails and text messages sent to retail consumers;
  2. The default threshold for notifying consumers of funds transfer transactions is S$100 or less;
  3. At least 12 hours must pass before a new soft token can be activated on a mobile device;
  4. Notification of any request to convert a customer’s mobile number or email address to an existing mobile number or email address registered with the bank;
  5. Additional precautions, such as a cooling-off period prior to implementing requests for significant account modifications, such as changes to a customer’s critical contact information;
  6. Customer help teams that are dedicated and well-resourced to dealing with input on probable fraud instances on a priority basis; and
  7. Alerts about scams on a more frequent basis.

These safeguards mitigate the risk of being duped by phony links in scam SMS messages and improve the possibility that customers will be notified immediately of any fraudulent transaction or attempt to take control of their bank account. Additionally, the MAS is monitoring large banks’ fraud detection processes to ensure they are appropriately ready to deal with the growing threat of online fraud.

A Data Protection Officer (DPO) oversees data protection responsibilities and ensures that organizations comply with the Personal Data Protection Act (PDPA).

Bank phishing scams: UOBs stringent measures to combat phishing scams

Like any other banks, UOB has also made security measures to ensure that the massive phishing scam incident that happened on OCBC will never happen again. The following are the recent measures to combat phishing scams:

  1. Resetting all default transfer limits to S$5,000.
  2. One-time fund transfers are limited to S$5,000; additional transaction signing is required for transfers exceeding S$1,000.
  3. For newly added payees, an additional transaction signature will be required for transactions over $5,000.
  4. A 12-hour delay on the addition of new payees for transfer.
  5. The transaction notification threshold is set to S$100 by default.
  6. A 12-hour delay before the Digital Token is activated
  7. Receive SMS notifications when a request to update contact information is received.
  8. Receive email notifications when you first connect to the UOB TMRW app or UOB Personal Internet Banking account using a new device or browser.
  9. All clickable links in bank-sent SMSes and emails have been disabled.
  10. Anti-scam alert while logging into UOB Personal Internet Banking via the UOB TMRW app.

This will make sure that the history will never repeat itself and the learning we had with OCBC will be embodied moving forward.

Also Read: Guarding against common types of data breaches in Singapore



Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection


We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.


Click one of our contacts below to chat on WhatsApp

× Chat with us