Singapore is moving aggressively to combat a deepening scam crisis by introducing comprehensive legislation that targets online account mules and strengthens enforcement powers against digital platforms. The Scams (Countermeasures) and Other Matters Bill, presented in Parliament on Tuesday, August 4, represents a significant escalation in the city-state's battle against fraud syndicates that have transformed social commerce and messaging apps into crime facilitators.

The proposed law creates new criminal offences specifically addressing the supply and misuse of online accounts on platforms including Carousell, TikTok, Telegram, Facebook, Instagram and WhatsApp. Previously, authorities could prosecute those who provided money mule services or sold illegally obtained SIM cards and Singpass credentials, but a critical enforcement gap existed around digital accounts. This loophole enabled sophisticated criminal networks to rapidly establish thousands of fraudulent accounts across multiple platforms. Under the new framework, individuals who furnish personal information for account creation, supply accounts for criminal purposes, or purchase such accounts will face criminal liability. Convictions carry penalties of up to S$10,000 in fines, imprisonment for up to three years, and twelve strokes of the cane.

The scale of Singapore's scam problem underscores the urgency behind these measures. In 2025 alone, scams accounted for three of every five police reports filed in the country, with total losses reaching S$913.1 million. The trajectory has been alarming, with cumulative scam losses exceeding S$4 billion since 2019. Government impersonation scams more than doubled from 1,504 cases in 2024 to 3,363 cases in 2025, making it the fifth most prevalent scam type. These figures reflect a fundamental shift in how criminals operate, moving away from traditional telephone-based deception towards coordinated digital campaigns that exploit the speed and anonymity of online platforms.

A parallel provision substantially increases penalties for non-compliant online service providers. The maximum fine rises from S$1 million to S$10 million, while the daily fine for continuing violations increases from S$100,000 to S$300,000. This represents direct pressure on major platforms to implement robust anti-scam controls. Meta has already received two implementation directives, in September 2025 and January 2026, requiring deployment of stronger fraud detection systems. Police data suggests these mandates have reduced impersonation scams on Facebook, demonstrating that regulatory pressure combined with technological investment can yield measurable results.

Criminal syndicates have adapted rapidly to enforcement efforts by deploying artificial intelligence to automate account creation, content posting, and targeting of victims. This technological sophistication has outpaced traditional manual review processes, which cannot scale to detect the vast quantities of fraudulent material appearing daily. The Bill addresses this asymmetry by authorizing police to issue anti-scam directions through computer programmes, including AI-powered systems. This technological countermeasure would enable automated identification and removal of suspect accounts and advertisements at machine speed, potentially neutralizing entire fraud campaigns within hours rather than days. The legislation includes safeguards requiring accuracy and fairness in algorithmic enforcement, though critics may question how such safeguards function in practice.

Three new police powers form the operational core of the legislation. A disclosure order would compel service providers to furnish information about specified accounts and scam-related transactions, enabling rapid investigation and victim identification. An account disabling order permits authorities to suspend specific accounts for up to 30 days with a possible single 30-day extension, disrupting fraudster operations and preventing further exploitation. These tools will feed into the Government's National Scams List, a forthcoming shared database enabling automatic, real-time information exchange between authorities and financial institutions. This infrastructure allows banks to freeze suspected accounts and intercept fund transfers before criminal proceeds disappear into overseas networks.

During February's Ministry of Home Affairs budget debate, Minister of State for Home Affairs Goh Pei Ming indicated the database will include culprit identities, bank account details, telephone numbers, and online account information. This represents a fundamental institutional change, shifting scam response from reactive investigation to proactive prevention. When a bank detects a flagged account receiving funds, it can immediately freeze the transaction, effectively closing the money flow pathway before victims' assets leave the jurisdiction. This approach directly targets the economic viability of scam operations, which depend on rapid capital movement to avoid detection and forfeiture.

The Bill also strengthens an existing framework restricting mule services. Since October 2025, the facility restriction framework has placed 1,423 money mules, 1,439 SIM card mules, and 53 corporate mules under restrictions affecting their access to financial, telecommunications, and Singpass services. Compliance has largely operated on a voluntary basis through sector-specific mechanisms, but the new legislation introduces a service limitation order allowing police to formally restrict service provision for scam prevention purposes. These restrictions can extend up to three years, creating sustained consequences for individuals who knowingly facilitate fraud. The approach balances firm enforcement with rehabilitation potential, as compliant individuals can eventually restore service access.

For Malaysia and other Southeast Asian economies, Singapore's legislative response offers instructive parallels. Scam networks operate across borders, with syndicates in one jurisdiction targeting victims throughout the region. Singapore's emphasis on disrupting the technical infrastructure—online accounts, payment rails, telecommunications credentials—addresses attack vectors relevant everywhere. The creation of automated enforcement mechanisms and real-time information-sharing frameworks represents best practice applicable to regional cooperation. However, the regional effectiveness ultimately depends on comparable legislative frameworks in neighbouring jurisdictions and functional cross-border cooperation agreements.

The legislation reflects recognition that traditional criminal penalties prove insufficient against industrialized fraud networks operating at digital scale. Scammers calculate risk-reward ratios using economics of scale; if a syndicate can establish ten thousand accounts at minimal cost and execute campaigns before detection, then the expected value of deception exceeds the probability-discounted cost of apprehension. By dramatically increasing service provider penalties, mandating automation-enabled detection, and restricting mule participation, Singapore's approach targets the economic foundations supporting fraud operations rather than merely punishing individual perpetrators after the fact.

Implementation challenges will prove substantial. Service providers must develop and maintain costly compliance infrastructure, raising questions about whether smaller platforms can afford required systems. The technical accuracy of AI-driven enforcement systems remains uncertain, with risks of false positives that could disable legitimate accounts. The expansion of police powers to unilaterally disable accounts raises civil liberties questions about due process and appeal mechanisms. Nevertheless, the scope and severity of Singapore's scam crisis appears to have generated political consensus that enhanced enforcement powers are justified by the magnitude of victimization and economic damage occurring.