Second Reading of the Scams (Countermeasures) and Other Matters Bill – Opening Speech by Mr Goh Pei Ming, Senior Minister of State for Home Affairs & Senior Minister of State for Social and Family Development
8 September 2026
Introduction
1. Mr Speaker, on behalf of the Senior Minister, Coordinating Minister for National Security and Minister for Home Affairs, I move, “That the Bill be now read a second time”.
2. Sir, Singapore’s scams situation has improved since 2025. After consecutive years of increases, both scam cases and losses fell in 2025. This improvement continued into the first half of 2026, where reported scam cases fell by 14.4% to about 16,800 cases, while losses fell by 17.9% to about $411 million, compared to the same period last year. This progress is a result of our strong public-private collaboration, robust enforcement and legal framework, and the adoption of technology. I would like to thank Members of this House for your strong support in our anti-scam efforts, and your personal contributions to spreading anti-scam public education to your constituents.
3. Our fight, however, is far from over. We still receive on average about 90 reported scam cases, involving about $2 million lost, every day. Globally, the scam situation continues to worsen, as syndicates evade international enforcement action. The United Nations Office on Drugs and Crime estimated that scam losses in East and Southeast Asia, Australia and New Zealand approximately tripled between 2023 and 2025. Scammers are also using increasingly sophisticated technologies to deceive victims. Singapore’s wealth density makes us an extremely lucrative target and scam syndicates spare no effort in adapting and attempting to overcome our safeguards.
4. This is why addressing scams remains a top priority for the Government. This Bill advances our fight against scams in three ways:
(a) One, it supports information exchange between the Police and various service providers for scam disruption;
(b) Second, it enhances the Government’s legal levers to combat scams on online platforms; and
(c) Third, it strengthens the Police’s ability to disrupt the supply of scam accounts, and conduct anti-scam operations.
Supporting Scam-Related Information Exchange Between the Police and Service Providers
5. Sir, I will first touch on amendments supporting information exchange.
6. Scammers rely on enablers such as phone lines, online accounts and bank accounts to reach victims and carry out their schemes. These enablers are provided by different service providers, including banks, digital payment token service providers, telecommunications companies, and online service providers. When scammers register for or use these enablers, they leave behind digital footprints that can serve as scam signals. These signals allow us to identify and disrupt other parts of the scam infrastructure. For example, a phone number detected by a telecommunications company as being used for scams, may also be linked to a bank account used to receive scam proceeds.
7. Today, scam signals are not being shared widely or quickly enough to disrupt scams effectively. To overcome technical limitations on this front, I announced during MHA’s Committee of Supply Debate earlier this year, that the Police and the Home Team Science and Technology Agency, or HTX, are developing the National Scams List, or NSL. The NSL is a platform to facilitate the exchange of information on suspicious scam accounts between the Government and service providers at speed and at scale. This Bill in turn provides the legal powers to enable and safeguard such information exchange on the NSL and other information-sharing platforms.
Account Disabling and Disclosure Orders
8. Now, information-sharing platforms like the NSL allow the Police to disrupt scam accounts early and facilitate information disclosure. To empower the Police to operationalise such platforms, Clause 7 introduces new orders into the Protection from Scams Act 2025.
9. First, we will introduce Account Disabling Orders, or ADOs.
(a) ADOs will empower the Police to direct a service provider to disable an account, if the Police suspect or have reason to believe that the account has been, or will be, used preparatory to or in furtherance of a scam-related offence. This threshold is lower than the existing threshold for disruption under the Criminal Procedure Code. This is necessary for the Police to proactively disable the account even before the scam takes place. And this allows a shift in approach from reactive to proactive. The Order may identify the specific account to be disabled or specify conditions for identifying suspicious accounts that should be disabled.
(b) Accounts may be disabled under ADOs for up to 30 days, with one possible extension of up to another 30 days. Clauses 8 and 9 amend the Protection from Scams Act to allow persons affected by ADOs to appeal to the Commissioner of Police. The Commissioner may designate an officer not below the rank of Superintendent, or its equivalent, to hear and determine the appeal.
(c) Non-compliance with an ADO will be a criminal offence.
10. Second, we will introduce Disclosure Orders, or DOs.
(a) DOs will allow the Police to direct service providers to disclose information relating to an account provided by the service provider. The Police will need to be satisfied that the disclosure is necessary or expedient to prevent the commission of a scam-related offence, and believe on reasonable grounds that the service provider is capable of disclosing the information.
(b) The wilful and reckless submission of false and misleading information pursuant to a DO, as well as non-compliance with a DO, will be an offence.
Immunity
11. Service providers have raised concerns that participating in information-sharing platforms could expose them to additional liability, especially where they act voluntarily. For example, civil liability could arise from breaches of confidentiality obligations.
12. This Bill balances these considerations by providing immunity from liability, while limiting it to actions taken for the prevention and detection of scam-related offences.
(a) Clause 10 introduces protections for service providers from criminal and civil liability for actions done, or omitted to be done, in good faith and with reasonable care to comply with an ADO or DO.
(b) Clause 11 introduces protections for prescribed service providers for voluntarily disclosing information. These service providers may voluntarily disclose information to a specified officer or a prescribed Singapore public sector agency. This is despite confidentiality obligations, including under the Personal Data Protection Act and the Banking Act. Certain circumstances need to be met, including:
(i) First, the information is disclosed to a specified officer or a prescribed Singapore public sector agency in the prescribed form and manner;
(ii) Second, the information is disclosed for the purpose of preventing a scam-related offence;
(iii) Third, the information disclosed was obtained by the service provider in the course of complying with, or on the basis of information contained in an ADO or DO, that was issued to the service provider; and
(iv) Lastly, the disclosure was done in good faith and with reasonable care.
(c) Clause 11 also introduces protections for service providers from civil liability for voluntarily preventing the use of an account for up to 30 days. Similarly, certain circumstances need to be met, including:
(i) First, the service provider suspected or had reason to believe that the account had been or will be used for a scam-related offence;
(ii) Second, this suspicion or belief was wholly or partially based on information shared via an ADO or DO; and
(iii) Third, it was done in good faith and with reasonable care.
Data Confidentiality
13. To protect the confidentiality of shared information, Clause 7 makes it an offence for the unauthorised disclosure or use of information obtained through an ADO or DO. Service providers will also be required to implement safeguards, prescribed through subsidiary legislation, to protect the confidentiality of such information. Failure to do so will be an offence.
Enhancing the Online Criminal Harms Act
14. Let me now move on to changes to the Online Criminal Harms Act 2023, or OCHA. OCHA was passed in Parliament in July 2023. And since its commencement in February 2024, the Police have used OCHA to fight scams in two main ways.
(a) One, to issue ex-post directions to online service providers to take down scam-related content; and
(b) Two, to issue ex-ante Codes of Practice or Implementation Directives, henceforth referred to as COPs and IDs respectively, to require designated online service providers to impose preventive anti-scam measures on their platforms. Today, the designated online services are WhatsApp, Telegram, WeChat, Apple, Google, Carousell, Facebook, Instagram, and TikTok.
15. After two years of operationalisation, MHA is now proposing three amendments to ensure that the law remains an effective tool in our fight against scams.
Enhancing the Penalty Regime for COPs and IDs
16. First, we will empower the Competent Authority to impose financial penalties on designated online service providers for non-compliance with COPs or IDs.
17. Today, platforms that fail to comply with a COP requirement may be issued with a Rectification Notice, or RN. Non-compliance with an RN or ID is an offence punishable with a fine not exceeding S$1 million, and to a further fine of S$100,000 for every day or part of a day during which the offence continues after conviction. These fines are imposed by the Courts upon conviction.
18. While criminal prosecution remains necessary in serious cases, charging non-compliant platforms in court may not be an efficient way to deal with less egregious cases. This Bill empowers the Competent Authority to issue an administrative financial penalty to more swiftly address and deter non-compliant behaviour.
19. Clauses 21, 23 and 27 amend the framework in the Online Criminal Harms Act for non-compliance with COPs and IDs. Going forward, for each instance of non-compliance with the COP, the Competent Authority may impose a penalty of up to S$10 million, or issue an RN to rectify the non-compliance with the COP. Where the non-compliance relates to an ID, the Competent Authority may similarly impose a penalty of up to S$10 million or issue a compliance order to the ID.
20. Failure to comply with an RN or compliance order is a criminal offence. The Courts may impose a fine not exceeding S$10 million and, in the case of a continuing offence, to a further fine not exceeding S$300,000 for every day or part of a day during which the offence continues after conviction.
21. Let me make two points about these changes.
(a) First, this approach retains criminal prosecution as an option, alongside the new financial penalty regime. The Competent Authority will decide which is appropriate, based on the facts of each case, considering factors which include the nature and severity of scam harm caused by the non-compliance, the culpability of the platform, and its antecedence.
(b) Second, we have set the maximum administrative financial penalty and fine that the Competent Authority and the Courts respectively can impose at S$10 million. This maximum penalty will be the highest fixed quantum financial penalty in Singapore’s statute book.
(i) We do not take this decision lightly. But it is necessary to provide an adequate deterrent against non-compliance by online platforms, commensurate with the scale of the challenge we are facing, and the severity of harm that scams delivered through online platforms can cause. Members will recall that a scam victim lost S$4.9million from a single scam case involving the impersonation of senior government officials on several online platforms including WhatsApp. Imagine what the scam losses would be had this modus operandi been executed at scale.
22. As the new penalty regime will allow the Competent Authority to impose administrative financial penalties directly on designated online service providers without going through the Courts, we will introduce safeguards to ensure due process.
(a) Clause 23 will require the Competent Authority to inform the designated online service provider of its intent to impose penalties, and to allow the designated online service provider to make written representations explaining why the penalty should not be imposed.
(b) The designated online service provider will have at least 7 days to make these representations. And the Competent Authority may decide, after assessing the written representation, whether to proceed, vary or withdraw the penalty.
(c) If the Competent Authority decides to proceed to impose financial penalties, the designated online service provider may appeal to the Minister for Home Affairs, whose decision is final.
23. While we fully intend to continue our collaborative approach of consulting and working with designated online service providers, the Government will not hesitate to take firm action against errant online service providers, that allow their platforms to be exploited by scammers.
Issuing OCHA Directions Using a Computer Program
24. The second key amendment to OCHA is in Clause 19, which will allow OCHA directions to be given by the operation of a computer program, including those leveraging AI or machine learning technologies.
25. Members will be aware that scammers have been using sophisticated technologies, including generative AI, to create highly convincing scam content, faster and at lower cost.
26. To stay ahead, we too must leverage AI more extensively in our scam disruption efforts. We want to use AI not just to assist in human decision-making, but also to issue OCHA directions in situations where scam content has been identified with a high degree of confidence.
27. To ensure human accountability for the issuance of OCHA directions, Clause 19 provides that a direction can be given by a computer program for which the head of the agency using the program is responsible. For example, this could be the Permanent Secretary of a Ministry or the Chief Executive of a Statutory Board.
(a) The existing appeal mechanism for OCHA directions continues to apply. Appellants may apply to a designated officer for reconsideration, and thereafter to an independent Reviewing Tribunal comprising a District Judge or Magistrate.
28. We will also ensure that AI systems are implemented with the appropriate safeguards, such as human assessment for lower confidence decisions, and regular audit checks.
Supporting a More Comprehensive Approach to Scam Prevention
29. The last key amendment to OCHA will support a more comprehensive approach to scam prevention.
(a) Clause 20 will allow the Competent Authority to impose requirements on designated online service providers, which indirectly counter the commission of scams or malicious cyber activity, such as public education initiatives. This allows the Government to direct the online platforms to work with us on scam education initiatives, which are a vital component of our whole-of-society anti-scam strategy.
(b) Clause 22 makes clear that measures imposed by an Implementation Directive are to be implemented until the Implementation Directive is cancelled or substituted.
(c) Clause 26 makes clear that the Competent Authority can require a designated online service provider to provide information to assess their compliance with any COP or ID, or to assess whether a COP or ID should be issued to the service provider. This allows the Government to evaluate the performance of online service providers vis-a-vis requirements set by the Competent Authority.
Restricting Supply of Scam Accounts and Supporting Police Operations
30. Mr Speaker, the amendments I have shared so far focus on legislative amendments that underpin our collaboration with service providers to combat scams. I will now move to amendments directed at those who facilitate scams.
Offences Relating to the Misuse of Online Accounts
31. Let me first turn to those who misuse online accounts, such as Carousell or WhatsApp accounts, to facilitate scams. We have observed instances where individuals sell their online accounts to scammers. These accounts may even have been Singpass-verified, and can be very convincing to potential victims, luring them into a false sense of legitimacy. We must take a firm stance against such misuse of online accounts.
32. Clause 16 introduces new offences against those who misuse accounts from designated online services, to facilitate criminal activity. In particular, under the new sections 39GA and 39GC of the Miscellaneous Offences (Public Order and Nuisance) Act 1906, or MOA, it will be an offence for a person to:
(a) Supply or offer to supply a designated online account to another person; or
(b) Provide or offer to provide personal information to another person, or consent or offer to consent to personal information being used by another person, for the purpose of opening a designated online account;
If the person knew or had reasonable grounds to believe that the designated online account will be used for an unlawful purpose.
33. Like other scam-related offences, such as the misuse of SIM cards and bank accounts, we expect the Police to face evidential difficulties in proving the offender’s criminal intent. Scam mules often claim that they acted because they were paid and were unaware of the serious consequences of their actions. To address this, going forward, a person is presumed to have known that the designated online account will be used for an unlawful purpose in any of the following scenarios:
(a) One, the person supplied the designated online account or provided or consented to the use of his/her personal information for any gain;
(b) Two, the person failed to take reasonable steps to ascertain the identity and the physical location of the person receiving the designated online account, or using the personal information to open a designated online account; or
(c) Three, the person failed to take reasonable steps to find out the recipient’s purpose for obtaining the designated online account, or using the personal information to open a designated online account.
34. Under the new section 39GB of the MOA, it will also be an offence for a person to:
(a) Receive or offer to receive a designated online account; or
(b) Retain control of a designated online account opened using another person’s personal information;
If the person does so with the intention to use or supply the designated online account for an unlawful purpose.
35. Similarly, a person who receives a designated online account is presumed to have intended to use or supply the account for an unlawful purpose, if the person received the account for any gain. This is intended to address the challenge of proving criminal intent.
36. The penalties for the new offences for misuse of online accounts will be pegged to the misuse of SIM cards under the MOA. Offenders who are individuals will be liable for a fine not exceeding S$10,000, or imprisonment not exceeding three years, or both. As for the offences under the new sections 39GA and 39GB regarding:
(a) Supplying designated online accounts;
(b) Receiving designated online accounts; and
(c) Retaining control of designated online accounts opened using the personal information of others.
The prescribed penalty for a second or subsequent conviction in respect of an individual is a fine not exceeding S$20,000, or imprisonment for a term not exceeding 5 years, or both.
37. In addition, discretionary caning of not more than 12 strokes will apply where the individual knew or intended, that the designated online account would be used to commit or facilitate any scam offence.
38. All the new offences will also apply to corporations and unincorporated associations. As such entities cannot be subject to imprisonment or caning, the maximum fines for entities will be double the amount of individuals.
39. Similar to the offences for the misuse of SIM cards, the offences for the misuse of online accounts will also apply extraterritorially, as long as there is a proven link to harm in Singapore. This is necessary, as most scam syndicates operate from overseas. The offences for the misuse of online accounts will also be arrestable.
40. To be clear, we do not intend to catch those who use designated online accounts for a lawful purpose. A person who receives, supplies or retains the control of a designated online account or provides personal information to another to open a designated online account will not be liable for an offence, if the person has reasonable grounds to believe that the purpose of the act was to facilitate the use of or access to the designated online account for a lawful purpose.
(a) So, what constitutes such reasonable grounds to believe, would depend on the facts of the case.
(b) For example, if a person sets up a WhatsApp account for his or her parent or child thinking that it is solely for their legitimate personal daily use, and is able to provide a credible explanation as to why he/she was led to think so, reasonable grounds to believe may be established.
(c) On the other hand, if a person does so for a stranger with no questions asked as to the purpose of the stranger, or was paid by the stranger to do so, reasonable grounds to believe would likely not be established.
(d) Ultimately, this would have to be assessed on a case-by-case basis.
Service Limitation Orders
41. Next, we will empower the Police to impose restrictions on certain individuals’ access to services that could be exploited to facilitate scams.
42. In October 2025, SPF, MAS, IMDA and GovTech implemented the Facility Restriction Framework. Under the framework, scam mules who:
(a) One, have been warned, issued with composition sums, prosecuted or convicted of mule-related offences; or
(b) Two, are under investigation for mule-related offences and are assessed to be at risk of further facilitating scams;
may face targeted restrictions on their access to facilities. And these facilities may include digital banking, card and ATM services, the subscription of new telephone lines, and the use of Singpass. These restrictions are risk-calibrated and take into account these individuals’ basic financial and communications needs.
43. Service providers, such as banks and telecommunications companies, today comply with the restrictions imposed under the Facility Restriction Framework either voluntarily or pursuant to requirements determined by their sectoral regulators. The Police today cannot compel service providers to impose such restrictions on persons.
44. Clause 7 of the Bill introduces a new set of orders, Service Limitation Orders, or SLOs, under the Protection from Scams Act 2025. SLOs empower the Police to require service providers to restrict the provision of services to a person for a period of up to 3 years. The Police may issue an SLO if the Police suspect, or have reason to believe, that the identified person will use the service specified to commit or facilitate a scam-related offence.
45. Service providers that do not comply with an SLO will be liable for an offence. Service providers that comply with an SLO in good faith, and with reasonable care, will be protected from criminal and civil liability.
46. Individuals subjected to restrictions pursuant to an SLO may appeal to the Commissioner of Police, and the Commissioner may designate an officer not below the rank of Superintendent or equivalent to hear and determine the appeal.
Supporting Police Operations
47. Finally, I will touch on two legislative amendments that will be introduced to support Police operations.
(a) First, with the launch of the Cyber Command in July 2026, SPF will be recruiting civilian talent with the right aptitude and skillsets to the Cyber Command. To support this and the Police’s future manpower needs, Clause 31 amends the Police Force Act to empower the Minister for Home Affairs to appoint Civilian Specialist Officers or CSOs. CSOs will be accorded the necessary powers to investigate any suspected offence which appears to him or her to have been committed under any written law. These include the powers to search, arrest, seize and request for documents. SPF may also deploy CSOs to support other Police units, requiring specialised skillsets in the future.
(b) Second, Clause 6 amends the Protection from Scams Act 2025 to empower specified officers, including Police Officers, Commercial Affairs Officers and CSOs, to obtain information on persons who must be notified of the issuance of a Restriction Order under the Protection from Scams Act. This is necessary as banks are today unable to provide information necessary for the Police to notify persons affected by the Restriction Order, given the banking confidentiality obligations under the Banking Act.
48. Mr Speaker, before I conclude, let me say a few words in Mandarin.
49. 议长先生,我国自去年以来的诈骗案和损失款项显著下降,但诈骗依旧对我们的国人构成严重的威胁。目前,警方每天平均接到约90起诈骗案件,每天平均损失达200万新元。诈骗案件层出不穷,诈骗手法也日新月异。不法分子不断地利用新科技寻找新的突破点,企图欺骗国人辛苦赚来的血汗钱。新加坡的经济高度发达,自然而然也成为了诈骗集团锁定的目标。
50. 这项法案将向三方面加强我国打击诈骗的能力:这项法案将像三方面加强我国打击诈骗的能力:
(a) 第一,我们将继续严打钱骡和协助诈骗者。诈骗分子经常冒用他人的账号来隐藏身份、转移不法所得。我们将进一步的加强相关法律,打击滥用网络账号的行为,并对出售和出借账号者实施严厉的制裁并对出售或出借账号者实施严厉的制裁。我吁请大家不要向他人提供网络账号、密码和个人资料。有些行为看起来可能只是帮个小忙,或者是让自己轻松地赚点快钱,但却能够因此给他人造成巨大的伤害,也可能让自己承担严重的法律后果。
(b) 第二,我们将提高能力更迅速、更主动地打击诈骗网络我们将提高更迅速、更主动地打击诈骗网络。诈骗分子依靠各种账号和服务组成的网络来行骗。这项法案有助警方与服务供应商更快地交换诈骗相关的信息,以确认可疑账号,并采取措施加以阻断,避免更多人受害。而通过及早介入,我们可减少受害者,也希望把损失降到最低也希望把损失降低最低。同时,我们会建立完善的保障、上诉和审核的机制,确保执法人员审慎、公平地行使他们的职权。
(c) 第三,我们将要求网络平台承担更大的责任。目前,网络平台仍是诈骗分子接触受害者的主要渠道。今年上半年,涉及网络平台的诈骗案占约九成。因此,政府将对未履行反诈责任的指定网络服务供应商加大惩处的力量。对于违反《网络犯罪危害法令》下的业务守则和实施指令的平台呢,每次违规的最高罚款将提高至1000万新元。
51. 打击诈骗,人人有责。政府部门、企业、家庭和个人都扮演重要的角色。不出售自己的账号、听取防诈骗的警告,以及主动地和我们的年长者分享诈骗讯息呢,都能够为防范诈骗出一分力。
52. 诈骗分子夺走的不只是金钱,更可能是人们多年来的积蓄、人与人之间的互信,甚至让年长者无法安享晚年。政府将继续完善相关的法律,加强打击诈骗的能力,让新加坡继续成为国人能够安居乐业的理想家园。
Conclusion
53. Mr Speaker Sir, every scam is more than a statistic. Each case involves a victim who may have lost his hard-earned life savings, destroyed his confidence in digital transactions, or demolished his trust in the people around him. Scams strike not only at individual victims, but at the very trust underpinning our digital economy and our way of life.
54. The measures in this Bill are firm, but they are also calibrated. They preserve accountability, provide safeguards and appeal mechanisms, and support constructive collaboration with service providers. This balance is important: we must act decisively against scammers and their enablers, while maintaining public confidence that powers will be exercised carefully and fairly.
55. The improvement in our scam situation shows that our efforts can make a tangible difference. But scammers will continue to adapt, and so must we. Our response must be sustained, coordinated and always forward-looking. The Government will continue to review our laws and strengthen our operational capabilities against scams, so that Singapore remains a trusted, safe and secure place to live, work and transact.
56. Sir, I beg to move.
