Don't take
the bait.
Three short modules on how phishing actually works today, from classic email scams to compromised-vendor attacks to SMS and QR-code tricks. Each part ends with a hands-on challenge.
Don't take
the bait.
You don't need to be an IT expert to catch a phishing email. You need ten seconds and a simple checklist. This guide shows you exactly where to look, with examples marked up.
Run every suspicious email through SUNDAE
SUNDAE is the checklist used in Singapore's public cyber-awareness campaigns, so it's the one your staff will keep seeing. Six red flags: if even one shows up, stop and verify through a channel you trust.
Spelling errors and bad grammar
Typos, odd phrasing, or awkward wording a real organisation wouldn't send.
Urgent or threatening message
Deadlines, threats, or "your account will be terminated." Pressure designed to make you act before you think.
Name of sender doesn't match the email address
The display name says one thing; the actual address behind it says another.
Domain or email address isn't legitimate
The domain is misspelled, padded with extra words, or a look-alike, like rnicrosoft.com imitating microsoft.com.
Attachment looks malicious
An unexpected file, especially .html, .zip, or anything asking you to "enable content."
Email links with misleading addresses
The link text and its real destination don't match. On a computer, hover over the link to see where it truly goes.
SLAM is a widely-used international shortcut: the same checks as SUNDAE, compressed into four. It isn't an official standard, but it's easier to hold in your head. Use whichever one sticks.
Anatomy of a phishing email
Here's a classic "your password is expiring" scam. The red marks show every tell. Then the black panel decodes each one.
Dear Valued User,4
Our system has detected that your password will expire today. To avoid permanent loss of access to your account5, you must verify your credentials immediately.
Link: http://office365-secure-login.account-verify.net/login6
If you do not act, your account will be terminated and all data deleted.7
Regards,
IT Helpdesk Support Team
The "overdue payment" trap
These target anyone who handles money or accounts. The attachment is the weapon.
Hello,
Please find attached your overdue invoice. Payment is 60 days late4 and must be settled today to avoid legal action. Open the attached document and confirm your banking details to process.
Kind regards,
Accounts Receivable
"Quick favour" from the CEO
The sneakiest kind: no links, no attachments, no bad grammar, just a plausible request from someone senior. This is what catches careful people.
Hi,
I'm in back-to-back meetings and can't take calls. I need you to handle something quickly and discreetly.3
Can you purchase 5 × $200 gift cards4 for a client gift? Send me the codes by photo. I'll reimburse you this afternoon. Keep this between us for now.5
Thanks,
David
Sent from my iPhone
When the only tell is one character
The best phishing gets the brand, tone, and grammar exactly right. There's no obvious mistake to catch. The giveaway is hidden in the sender's address, and you only see it by reading it slowly, one character at a time. This is the kind that beats a simulated test.
We noticed a new sign-in to your Microsoft account from a new device. If this was you, you can safely ignore this email.
If you don't recognise this activity, please review it to keep your account secure.
Thanks,
The Microsoft account team
See where a link truly leads: hover, don't click
On a computer, resting your mouse over a link, without clicking, reveals its real destination in a small tooltip and in the bar at the bottom of the window. If that address doesn't match the text, it's a fake. Here's the reveal in action:
Your Microsoft 365 sign-in needs to be re-verified. Please confirm your account here:
https://login.microsoftonline.com/verify http://rnicrosoft-verify.com/login
Sign in with your work email to continue.
What a homoglyph is
The trick above has a name: a homoglyph attack. Homoglyphs are characters that look the same but are different to a computer, so an address can look right to your eye while pointing somewhere else entirely.
Two kinds show up most:
1. Latin look-alikes. Ordinary letters and numbers arranged to fool a glance, like rn reading as m, a capital I as a lowercase l, or a zero as an o. No special characters involved, just a quick eye.
2. Non-Latin look-alikes. Letters from other alphabets that are drawn identically. A Cyrillic а, е or о is pixel-for-pixel the same as the Latin one, so аmazon.com (Cyrillic first letter) is impossible to tell from the real thing by sight.
This is why homoglyphs are the hardest phishing to catch: there is often nothing visible to spot. Worse, a careful attacker can register the look-alike domain and set up its email authentication properly, so it can even pass SPF, DKIM and DMARC. Those checks only prove the mail really came from the domain shown; they cannot tell you that domain is a fake.
So how do you catch what you cannot see? Let the computer show you the real characters. Browsers convert non-Latin domains into an ASCII form called punycode, which always starts with xn--. Hover over any link (on a computer) and check where it truly goes:
The rule: if a hover preview reveals an address beginning with xn-- that you were not expecting, treat it as hostile. And whenever a login or payment is involved, do not trust the address at all, open the site yourself by typing it or using a saved bookmark.
The lookalike alphabet
These character swaps are designed to slip past a quick glance. Any address containing one deserves a slow second look.
Real vs. fake: spot the difference
Attackers register domains that look right at a glance. Read every character. The trick is almost always in the domain, the part right before the first single slash.
Phishing by calendar invite
Phishing doesn't only arrive as an email. Attackers also send meeting invites, because on many calendars an invite adds itself to your schedule before you accept, then reminds you to click at meeting time. The malicious link hides in the location or the notes.
Confirm details now
The four emotional hooks
Phishing rarely beats your knowledge. It beats your feelings. Naming the hook helps you resist it.
Urgency
A ticking clock stops you thinking. Deadlines, "expires today," "final notice."
Authority
A request that seems to come from a boss, IT, HR, or the bank feels safe to obey.
Fear
Threats of loss, fines, or account closure push you to comply before verifying.
Curiosity / reward
A refund, prize, parcel, or juicy attachment you just have to open.
Do this, in order
You don't have to be certain it's phishing. "Not sure" is exactly when to use these steps.
Stop. Don't click, reply, or open anything.
Not the link, not the attachment, not "unsubscribe." Your instinct that something's off is usually right.
Verify through a channel you trust.
Call the person or company on a number you already have, never the one in the email. Type the website in yourself instead of clicking.
Report it.
Use the "Report Phishing" button in your mail app, or forward it to your IT / security team. Reporting protects everyone else too.
Delete it, and if you clicked, tell IT immediately.
Clicked or entered a password? Speak up fast and change that password. Early reporting turns a big problem into a small one. You will not be in trouble for reporting.
The 10-second checklist
Test yourself when ready
Ten emails, ten seconds each. See how many phishing attempts you can spot, then get a full breakdown of what to watch for next time.
The trusted sender trap.
Part 1 taught you to check the sender, the domain, the link. This one covers what happens when all three are genuine, because the account really does belong to your vendor, contractor, or colleague. It has just been taken over.
When the sender checks out, run RADAR
RADAR is behaviour based, so it still works when the account is completely genuine. It's a memory aid built for this training, not an official standard, same as SLAM in Part 1.
Request changed
A different bank account, a new payee, an "updated" invoice for an existing order. Genuine payment details rarely change over email.
Asks urgency + secrecy
"Confirm today" and "keep this between us" almost never belong in the same real email. That pairing exists to stop you checking.
Different channel
A push to move to WhatsApp, a personal email, or a "quicker" side chat, away from the usual thread or system of record.
Attachment unexpected
A password-protected zip, an unusual file type for that contact, or a "document portal" link neither of you has used before.
Rhythm feels off
A different greeting, sign-off, or level of formality compared to how this person usually writes to you.
The compromise chain, step by step
This is not a single email. It is usually a short campaign that starts well before you ever see a message.
Passes SUNDAE, still worth a RADAR check
Two real-thread scenarios
Both emails below pass SUNDAE completely. The tell is entirely in the request.
Hi, apologies for the short notice. Our bank has flagged some issues with our usual account so we have moved to a new one temporarily. Could you please update the details below and process payment today, our finance lead is travelling and this needs to close before end of day.
Please do not loop in the wider team for now, we are keeping this change quiet until it is confirmed on our end.
Fictional example for training purposes only. Any resemblance to a real supplier is coincidental.
eh can u take a look at this asap, client chasing. file was too big so used this new sharing link, should open straight away. need ur ok by end of day latest thanks so much
Fictional example for training purposes only. Any resemblance to a real colleague is coincidental.
Do this, in order
Same principle as Part 1: you don't need to be certain. "Not sure" is exactly when to use these steps.
Stop. Don't act on the request yet.
Not the payment, not the reply, not the attachment. A genuine urgent request can wait for a two-minute check.
Verify on a separate, known channel.
Call a phone number you already had on file, not one in the email. Ask the actual person, don't reply to the same thread.
Don't open unfamiliar attachments or links.
Even from people you trust. If in doubt, ask them to resend through your usual shared system instead.
Report it.
If the account really is compromised, the real person needs to know too, and so does IT.
Spot the trusted sender trap
Five real-thread scenarios where the sender checks out completely. Can you still catch the tell?
Don't tap
the link.
Email phishing needs you to read carefully. Text phishing needs you to tap fast, on a small screen, while you're walking, queueing, or half paying attention. This guide covers SMS, iMessage and WhatsApp scams built to steal your details, or worse, put malware on your phone.
Run every text through TEXT
CSA's own national campaign boils this down to two words: stop, then check. This guide breaks that pause into four things to actually look at on a phone screen. It's a memory aid built for this training, not an official standard, same as SLAM in Part 1.
True sender
Is it a registered name, like a bank, courier, or "gov.sg", or a random local or overseas number?
Expected
Were you actually waiting on this delivery, bill, or account notice? Unprompted "problems" are the opening move.
eXamine the link
Don't touch it at all, not even to preview. Verify through the official app instead, never through anything in the message.
Told to act first
Reply "Y", install an app, or "confirm" before you can see details? Genuine services never gate information behind an action.
Anatomy of a scam text
A message dressed up as a government agency, sent to an iPhone. iOS already flagged it as spam, but the marked-up version below shows exactly why.
[LTA Central Clearing]2
Database audits show an unpaid ERP transaction linked to your vehicle record. The automated deduction was interrupted due to a localized OBU synchronization drop during transit at the CTE gantry checkpoint.3
Please manage this clearance via official LTA digital platforms:
https://onemotoring-iox.top/sg4
Accounts with unsettled balances face an immediate administrative restriction, blocking digital road tax issuance and ownership transfer clearances after 12/08/2026.5
Why texts say "reply Y to activate the link"
This one only works on messaging apps, which is exactly why it doesn't show up in email phishing. It turns one of your phone's built-in protections against you.
[Ninja Van] Parcel Notification – Further Delivery Action Required2
At 07:15 am, our courier Theo Harwood (ID: 517968) attended your delivery address for parcel NVSG7849201536. The address provided did not contain the required unit number (#).
Please click here to add your unit details so we can send it out again:
https://ninjavan.pxqvma.club/com3
(Simply reply with "Y", then close the SMS and reopen it to activate the link. If the link still does not work, please copy it and paste it directly into Safari.)4
The parcel is now being held pending updated delivery instructions... will be held until 31 July.5
The sender is not in your contact list
Ninjavan Courier: I'm sorry to tell you that the label on your order is damaged... Please check and confirm your address online within 24 hours.2
https://ninjavan.xotnbx.help/my3
(Reply with "Y" and reopen the text message to activate the link, or copy the link directly into your browser)4
Real vs. fake: sender IDs and links
Singapore runs a registry that outs spoofed senders. Knowing it exists turns "does this look official" into something you can actually check.
Organisations that send SMS under a name instead of a number must register that Sender ID with the SMS Sender ID Registry, run by SGNIC under IMDA. Since 31 January 2023, any unregistered Sender ID sent to a Singapore number is automatically tagged "Likely-SCAM". Every government agency now sends under one single verified ID, "gov.sg", instead of dozens of separate names.
What a registered sender ID looks like
Genuine mass SMS from an SSIR-registered sender shows a name at the top of the thread, not a number, and never asks you to tap a link to avoid a penalty. Below is a real gov.sg message in that format, a National Day Parade ticket acknowledgement: short, factual, no link, and no action requested.
National Day Parade
---
We have received your NDP 2026 ticket application for 6 tickets on NDP 2026 (9 August 2026).
---
This is an automated message sent by the Singapore Government.
The code you can't preview before you scan
A QR code hides its destination until the moment you scan it, so the "eXamine the link" habit from the TEXT framework doesn't work the same way here. CSA and the Singapore Police Force have jointly warned the public about this since 2023, and it hasn't slowed down.
Stuck over the real one
Scammers print a sticker matching a stall's genuine PayNow or NETS QR code and paste it directly on top. You scan, you pay, the money goes to the scammer, not the stall. This exact method is well documented overseas; Singapore payment-security commentary has flagged the same tactic here, though it's a pattern to watch for rather than one confirmed police case.
The "free reward" survey
A poster or table sticker offers a free drink or prize for scanning and filling in a "survey." A 60-year-old woman in Singapore lost $20,000 this way in May 2023, after the "survey" app she was told to download turned out to be malware.
Fake Singpass "verification"
Scammers ran fake paid surveys, then asked participants to scan a Singpass QR code with their Singpass app as a "verification step" before releasing a reward. Scanning it can hand over control of your actual Singpass.
Parking and delivery notices
Fake QR stickers on parking signage or "delivery held" notices lead to phishing pages that harvest card details, the same playbook as the fake courier texts, just printed instead of texted.
When the text asks you to install something
The most damaging smishing texts don't want your password, they want an app installed on your phone. Once that happens, the scammer doesn't need to guess your OTP, they can just read it.
Police advisories on this pattern are frequent and current. Since February 2025 alone, at least 128 cases were reported with $2.4 million lost, all starting with a link sent over WhatsApp (SPF Advisory, 17 Apr 2025). A newer wave since April 2026 has specifically targeted senior citizens through fake activity ads, with victims later finding their Singpass or ScamShield apps had been uninstalled without their knowledge (SPF Advisory, 18 Jun 2026).
This isn't a one-off. The Annual Scam and Cybercrime Brief 2025 confirms malware-enabled scams saw a significant drop in total losses that year, but police continued issuing standalone advisories on new variants throughout 2025 and 2026, a sign this category is still being actively tracked rather than closed (SPF Annual Scam and Cybercrime Brief 2025, p.2).
The four emotional hooks, text edition
Same four hooks as Part 1, compressed into a sentence you read in under two seconds.
Urgency
A short window before something is restricted, returned, or cancelled.
Authority
A government agency, bank, or courier you actually deal with, so the request feels routine.
Fear
A restriction, block, or loss of access hanging over an ordinary transaction.
A small, plausible snag
Not a prize this time, just a minor delivery hiccup that feels too mundane to fake.
Do this, in order
Same principle as email: you don't need to be certain. "Not sure" is exactly when to use these steps.
Stop. Don't tap, reply, or install anything.
Not the link, not "Y", not "STOP". A reply can unlock the link or confirm your number is active.
Verify through a channel you open yourself.
Use the courier's own app, your banking app, or a bookmark you already trust, never anything from the message. For anything unclear, call the ScamShield Helpline at 1799, or check the ScamShield app.
Report it.
Use "Report Junk" on iPhone or "Report spam" on Android/WhatsApp, and report the number in the ScamShield app so it's flagged for others too.
Delete it, and if you acted on it, move fast.
Tapped, entered details, or installed an app? Tell your bank immediately and change your passwords. If you installed an APK, switch to Airplane Mode and get help removing it; a factory reset may be needed. You will not be in trouble for reporting.
The 10-second text checklist
When in doubt, don't guess
The ScamShield app checks numbers and links against Singapore's scam registry for free. Over 1.53 million people already have it, and the 24/7 helpline is 1799 (SPF Annual Scam and Cybercrime Brief 2025, p.31).