Introduction
Singapore has been making a concerted effort to tackle online threats, including the introduction of legislation, regulations and guidance for stakeholders. In particular, scams remain a severe and evolving threat in Singapore, with scammers continuing to adapt their tactics and exploit new technologies and platform features.
In response to the threat posed by scams and malicious cyber activities, the Singapore Police Force (“SPF“) issued three Codes of Practice (“COPs“) on 17 August 2026. The COPs require providers of designated online services to implement measures to proactively disrupt scams and malicious cyber activities affecting people in Singapore.
The three COPs issued are as follows:
- A new COP for Online Messaging and Conferencing Services (“Messaging Code“);
- A new COP for Social Media Services (“Social Media Code“); and
- An enhanced COP for E-Commerce Services (“E-Commerce Code“).
These COPs build on the existing COPs introduced in June 2024, namely: (i) the Online Communication Code and (ii) the E-Commerce Code. In particular, the requirements under the existing Online Communication Services Code have been separated into the Messaging Code and Social Media Code, creating a distinction between messaging applications and social media platforms. Consequently, the existing Online Communication Services Code will be rescinded when the new COPs come into force. For background information on the existing COPs, please refer to our July 2024 Legal update titled “Implementation of the Online Criminal Harms Act – Codes of Practice for Designated Online Services Come into Force“.
This Update summarises the key changes introduced by the new and enhanced COPs and the takeaways for messaging service providers, social media platforms and e-commerce platforms.
Messaging Code
The Messaging Code applies to seven designated online messaging and conferencing services, comprising the following existing designated services: (i) WhatsApp; (ii) Telegram; and (iii) WeChat, and four newly designated services: (iv) Apple iMessage; (v) Apple FaceTime; (vi) Google Message; and (vii) Google Meet. These services have been identified as posing the highest risk of scams to users in Singapore, especially in relation to investment scams and Government Officials Impersonation Scams (“GIOS“).
To address the identified threats, the Messaging Code introduces enhanced requirements for online messaging platforms to implement measures to make it more difficult for unknown contacts to engage users, or to alert users to potential scam risks posed by unknown contacts. This includes the following key measures:
- Proactive detection of malicious accounts and activities, including:
- Proactively detecting and acting against suspected scams or malicious cyber activities;
- Putting in place a reporting mechanism for suspected scams or malicious cyber activities;
- Identifying trending or changing behaviour associated with scams or malicious cyber activities and updating the fraud analytics accordingly; and
- Reviewing and screening advertisements for suspicious content and regularly monitoring embedded URLs.
- Verification measures, including:
- Verification measures to prevent the creation and usage of inauthentic, bot-controlled or compromised accounts;
- Additional verification procedures on an account when there is detection of suspicious conduct or activity by the account;
- Login verification features that provide effective protection against unauthorised access;
- Requiring consent from the account holder before permitting a login from a new or unrecognised device; and
- Verification of the identities of advertisers by conducting checks against Government-issued records.
- Account and user protection measures, including:
- Requiring the end-user’s consent before the end-user can be added into a chat group or channel by an unknown contact;
- Displaying contextual warnings or risk indicators when receiving messages or calls from unknown or suspicious accounts;
- Providing end-users with the option to silence, filter, or block messages or calls originating from accounts or telephone numbers that are not present in the end-user’s contact list; and
- Implementing restrictions on user accounts where there is suspicious conduct or activity detected.
- Disabling of malicious accounts and activities, including:
- Preventing the spoofing of the Singapore Government through profile names or pictures;
- Implementing stronger enforcement measures where suspicious conduct or activity is detected in relation to a channel or moderator; and
- Disallowing the publication of advertisements offering unlicensed financial services or products.
- Reporting and accountability requirements, including:
- Informing the relevant authorities of any detected trends or modalities of scams or malicious cyber activities;
- Retaining all available data of accounts used for scams or malicious cyber activities;
- Facilitating requests for information and data from law enforcement agencies; and
- Submitting an annual report on the implementation of the systems, processes and measures to counter and prevent online scams and malicious cyber activities.
The seven designated online messaging and conferencing services will be required to implement the necessary systems, processes and measures to comply with the Messaging Code by 31 January 2027, with the exception of requirements relating to spoofing of the Singapore Government, which must be complied with by 30 September 2026, given the urgency of addressing GIOS cases.
Social Media Code
The Social Media Code applies to the same social media services previously designated under the Online Communication Code, namely: (i) Facebook; (ii) Instagram; and (iii) TikTok. These social media services pose the highest scam risks to users in Singapore, particularly from scams disseminated through the advertisements on these platforms.
In recognition of the role that social media platforms play in the publication and dissemination of advertisements, as well as the revenue they derive from such advertisements, the Social Media Code introduces enhanced advertising-related requirements aimed at preventing advertisements from being used in furtherance of criminal activity. This includes the following key measures:
- Proactive detection of malicious accounts and activities, including:
- Proactively detecting and acting against suspected scams or malicious cyber activities;
- Putting in place a reporting mechanism for suspected scams or malicious cyber activities;
- Reviewing and screening advertisements for suspicious content and regularly monitoring embedded URLs; and
- Preventing the publication of any advertisement if there is reason to suspect that the advertisement is in furtherance of a scam.
- Verification measures, including:
- Verification measures to prevent the creation and usage of inauthentic, bot-controlled or compromised accounts;
- Additional verification procedures on an account when there is detection of suspicious conduct or activity by the account;
- Login verification features that provide effective protection against unauthorised access;
- Requiring consent from the account holder before permitting a login from a new or unrecognised device; and
- Verification of the identities of advertisers by conducting checks against Government-issued records before they are permitted to publish any advertisements.
- Disabling of malicious accounts and activities, including:
- Promptly removing suspected scam advertisements that are accessible to Singapore users, including those reported by users; and
- Disallowing the publication of advertisements offering unlicensed financial services or products.
- Reporting and accountability requirements, including:
- Informing the relevant authorities of any detected trends or modalities of scams or malicious cyber activities;
- Retaining all available data of accounts used for scams or malicious cyber activities;
- Facilitating requests for information and data from law enforcement agencies; and
- Submitting an annual report on the implementation of the systems, processes and measures to counter and prevent online scams and malicious cyber activities.
The three social media services will be required to implement the appropriate systems, processes or measures to comply with the Social Media Code by 31 January 2027.
E-Commerce Code
The e-commerce platforms designated under the E-Commerce Code remain unchanged, namely: (i) Carousell, (ii) Facebook Marketplace, and (iii) Facebook Business Pages. The enhanced COP expands on the existing requirements by introducing stronger consent measures before permitting logins from new or unrecognised devices and adopts end-user protection measures against the exploitation of online advertisements by scam actors, similar to requirements under the Social Media Code. This includes the following key measures:
- Proactive detection of malicious accounts and activities, including:
- Proactively detecting and acting against suspected scams or malicious cyber activities;
- Putting in place a reporting mechanism for suspected scams or malicious cyber activities;
- Reviewing and screening advertisements for suspicious content and regularly monitoring embedded URLs; and
- Preventing the publication of any advertisement if there is reason to suspect that the advertisement is in furtherance of a scam.
- Verification measures, including:
- Verification measures to prevent the creation and usage of inauthentic, bot-controlled or compromised accounts;
- Additional verification procedures on an account when there is detection of suspicious conduct or activity by the account;
- Login verification features that provide effective protection against unauthorised access;
- Requiring consent from the account holder before permitting a login from a new or unrecognised device;
- Verification of the identities of advertisers by conducting checks against Government-issued records before they are permitted to publish any advertisements; and
- Subjecting end-users who advertise or post about the sales of goods or services to verification against Government-issued records.
- Account and user protection measures, including:
- Providing users with the option of payment protection mechanisms that require the delivery of goods or services to be verified before payment is released to sellers.
- Disabling of malicious accounts and activities, including:
- Implementing stronger enforcement measures where suspicious conduct or activity is detected in relation to a channel or moderator;
- Promptly removing suspected scam advertisements that are accessible to Singapore users, including those reported by users; and
- Disallowing the publication of advertisements offering unlicensed financial services or products.
- Reporting and accountability requirements, including:
- Informing the relevant authorities of any detected trends or modalities of scams or malicious cyber activities;
- Retaining all available data of accounts used for scams or malicious cyber activities;
- Facilitating requests for information and data from law enforcement agencies; and
- Submitting an annual report on the implementation of the systems, processes and measures to counter and prevent online scams and malicious cyber activities.
The designated e-commerce platforms will be required to implement the appropriate systems, processes or measures to comply with the E-Commerce Code by 31 January 2027.
Enforcement
The Ministry of Home Affairs has proposed legislative amendments in Parliament in August 2026 to strengthen the Online Criminal Harms Act 2023 (“OCHA“) penalty framework. Under the proposed framework, for each instance of non-compliance with a COP or Implementation Directive, the OCHA Office may:
- Issue a financial penalty not exceeding S$10 million; or
- Direct the online platform to rectify the non-compliance through a Rectification Notice (“RN“) or a Compliance Order (“CO“). Failure to comply with a RN or CO without reasonable excuse is a criminal offence, punishable with a fine not exceeding S$10 million and, in the case of a continuing offence, a further fine not exceeding S$300,000 for every day during which the offence continues after conviction.
By comparison, under the current OCHA framework, failure to comply with a RN is punishable by a fine of up to S$1 million, together with a further fine of up to S$100,000 per day for any continuing offence after conviction.
More details will be shared at the Second Reading of the Scams (Countermeasures) and Other Matters Bill in September 2026.
Key Insights
The issuance of the new and enhanced COPs reflects a continued shift towards a more service-specific and proactive approach to addressing online criminal harms, with obligations tailored to the distinct risks posed by different categories of online services. The 2026 COPs adopt a more prescriptive approach than the previous framework, setting out clearer expectations on the safeguards, reporting processes and operational measures that designated service providers must implement. While preventive measures remain the main focus, the framework also strengthens service providers’ responsibilities in responding to reports and retaining relevant information.
Together with the proposed strengthening of OCHA’s enforcement framework, these developments underscore the seriousness with which online criminal harms are regarded in Singapore and the expectation that designated online service providers play an active role in mitigating such risks.
The full list of requirements under each COP can be found at https://go.gov.sg/ocha.
If you have any queries on the above, please reach out to our team set out on this page.
For regional Technology, Media & Telecommunications matters and regional Fraud, Asset Recovery & Investigations matters, please see Rajah & Tann Asia’s Regional Technology, Media & Telecommunications Practice and Regional Fraud, Asset Recovery & Investigations Practice respectively for more information.
Disclaimer
Rajah & Tann Asia is a network of member firms with local legal practices in Cambodia, Indonesia, Lao PDR, Malaysia, Myanmar, the Philippines, Singapore, Thailand and Vietnam. Our Asian network also includes our regional office in China as well as regional desks focused on Brunei, Japan and South Asia. Member firms are independently constituted and regulated in accordance with relevant local requirements.
The contents of this publication are owned by Rajah & Tann Asia together with each of its member firms and are subject to all relevant protection (including but not limited to copyright protection) under the laws of each of the countries where the member firm operates and, through international treaties, other countries. No part of this publication may be reproduced, licensed, sold, published, transmitted, modified, adapted, publicly displayed, broadcast (including storage in any medium by electronic means whether or not transiently for any purpose save as permitted herein) without the prior written permission of Rajah & Tann Asia or its respective member firms.
Please note also that whilst the information in this publication is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as legal advice or a substitute for specific professional advice for any particular course of action as such information may not suit your specific business and operational requirements. You should seek legal advice for your specific situation. In addition, the information in this publication does not create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on the information in this publication.