iMessage courier scam losses climb to S$2.2 million as scammers widen their targets
SINGAPORE: Losses from Apple iMessage scams impersonating courier companies have risen to approximately S$2.2 million as the Cyber Command has detected and disrupted more than 30,000 Apple iMessage accounts linked to the ongoing scam campaign since June 2026.
This is an update to a story previously reported by The Independent Singapore, when the Police first issued an advisory on Aug 5 about the iMessage courier scam variant with losses then standing at S$1.2 million across 251 cases.
The surge comes as scammers have expanded their impersonation targets beyond courier companies like NinjaVan, J&T Express, and SPX Express to include government agencies and financial institutions, broadening the pool of potential victims.
How the scam works
The mechanics of the scam remain consistent with the earlier advisory. Victims receive iMessages from foreign numbers, bearing country codes including +212 (Morocco), +63 (Philippines), and +44 (United Kingdom), or from email addresses made up of random alphanumeric strings.
Messages direct recipients to click links closely resembling those of legitimate couriers, government agencies, or financial institutions.
In some cases, recipients are instructed to reply “Y” or “1” to activate the embedded link. This move exploits Apple iMessage’s built-in protection, which prevents links in messages from unknown senders from being clickable until the recipient interacts with the sender. Once the recipient responds, the link becomes active.
Clicking through leads to spoofed websites where victims are prompted to enter card details, internet banking credentials, or OTPs, supposedly to pay a small redelivery fee or fine. In several cases, victims’ credit cards were subsequently added to Google Pay or Apple Pay, or their bank digital tokens were provisioned to unfamiliar devices.
Unauthorised logins to bank accounts from unknown devices have also been reported.
Why iMessage is a particular vulnerability
The Police noted a critical gap in iMessage’s structure: unlike SMS, which is protected through network-level anti-scam filters and the Singapore SMS Sender ID registry, iMessage operates on Apple’s separate ecosystem and is not covered by these protections. This makes it a preferred channel for scammers looking to bypass Singapore’s existing anti-scam infrastructure.
Government agencies and courier companies do not use iMessage to communicate with the public.
What to do now
iPhone users should immediately verify that “Filter Unknown Senders” and “Filter Spam” are enabled in their iMessage settings, and report suspicious messages using the in-app reporting function.
Newsletter
Get updates straight to your inbox
The Police’s ACT framework applies:
A-dd the ScamShield app, enable Two-Factor Authentication, set transaction limits, and activate the Money Lock feature for bank accounts.
C-heck the authenticity of any delivery or payment notification through official websites rather than clicking links in unsolicited messages, even if you are expecting a parcel.
T-ell family, friends, and authorities about scam attempts, and report fraudulent transactions to your bank immediately.
For more information, visit www.scamshield.gov.sg or call the ScamShield Helpline at 1799. To report scam-related information, call the Police Hotline at 1800-255-0000 or submit at www.police.gov.sg/i-witness. For urgent assistance, dial 999.
Read also: Singapore introduces tougher anti-scam rules for online platforms, with fines of up to S$10 million