Singapore is moving decisively to combat digital fraud with sweeping new legislation that will criminalise the creation and sale of online accounts used in scams. The Scams (Countermeasures) and Other Matters Bill, tabled in Parliament on Tuesday, August 4, closes a significant legal gap by targeting account mules operating across popular platforms including Carousell, TikTok, Telegram, Facebook, Instagram and WhatsApp. Until now, authorities could prosecute money mules and SIM card mule suppliers, but lacked statutory tools to address the growing problem of compromised social media and e-commerce accounts weaponised for criminal purposes.

The legislation introduces stiff criminal penalties for individuals who supply, receive, possess or provide personal information to create accounts for scams. Convicted offenders face fines up to S$10,000, imprisonment for up to three years, and caning of up to 12 strokes, making this among the harshest penalties for online fraud support in the region. This three-pronged punishment approach signals Singapore's determination to deter participation in scam ecosystems at every level, from the account creators themselves to those who knowingly purchase or use compromised accounts for criminal schemes.

The bill's enforcement framework extends beyond individual offenders to hold online service providers accountable for non-compliance with anti-scam measures. Recognising that platforms have become critical infrastructure in the fraud chain, Singapore is raising maximum penalties against non-compliant service providers from S$1 million to S$10 million, with daily penalties for continuing offences jumping from S$100,000 to S$300,000. This represents a tenfold increase in financial consequences, reflecting growing frustration with platforms' inadequate response to scam proliferation. Meta has already received two implementation directives, in September 2025 and January 2026, and police data suggests these measures have reduced impersonation scams on Facebook, validating the enforcement approach.

The scale of Singapore's scam problem underscores the urgency of legislative action. In 2025 alone, fraud constituted three in five police reports, with losses totalling S$913.1 million—a staggering figure that represents only part of the broader impact. Since 2019, scams have cost victims in excess of S$4 billion, demonstrating that this is not a temporary phenomenon but a deepening structural challenge to digital security. Particularly alarming is the explosion in government official impersonation scams, which more than doubled from 1,504 cases in 2024 to 3,363 in 2025, making it the fifth most prevalent fraud type. This subset of scams proves especially damaging as it exploits citizens' trust in official institutions.

A critical innovation in the legislation addresses the technological sophistication of modern scam operations. Police have noted that scammers now deploy artificial intelligence and automated systems to create vast networks of fraudulent sites, accounts and advertisements faster than manual review processes can identify and remove them. The new bill grants authorities the power to issue anti-scam directions via computer programmes, including AI-powered systems, that can rapidly detect and act against emerging scam infrastructure. Safeguards are embedded to ensure algorithmic fairness and accuracy, acknowledging the potential risks of automated enforcement while harnessing technology's capacity to match criminal innovation.

The legislation introduces three new police orders that fundamentally reshape how authorities and service providers combat fraud. A disclosure order compels service providers to furnish information about specified accounts and scam-related activities, enabling law enforcement to map criminal networks. An account disabling order permits authorities to temporarily shut down compromised accounts for up to 30 days, extendable for another 30 days, directly interrupting the fraud pipeline. These mechanisms feed into a National Scams List, a real-time information-sharing platform that allows the government and financial institutions, telecommunications companies and other stakeholders to synchronise their responses. This coordination infrastructure represents a paradigm shift from siloed institutional responses to integrated ecosystem-wide defence.

The potential of real-time information-sharing to disrupt scam economics cannot be overstated for regional observers. When banks receive simultaneous alerts about which accounts are receiving scam proceeds, they can freeze transfers before criminal networks access the funds. Telecommunications companies alerted to phone lines used in scams can suspend services. This collective intelligence, as Minister of State for Home Affairs Goh Pei Ming outlined during parliamentary budget discussions in February, will incorporate culprits' identities, bank accounts, phone numbers and online accounts—effectively creating a scam offender database with immediate enforcement implications. For Malaysia and other Southeast Asian nations facing similar fraud epidemics, Singapore's approach offers a blueprint for institutional coordination.

Complementing information-sharing mechanisms, the bill introduces a service limitation order that allows police to restrict service access for individuals identified in scam ecosystems. These restrictions span financial services, telecommunications and Singpass access, and can persist for up to three years. This represents a significant expansion of the facility restriction framework that has operated since October 2025, when authorities placed 1,423 money mules, 1,439 SIM card mules and 53 corporate mules under restrictions as of June 30. Previously, compliance with these restrictions relied largely on voluntary cooperation or sector-specific levers; the new bill formalises enforcement and extends its reach. For ordinary citizens, this means one's financial services and telecommunications access could be suspended for years based on involvement in scam operations, creating powerful incentives for distance from fraudulent schemes.

The legislation also reflects evolving understandings of scam syndicates' operational architecture. By targeting not just the masterminds but the support ecosystems—account providers, SIM suppliers, money mule networks—Singapore acknowledges that modern scams function as distributed criminal enterprises dependent on compartmentalised participation. Many participants may not fully understand their role in larger schemes, making legal clarity about liability essential. The bill's comprehensive approach addresses recruitment pathways, ensuring that anyone knowingly providing accounts, money laundering services or identity information for scams faces prosecution, not merely individuals directly perpetrating fraud. This ecosystem approach recognises that disrupting the supply chains of scam infrastructure is more efficient than pursuing individual perpetrators downstream.

For Malaysia and the broader Southeast Asian region, Singapore's legislative response carries significant implications. Transnational scam operations frequently route stolen funds across multiple jurisdictions, with criminals exploiting gaps between legal regimes. As Singapore implements tougher penalties and enforcement mechanisms, criminals may attempt to shift operations to neighbouring jurisdictions with less robust frameworks. Malaysian policymakers should take note of the specific mechanisms—automated detection systems, real-time information-sharing platforms, and service limitation orders—as models for addressing what has become a regional crisis. The bill also signals that the era of expecting tech platforms to self-regulate has ended; governments now view non-compliance with anti-scam measures as grounds for heavy financial penalties and operational restrictions. This forceful stance may pressure platforms operating across Asia to implement more stringent measures uniformly, potentially benefiting all users in the region.