In this article

Kooky
Builder of Shaka, the payment router that pays every agent their commission on closing date.
About Kooky and Shaka →A property transaction concentrates the things a fraud control is meant to protect: large sums, identity documents, tight deadlines and several parties who have never met. A property agency in Singapore that wants to know how exposed its clients and its own accounts are has two official places to start. The Singapore Police Force publishes a scam and cybercrime brief twice a year, and the Council for Estate Agencies (CEA), the trade's regulator, publishes its enforcement figures and a practice circular on the written procedures every estate agent must keep.
This guide reads those documents side by side, as they stood in October 2026. It sets out what the two latest police briefs count and what they leave out, which of their categories can reach a sale or a tenancy, what CEA's own figures show, which safeguards now sit around a bank transfer, and how an agency can turn the regulator's procedural requirements into checks that leave evidence. It is written in the language of audit: what to check, what to keep and what to report. It does not cover the tenant's side of a rental listing, and it describes general rules, not what a particular agency should do in a particular case.
Singapore Police Force, Mid-Year Scam and Cybercrime Brief 2026, published 26 August 2026; Council for Estate Agencies, Practice Circular PC 02-17 of 10 October 2017.
Two briefs a year, and what they are
The Singapore Police Force issues an annual brief early in the year and a mid-year brief in the third quarter. The two editions read for this guide are the Annual Scam and Cybercrime Brief 2025, dated 25 February 2026, and the Mid-Year Scam and Cybercrime Brief 2026, dated 26 August 2026 and covering January to June 2026. The mid-year edition was issued by the force's Public Affairs Department.
Related readMortgage fraud in the United States: red flags and where to reportEach brief gives a total for scams and cybercrime together, a separate total for scams, the amount reported lost, and an annex ranking the ten scam types with the most cases. The briefs count reported cases. They are organised by the method used on the victim, not by the industry in which the money was moving, and this matters for anyone reading them from inside the property trade: there is no line for housing, real estate, landlords or property agents in either edition. The words do not appear. What a property agency can take from the briefs is therefore the size and direction of each method, and a view of which methods could meet a deal on its way to completion.
What the 2025 annual brief counted
According to the annual brief, scam and cybercrime cases in Singapore numbered 41,974 in 2025, down 24.8 per cent from 55,810 in 2024. Scams alone accounted for 37,308 cases, down 27.6 per cent from 51,501. The amount lost was about S$913.1 million, against about S$1,112.4 million the year before, a fall of 17.9 per cent.
The brief describes a distribution with a long tail. About 67.1 per cent of scam cases involved a loss under S$5,000, and the median loss per case was S$1,644. The total is carried by a small number of very large cases in a few categories. Investment scams accounted for S$336.2 million across 5,462 cases, and scams impersonating government officials for S$242.9 million across 3,363 cases. Added together for this guide, those two categories come to S$579.1 million, or 63.4 per cent of the year's reported losses.
Related readUSA: NAR warns AI voice cloning can defeat phone checks at closingTwo movements in the annual figures stand out. Phishing fell: 6,264 cases against 8,552, and S$39.9 million lost against S$59.4 million, which the brief gives as declines of 26.8 per cent and 32.8 per cent. Impersonation of government officials went the other way. Cases more than doubled, from 1,504 to 3,363, and losses rose 60.5 per cent from S$151.3 million. The annual brief also records that 81.8 per cent of reported scams in 2025 involved self-effected transfers, meaning the victim made the payment.
The first half of 2026
The mid-year brief shows the decline continuing. From January to June 2026 the police recorded 18,391 scam and cybercrime cases, down 17.9 per cent from 22,397 in the first half of 2025. Scam cases numbered 16,821, down 14.4 per cent from 19,644, and made up 91.5 per cent of the combined total. The amount lost was about S$410.6 million, down 17.9 per cent from about S$500.2 million.
The shape of the losses is the same as in the annual brief. The mid-year edition says 69.5 per cent of cases involved less than S$5,000, made up of 56.9 per cent under S$2,000 and 12.6 per cent between S$2,000 and S$5,000. The median loss fell to S$1,350 from S$1,682. Cases of S$100,000 or more were 4.7 per cent of the total, and the brief says their number fell 24.5 per cent. Self-effected transfers stood at 80.8 per cent of reported scams, up from 78.8 per cent a year earlier.
The brief's annex of the ten most frequent scam types accounts for 15,010 cases and S$330.3 million. Calculated for this guide, that is 89.2 per cent of scam cases and 80.4 per cent of the amount lost. Three rows of that annex that matter most to a property deal are shown below, with a fourth category, business email compromise, which the brief reports outside the top ten by number of cases.
Related readSeller impersonation on US vacant land: warning signs and checks| Category | Cases | Amount lost | Why an agency would log it |
|---|---|---|---|
| Investment | 2,256 (2,692) | S$169.8m (S$178.9m) | Offers presented to clients as returns on an asset. |
| Government officials impersonation | 1,363 (1,772) | S$90.8m (S$132.9m) | Clients with sale proceeds or a deposit in hand. |
| Business email compromise | 262 (156) | S$57.3m (S$19.5m) | Changed bank details on an invoice or instruction. |
| Phishing | 3,104 (3,772) | S$9.6m (S$30.0m) | Messages posing as an agency, bank or public body. |
Singapore Police Force, Mid-Year Scam and Cybercrime Brief 2026. The last column is this guide's reading, not the brief's.
Four categories that can meet a transaction
None of the four categories in the table is defined by property. Each is described here only as far as the briefs describe it, and only to show what an agency's records would need to capture.
Phishing, in the mid-year brief's description, involves emails, texts or calls that pose as government officials, financial institutions or businesses and lead a person to give up banking credentials or card details, often through a link. A property agency is a business whose name, logo and staff names are public, so the audit question is whether the agency has a record of every channel it uses to write to clients, and whether clients have been told which channels those are.
Impersonation of government officials is the category with the second-largest losses in the mid-year brief. The annual brief lists the Singapore Police Force, the Immigration and Checkpoints Authority and the Monetary Authority of Singapore among the bodies whose officers were impersonated; the mid-year brief adds the Ministry of Law. Neither brief, as read for this guide, names a housing or property body. The mid-year brief describes requests to move money to a so-called safety account, to deposit cash or to hand over valuables for investigation purposes, mostly by phone call and WhatsApp. CEA's guidance, last updated on 25 June 2026, states the rule against which any such request can be tested: government officials will never ask a person to transfer money, to disclose bank log-in details, to install mobile apps from unofficial app stores, or to have a call transferred to the police.
Related readAustralia: AUSTRAC issues first notices to non-enrolled businessesInvestment scams are the largest category by amount lost in both editions, on the figures above. The mid-year brief puts the average loss at S$75,267 a case and lists the routes by which victims were reached: online acquaintances, internet searches, online advertisements, unsolicited messages or calls, and invitations to investment chat groups. It does not mention property or real estate, and this guide does not claim a figure for property-themed offers. The ScamShield website, in a page last updated on 22 May 2026, does name property alongside investment and job information as something to verify with official sources and trusted registers before acting.
Business email compromise is the one that speaks most directly to an agency's own finance function. The mid-year brief describes it as the impersonation of suppliers, vendors, clients or internal staff through spoofed or compromised email accounts. It reports 262 cases in the first half of 2026, up 67.9 per cent from 156, and losses of S$57.3 million, up 193.1 per cent from S$19.5 million, which it ranks fifth by amount lost. Dividing the two figures, as a calculation for this guide, gives about S$219,000 a case.
The police ask businesses to verify any sudden change of bank details
The Mid-Year Scam and Cybercrime Brief 2026 advises businesses to train the staff who make fund transfers to verify sudden payment instructions or changed bank details. An agency that pays commission to its salespersons and receives it from clients and developers handles both kinds of message.
Where rental and agent-impersonation cases sit
Rental scams, the category most closely tied to the property trade, are not in the top ten of either brief and are not mentioned in either document. That is a statement about what the briefs print, not about absence. Neither brief gives a figure for that method; CEA's page on rental scams points readers to the Singapore Police Force for its latest advisories.
Related readAustralia: payment redirection scams in property settlements, explainedCEA's page describes the regulator's own role in such a case. In one example it publishes, a member of the public alerted CEA to a listing, the regulator looked into it and told her to stop communicating with the person behind it. The page states that changes to an agent's phone number are reflected on the CEA Public Register immediately, and that CEA does not send emails saying a new number will take 14 days to appear. It gives no count of impersonation reports received, and it sets out no step-by-step procedure for a salesperson whose identity has been misused. An agency that wants one has to write its own.
What CEA's enforcement figures show
CEA publishes a table of enforcement actions by calendar year. The page, last updated on 14 July 2026, gives 2023 and 2024.
Council for Estate Agencies, enforcement statistics, page last updated 14 July 2026. Total for 2024: 331 actions.
The 2023 column is almost identical: 267 letters of advice or warning, 36 letters of censure, 17 disciplinary committee actions and 8 court prosecutions, a total of 328. In both years, court prosecution was the rarest outcome, at 8 of 331 actions in 2024, or 2.4 per cent by this guide's calculation.
The table has a limit that an honest reading must state. It counts actions by type, not by offence. It does not say how many of the eight prosecutions in either year concerned people doing estate agency work without registration, and no CEA page read for this guide gives a yearly count of unregistered-agent cases. What CEA's page on court prosecution does give, in the version last updated on 18 March 2026, is the offences and their ceilings under Singapore's Estate Agents Act 2010. Acting as an estate agent without a licence, under section 28(2), carries a fine of up to S$75,000, imprisonment of up to three years, or both, and a further fine of up to S$7,500 for each day a continuing offence goes on after conviction. Acting as a salesperson without registration, under section 29(3), carries a fine of up to S$25,000, imprisonment of up to 12 months, or both. The same page lists the employing of unregistered salespersons as an offence under section 39(2).
Related readRental scams in Australia: official warnings, figures and checksBelow the courts, the enforcement statistics page gives the ceilings for the regulator's own sanctions: a letter of censure may come with a financial penalty of up to S$5,000, and a disciplinary committee may impose up to S$100,000 a case on a salesperson and up to S$200,000 a case on an estate agent.
The safeguards around a transfer
A property payment passes through a bank, and the police briefs record the controls that have been added on that side. They are described here as the briefs describe them.
The first is Money Lock, which the mid-year brief presents as a means of limiting potential losses if a customer's digital banking access is compromised. As at 30 June 2026, about 589,000 customers had locked close to S$49 billion of savings, according to that brief; the annual brief gave at least 479,000 customers and close to S$44 billion as at 31 December 2025.
The second is delay. The mid-year brief says major retail banks have introduced additional cooling periods for high-risk activities, giving the examples of raising a transaction limit and changing contact details, so that a potential victim has an opportunity to reassess. It also says enhanced fraud surveillance rules have applied since October 2025 to block or hold transactions that drain large sums from accounts with significant balances. The brief gives no duration for the cooling periods and no threshold for the block or hold.
The third is the Protection from Scams Act, which both briefs say was operationalised on 1 July 2025. Under it the police issue Restriction Orders to banks, restricting the banking facilities of victims who, in the mid-year brief's words, remained deeply entrenched despite police engagement. Twelve orders had been issued as at 1 February 2026 and 18 as at 30 June 2026.
Related readStalled or cancelled off-plan project in Dubai: what protects buyersAround these sit the public tools. The mid-year brief counts 1.61 million downloads of the ScamShield app, 2.88 million checks and 1.04 million reports by users, against 1.53 million, 2.11 million and 832,000 in the annual brief. The ScamShield Helpline had taken more than 310,000 calls since its launch, around 500 a day, and about 84 per cent of them were enquiries to check whether something was a scam. The mid-year brief also says all government agencies send text messages through a single government sender ID, that 360 million messages have gone out through it and that no scam message has been sent from it. For members of the Central Provident Fund aged 55 and above, both briefs describe a CPF Safety Switch that disables online access and stops withdrawals. For a transaction timetable the point is narrow: the briefs do not say how long a cooling period or a hold lasts, so the briefs give no basis for assuming how quickly a large transfer will clear.
The written procedures CEA already requires
The checks an agency can audit do not have to be invented. Paragraph 4(1) of the Code of Practice for Estate Agents, in the Second Schedule to Singapore's Estate Agents (Estate Agency Work) Regulations 2010, requires an estate agent to have proper systems and processes, documented in writing, for managing its business and supervising its salespersons. CEA's Practice Circular PC 02-17, issued on 10 October 2017 and effective from 1 May 2018, lists the areas those standard operating procedures must cover. The circular says CEA will inspect for compliance from that date.
Related readDubai property fraud: official checks, Ejari and where to complainFive areas fall under the management of the business and its salespersons: the dissemination of information, including CEA circulars, laws and internal policies; the handling, processing and retention of transaction documents; the registration, resignation and termination of salespersons; the vetting of publicity and advertising materials; and the contactability of the Key Executive Officer. Two more stand alone: claims and complaints, and the estate agent card.
Several of these read as fraud controls once the police figures are in mind. The transaction documents procedure covers agreements, receipts for transaction money, powers of attorney, conflict declarations and customer due diligence documents. The advertising procedure requires a check that material is not inaccurate, false or misleading and that the owner's consent has been obtained, with approval or rejection given in writing. The card procedure covers issuing a card at registration, recovering it when a salesperson leaves and keeping records of every card issued, and the circular states its purpose in terms: to prevent estate agency work by unregistered individuals. The departure procedures carry deadlines, with the removal application and resignation letter, or the termination report and letter, uploaded to CEA within seven days.
Across most of the procedures, the circular sets the same retention period: records are kept for at least five years.
Turning procedures into audit checks
An audit-style check has three parts: the control, the source that requires or suggests it, and the evidence that it was performed. The table sets five of them out from the documents read for this guide.
| Control | Source | Evidence on file |
|---|---|---|
| Advertisement vetted before release | PC 02-17, advertising procedure | Written approval or rejection, and the owner's consent. |
| Card recovered on departure | PC 02-17, card procedure | Card register entry and the upload to CEA within 7 days. |
| Transaction documents retained | PC 02-17, documents procedure | Receipts, authorities and due diligence papers, kept 5 years. |
| Changed bank details verified | Police mid-year brief 2026 | A note of who verified the instruction, and how. |
| Complaint investigated on time | PC 02-17, complaints procedure | Complaint register with dates of each stage. |
Council for Estate Agencies, Practice Circular PC 02-17; Singapore Police Force, Mid-Year Scam and Cybercrime Brief 2026. The fourth row is advice to businesses in general, not a CEA requirement.
A sample test is the usual method. An auditor draws a number of files from a period and asks, for each, whether the evidence exists. For advertisements, the question is whether a written approval is on file for each listing in the sample and whether the owner's consent is with it. For departures, it is whether each card issued to a salesperson who left in the period is recorded as recovered. Each test establishes that the agency can show, from its own records, which listings and which cards are genuinely its own, and that is the information the agency will be asked for when a member of the public reports a listing in its name.
Related readTitle fraud in New South Wales: how the Torrens Assurance Fund worksThe dates can be tested in the same way. Take a worked example with assumed dates. A salesperson resigns on 1 September 2026; under the circular, the removal application and resignation letter are uploaded by 8 September 2026, seven days later, and the test is whether the upload is dated on or before that day. A complaint is registered on the same 1 September; the circular, citing paragraph 6 of the Code of Practice, gives two weeks for the investigation, which runs to 15 September 2026. If CEA asks for a report on that complaint on 16 September, the report is due within two weeks of the request, by 30 September 2026, unless CEA allows longer. The papers for all of it are kept for at least five years, which for a file closed on 30 September 2026 means until at least 30 September 2031.
The fourth row of the table is different in kind, since no CEA document read for this guide prescribes it. It rests on the police advice to businesses, and the evidence it produces is modest: a record, for each change of payee details, of who checked it and by what means. Whether to add it, and how, is for each agency to decide.
Recording and reporting a suspected case
The sources name the places a suspicion can be taken. The mid-year brief advises calling the ScamShield Helpline or using the ScamShield app when in doubt, and CEA's rental scams page gives the same helpline together with the ScamShield website and the police advisories. The ScamShield website carries a link for reporting a scam and a page of steps for a person who believes they have been scammed.
Related readWhy Singapore property agents ask for your ID and source of fundsInside the agency, the complaints procedure under PC 02-17 gives the structure for the record: register the matter, investigate, meet the complainant where needed, determine the outcome and inform the complainant, with a report to CEA on request. A report from a stranger that a listing carries the agency's name is not a complaint about the agency's service, and the circular does not say such a report must go through the complaints procedure. Using the same register for it is one way to make sure the dates and the people involved are written down, and the circular's five-year retention then applies to what is recorded.
The briefs also show why a prompt report has value. The mid-year brief says the Anti-Scam Centre recovered more than S$97.7 million in the first half of 2026, of which over S$89.7 million was in ordinary currency and over S$8 million in cryptocurrency, and that at least S$127.1 million of potential losses was prevented. For 2025 as a whole, the annual brief gave about S$140.5 million recovered and at least S$348 million averted.
The briefs measure methods, and the regulator measures conduct. An agency's own records are the only place where the two meet.
What the sources leave open
Several points an agency might want are not in the documents read for this guide in October 2026, and they are listed so that no reader takes silence for an answer.
Neither police brief gives a figure for scams involving property, housing or property agents, and neither names a housing body among the public agencies impersonated. CEA's enforcement table does not separate unregistered estate agency work from other matters and stops at 2024. No CEA practice circular in the regulator's published list is addressed to impersonation or to scams as such; the closest instrument is PC 02-17, which predates the current figures by several years. The briefs confirm cooling periods and the blocking or holding of large transfers by banks but give no hours, amounts or percentages, and they do not describe a bank-side emergency switch for customers; the page of the Association of Banks in Singapore consulted for this guide carried no detail on these measures. The duration of a Restriction Order is not stated in either brief.