CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
privacy

Deepfake Scams Cost Singapore S$242.9M as Deepfake Fraud Risk Grows

deepfake scam warning signs on phone screen showing verified government call prefix, close-up of incoming call display
A phone screen shows an incoming call as Singapore pilots a common prefix to fight deepfake scam impersonation of government officials. Illustration: CaraComp

A retiree in Singapore joined a Zoom call last year and watched the Prime Minister explain why she needed to transfer S$4.9 million immediately. The Prime Minister on that call was not real. It was a deepfake (a fake video or audio clip made by AI that copies someone's face and voice), and by the time anyone figured that out, the money was gone.

A deepfake scam wave that cost Singapore residents S$242.9 million is pushing the government to try something almost too simple to believe: giving every real government phone call the same recognizable prefix (the first few digits of the number), so a fake one might finally stick out.

TL;DR

Deepfake scam cases impersonating Singapore government officials more than doubled in a year, so police are piloting one shared prefix for every legit government call, starting later in 2026.

Here's the number that should scare you more than any AI headline this year: government-official impersonation scams in Singapore jumped from 1,504 cases in 2024 to 3,363 in 2025, according to AsiaOne. That's not a rounding error. That's a doubling, in twelve months, in a country that already runs some of the tightest digital ID systems on earth. Much of this rise is tied to synthetic media, the broader category of AI-generated voice and video that deepfakes belong to, and the risk it creates for both individuals and employees at organizations that handle money transfers. These scams increasingly overlap with phishing, since many impersonation attempts still start with a suspicious email or text before the call ever happens. If Singapore can't out-tech this problem, nobody's out-teching it either.

So the Singapore Police Force is trying something that sounds almost quaint. Instead of building a fancier detector, they're giving every government phone call the same visible fingerprint: a shared prefix (a set first few digits) that will appear on your screen before a government caller says a word. The pilot starts later in 2026, according to Fintech News Singapore, and if it works, it rolls out across more agencies from there, lowering the risk that the next scam deepfake catches someone off guard.

S$242.9M
lost to impersonation scams in Singapore, per The Online Citizen's reporting on the case that triggered the pilot
Source: The Online Citizen

Why a deepfake attack, deepfake phishing call and video scam risk are so hard to spot

A deepfake scam used to require real skill. Now it takes almost none. Voice cloning tools can copy a person's voice using as little as 30 seconds of audio, according to research cited by ThreatLocker, and some tools reach 85% match accuracy (how closely a fake matches the real thing) with just three seconds, according to data compiled by SQ Magazine. Three seconds. That's shorter than the time it takes to say "hello, this is." Awareness training for employees at banks and government agencies increasingly covers exactly this window of vulnerability, and phishing-specific training is now often bundled into the same sessions.

Once a scammer has a cloned voice, the conversion rate is brutal. Research aggregated by StationX puts the victim conversion rate for voice cloning scams at 77%. Meaning: if a scammer gets a real person on the phone with a convincing cloned ai voice, more than three out of four times, it works. Not "might work." Works. Phishing calls that pair a spoofed number with an ai voice sample are quickly becoming the default playbook, not the exception. This article is part of a series, start with Social Media Identity Verification Macron Eyes Id Scanning.

What makes a deepfake phishing call convincing, and where scam deepfake risk hides

It's not the voice alone. It's the whole package: a caller ID that looks legitimate, an urgent story (frozen bank account, warrant for your arrest, unpaid tax bill), and an ai voice that sounds exactly like the official you'd expect to hear. Add a fake video call with a deepfaked official, like the one that fooled the Singapore victim into a S$4.9 million transfer, and you've got a video scam that beats human instinct almost every time. Phishing texts and emails often set up the call in advance, priming the target before the deepfake voice ever comes on the line.


How does Singapore government calls verification actually work against phishing and scams?

Here's the mechanic, stripped down. Right now, when a government agency calls you in Singapore, the number on your screen could be almost anything, a mobile number, a spoofed landline, whatever a scammer wants it to look like. Under the pilot, every genuine government call will start with the same prefix. See a government-sounding call without that prefix, and you have your answer before the person on the other end says a word. This is basic security hygiene, and it costs nothing to practice, whether the threat arrives as a phone scam, a phishing email, or a mix of both.

It's not encryption. It's not some clever cryptographic (math-based security) trick. It's a shared, memorable pattern, the kind of thing a tired person can actually use at 11pm without googling anything. That's the whole point, and it's the kind of security layer that scales without needing every citizen to become a fraud expert or a phishing analyst.

Scam prevention requires a multi-layered approach involving government agencies, banks, online platforms and the public.

Singapore government messaging, as reported by OpenGov Asia

That "multi-layered" line matters more than it sounds like it should. A prefix on its own can't stop a scammer who's already broken into a real government phone line, and it does nothing for the scammer who skips phone calls entirely and goes straight to a deepfake video call, like the Zoom impersonation of the Prime Minister. Singapore's own officials know this. The prefix is one layer of a taller stack, sitting next to bank fraud checks, platform-level identity checks, ongoing training for frontline staff, phishing awareness training for the public, and, frankly, whether regular people actually know the prefix exists. Better security awareness across the population is the real long-term defense against deepfake fraud, phishing and the wider family of deepfake scams now circulating.

Deepfake schemes, deepfake scams and warning signs beyond the phone

Video is where a deepfake scam usually falls apart, if you know where to look. Guidance from Singapore's Cyber Security Agency, cited by OpenGov Asia, points to lip movements that don't quite line up with the words being said, and facial features that look slightly off, distorted, or too smooth. Skin that appears too smooth is a real tell in these deepfake scams. So is a face that never quite blinks right, or lighting that doesn't match the rest of the room. None of this is foolproof. All of it takes a few extra seconds most panicked people don't have. Many of these same deepfake scams are paired with a phishing message sent beforehand to lower a victim's guard. Previously in this series: Biometric Research Ireland Probes X Facial Age Data Podcast.

Why deepfake scam prevention and phishing training matter right now

  • Cases doubled in a yearimpersonation scams went from 1,504 to 3,363 cases in twelve months, per AsiaOne's reporting
  • 📊 Voice cloning needs almost nothingsome tools clone a convincing voice from three seconds of audio, per SQ Magazine's data
  • 🔮 Detection is losing groundscam sophistication is projected to push detection evasion rates up more than 30%, according to research cited by StationX
  • 🎯 Low-tech beats no-techa shared call prefix creates one clear, checkable signal instead of asking victims to spot AI fakery, phishing attempts, or deepfakes in real time
Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The deepfake threat, phishing risk and one thing you can check before you trust a call

If you've ever gotten a call that sounded official and felt your stomach drop, that's exactly the moment this whole idea exists for. You shouldn't have to become an audio forensics expert to know whether the "government officer" on the line is real. Here's the one useful habit worth building now, before any prefix system exists where you live: hang up, and call the agency back using a number you looked up yourself, not one the caller gave you. That single step defeats almost every version of this scam, prefix or no prefix, and it works against phishing attempts made over email or text too. Basic risk awareness training built around this one habit does more for most households than any single piece of software.

Old approach to a suspicious callWhat a common prefix pilot changesStatus
Judge legitimacy by voice and urgency aloneCheck for a known, verified prefix before trusting anything saidAddressed by pilot
Caller ID can be spoofed to look officialPrefix is standardized across agencies, harder to casually fakeAddressed by pilot
Victim must spot deepfake voice cloning in real time, a high risk task for most peopleVictim only needs to glance at a number patternReduces risk
Deepfake video calls (like the S$4.9 million case) bypass phone checks entirelyPrefix does nothing for video-based impersonation, layered defenses and training still requiredUnresolved risk
Rollout stage in 2025Pilot phase, single agency, limited public awarenessComplete
Rollout stage in 2026Expanded pilot, additional agencies, wider social awareness and training campaignsIn progress

Where deepfake fraud, deepfake scams and phishing defenses go from here

Look, nobody's saying a prefix solves this. Attackers adapt fast, and a scammer sophisticated enough to run a deepfake Zoom call with a fake Prime Minister isn't going to trip over a missing three-digit prefix for long. Some will simply stop using phone calls altogether and lean harder into video and phishing messages, since that's where the S$4.9 million loss actually happened. Detection tools, meanwhile, are losing the arms race in real time; evasion rates tied to more sophisticated scams are expected to climb over 30%, per the research StationX has compiled. Social platforms are also part of the picture, since many deepfakes first surface and spread through social feeds before ever reaching a phone call, often carried by the same phishing links that show up in email inboxes.

But here's the case for doing it anyway. Most deepfake scam attempts aren't run by patient, well-funded operations building custom Zoom deepfakes. Most are volume plays, hundreds of calls a day, hoping a fraction land. A prefix raises the cost of that volume game. It doesn't need to stop the sophisticated 1%. It needs to stop the other 99% who are just dialing numbers and hoping panic does the work for them. That's a genuinely reasonable bet, even if it's not a complete one, and it reduces overall risk even where phishing and deepfake scams keep evolving.

Singapore government calls prefix pilot timeline and training rollout

The pilot is expected to launch later in 2026 under the Singapore Police Force, expanding to additional government agencies if it proves useful, according to reporting from Fintech News Singapore and The Online Citizen. Nothing about it is retroactive protection for the S$242.9 million already lost. It's a bet on the next wave, and on giving employees and everyday residents alike one simple, checkable habit, backed by ongoing training in how to spot phishing and deepfake scams before money moves.

Key Takeaway

A deepfake scam thrives on split-second trust, and Singapore's answer isn't a smarter algorithm, it's a dumber, more checkable habit: know the prefix, or hang up and call back yourself.

The uncomfortable truth sitting underneath all of this: authority bias, the instinct to trust a voice or a face that sounds official, is exactly what deepfake technology was built to exploit. A prefix doesn't kill that instinct. It just gives you one honest question to ask before the instinct takes over: does this number even start with the right digits? If it doesn't, you already have your answer. If it does, you still shouldn't stop asking questions, because a scammer who's willing to fake the Prime Minister's face on a Zoom call is willing to fake three more digits eventually too. Up next: Social Media Identity Verification Macron Eyes Id Scanning P.

deepfake scam: Frequently Asked Questions

What is a deepfake scam and how does it target government calls?

A deepfake scam uses AI to fake someone's voice or face, usually to impersonate a trusted figure like a police officer or government official. In Singapore, scammers have used cloned voices and even a deepfake video scam, including a fabricated Zoom call featuring a fake Prime Minister, to convince victims to transfer money. Government-official impersonation cases in Singapore doubled from 1,504 in 2024 to 3,363 in 2025, a clear sign that deepfake fraud risk, alongside ordinary phishing risk, is rising fast for both individuals and employees handling sensitive transfers.

How can I tell if a video call is a deepfake attack?

Watch for lip movements that don't sync naturally with the words being spoken, distorted or oddly smooth facial features, and lighting that doesn't match the room. Skin that appears too smooth is one common giveaway cybersecurity guidance points to, alongside faces that look slightly warped when the person turns or blinks. None of these signs are guaranteed, but spotting even one is reason enough to pause and verify independently before acting, especially on social video calls where scammers hope you will not look closely, and where phishing links often follow if you engage.

Will the singapore government calls prefix system stop all scam calls?

No. It's designed to raise the cost of the most common, high-volume scam attempts, not to stop every sophisticated attacker. A scammer running an elaborate deepfake video operation, like the one behind the S$4.9 million loss, can simply avoid using a phone number altogether and lean on phishing messages instead. Officials have described this as one security layer in a multi-layered approach that also includes bank fraud checks, employee training, and platform-level verification.

How much has voice cloning made deepfake scams easier to pull off?

Dramatically easier. Some voice cloning tools now need only three seconds of audio to reach 85% match accuracy, and cloned voices carry a reported 77% victim conversion rate once a scammer gets someone on the phone. What once required real technical skill and time is now available to almost anyone with a laptop, which is exactly why simple, checkable signals like a shared call prefix, backed by better security, phishing awareness and regular training, are getting serious attention.

What should I do if I get a call claiming to be from a government agency?

Don't act on anything said during the call, no matter how urgent it sounds or how official the voice seems. Hang up, find the agency's real number yourself through an official website, and call that number directly. This defeats spoofed caller ID, cloned voices, phishing tricks, and fake urgency all at once, and it works whether or not your country has adopted a common prefix system like Singapore's pilot, cutting overall risk regardless of which scam or deepfake variant you face.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search