Centre For Cybersecurity Institute Centre For Cybersecurity Institute
Menu
cybersecurity

Scam Mule Recruitment: What Singapore Employers Must Know

Staff in Singapore are being offered S$10 to S$20 to hand over SIM cards, bank accounts and Singpass logins. What the law says, and what to brief your team.

By James Lim, CEO and Academic Director · Published 26 August 2026 · Updated 26 August 2026 · 8 min read

Scam mule recruitment is the paid recruitment of ordinary people to lend their identity to a criminal syndicate: a SIM card, a bank account, a Singpass login. Your employees are inside the recruitment pool. It is not phishing, because nobody is deceived, and that difference is why it so rarely appears in an awareness programme at all.

Singapore organisations have trained hard on the deception side of scams. The recruitment side, where a staff member is offered a small sum of cash for a piece of their identity, is rarely mentioned in an induction pack. This article covers what is being asked for, what Singapore law actually says, and what a briefing should contain.

If you would rather work through it with someone, CFCI runs cybersecurity awareness training for Singapore organisations built for non-technical teams. No obligation, and the rest of this article is useful whether or not you ever speak to us.

What Is Scam Mule Recruitment, and Why Does It Reach Employees?

Scam mule recruitment is the sourcing of ordinary account holders and subscribers to supply the infrastructure a scam needs: local phone numbers to reach victims, bank accounts to receive money, and digital identities to open more of both. The Singapore Police Force applies the term “scam mule” to people who facilitate scams by giving away bank and payment accounts, SIM cards and Singpass, or by helping to collect and transfer money, gold and valuables.

It reaches employees because it is advertised as a small, harmless favour with cash attached. Between 4 and 21 August 2026, officers from the Cyber Command and the seven Police Land Divisions ran an island-wide operation against subscribers who had registered postpaid SIM cards later linked to crime. Twenty people were arrested and 42 more are assisting with investigations. Each had reportedly handed between 10 and 33 registered SIM cards to a syndicate courier. The police release states that “preliminary investigations revealed these errant subscribers were offered cash rewards between $10 and $20 per registered SIM card”.

Two details in that release matter more to an employer than the arrest count. The people under investigation are aged 16 to 75, so this is not a young-person problem you can brief at graduate intake and forget. And this was the third island-wide operation of its kind in 2026, after ones announced in January and May. The May release quotes exactly the same reward range of between $10 and $20 a card. Four months of enforcement later, the price of a piece of somebody’s identity has not moved.

What is asked forWhat it pays the person handing it overThe offence and its maximum penalty
A postpaid SIM card registered in your nameS$10 to S$20 per card, per the August 2026 police releaseSection 39B, Miscellaneous Offences (Public Order and Nuisance) Act 1906: fine up to S$10,000, imprisonment up to three years, or both
Your own Singpass credentialsUsually a one-off cash paymentComputer Misuse Act, in force 8 February 2024: fine up to S$10,000, imprisonment up to three years, or both
Obtaining or dealing in another person’s Singpass credentialsA recurring syndicate role rather than a one-off favourComputer Misuse Act: up to S$10,000 and three years for a first offence, up to S$20,000 and five years thereafter
A bank or payment account used to receive and move fundsA cut of the transfer, or a flat sum per transactionCDSA: rash money laundering, fine up to S$250,000 and imprisonment up to five years; assisting another to retain benefits, up to S$50,000 and three years

Read that table as a price list next to a penalty list. The gap between the two columns is the entire briefing. The SIM-card offences in the first row were introduced through the Law Enforcement and Other Matters Bill, passed on 2 April 2024, and the police set out the conduct they cover in plain terms: transferring a SIM card registered in your name, letting your details be used to register one, or supplying cards as a middleman.

What Are Employees Actually Being Asked to Hand Over?

Employees are asked for four things, and none of them will look like a security incident at the moment it happens. A SIM card registered in the employee’s name gives a syndicate a Singapore number, which is what makes a scam call or message look local. A bank or payment account gives it somewhere for a victim’s money to land. Singpass credentials give it the ability to open more accounts and register more services in someone else’s name. And Corppass, the business equivalent, gives it a company identity to transact with.

That last one is the reason this belongs on a corporate risk register rather than a personal-finance leaflet. Corppass access is delegated by an organisation to named individuals, so an employee under pressure has something to sell that is not entirely theirs.

This is also why the behaviour does not show up in the metrics most organisations already collect. A phishing simulation measures whether someone can be tricked. It measures nothing at all about whether someone can be paid.

Does It Matter That the Employee Did Not Know?

It matters less than most people assume, and that is the single most useful thing to put in front of staff. When Singapore amended the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act and the Computer Misuse Act with effect from 8 February 2024, it added money-laundering offences that do not require proof that the person knew what they were assisting. Per the Ministry of Home Affairs, rash money laundering carries a maximum fine of S$250,000 or five years’ imprisonment, and negligent money laundering a maximum fine of S$150,000 or three years.

Close-up photograph of two anonymous hands exchanging a small SIM card across a dark table, no faces visible
The exchange itself is the offence. What the person believed they were doing rarely changes that.

There is a second consequence that staff briefings tend to get wrong in both directions, so it is worth stating precisely. Since 30 December 2025, following the Criminal Law (Miscellaneous Amendments) Act 2025, caning applies to scams and scams-related offences. Scammers and the members and recruiters of scam syndicates face mandatory caning of at least six strokes and up to 24. Scam mules who enable scammers, including by providing SIM cards and Singpass credentials, are liable to discretionary caning of up to 12 strokes.

That provision and the SIM-card offence are different provisions. Section 39B of the Miscellaneous Offences Act, the one the August operation cites, carries a fine and imprisonment and no caning. Both facts are true at once, and neither “SIM-card mules face the cane” nor “SIM-card mules are outside the caning rules” is an accurate thing to tell your staff.

Why Is This an HR and Operations Issue, Not Only an IT One?

Scam mule recruitment is an HR and operations issue because the consequences now land on an employee’s ability to do ordinary things, including things they do on your behalf. In September 2025 the Singapore Police Force, MAS, IMDA and GovTech announced a facility restriction framework for scam mules. People who have been warned, fined, prosecuted or convicted for mule offences, and some assessed as posing a risk while under investigation, can be restricted from internet and mobile banking, card transactions and ATM access, and from subscribing to new mobile lines. Restrictions on Corppass and on using Singpass to register higher-risk services follow in a later phase. Banking and telecommunications restrictions began in October 2025, restriction periods are calibrated to the assessed risk, and the police handle appeals.

The same announcement gives a sense of how repetitive this behaviour is: nearly 15% of telephone line subscribers in 2025 who allowed their subscribed lines to be used for scams were repeat mule offenders, accounting for over 11,000 lines.

For an HR or operations lead, the practical questions follow quickly. Who else in the organisation holds Corppass authorisation for the same filings? Can payroll still reach an employee whose digital banking is restricted? Is your finance team’s approval chain resilient to one person losing access without notice? These are continuity questions, and they are far easier to answer before you need to.

Photograph of an empty Singapore office desk at dusk, a closed unbranded laptop and an access lanyard left alone under a desk lamp, the rest of the office dark and empty
One desk, one login, one person's trouble away from stopping a filing.

What Should a Singapore Employer Put in the Briefing?

A briefing on scam mule recruitment should be short, concrete and free of moralising. The employees most exposed to a S$20 offer are the ones under financial pressure, and a lecture lands badly. What works is a plain description of what is being asked for, an accurate statement of the penalty, and one rule simple enough to recall under pressure.

Adding recruitment risk to an existing awareness programme
  1. 1

    Write the one rule This week

    Agree a single sentence and use it everywhere: no legitimate employer, agent, bank or government agency ever needs a SIM card, a bank account or a Singpass login registered in your name. Name an internal contact staff can approach in confidence.

  2. 2

    Put it in induction This month

    Add a short recruitment-risk section to onboarding alongside the phishing material, and cover the four assets by name: SIM card, bank or payment account, Singpass, Corppass. State the maximum penalties accurately rather than dramatically.

  3. 3

    Close the continuity gaps This quarter

    Map every process that depends on one person's Corppass or banking authorisation and add a second authorised user. Review who holds delegated Corppass roles and remove access nobody uses.

  4. 4

    Refresh with real cases Ongoing

    Police releases on mule operations are published through the year and are free, dated, local teaching material. Refresh the briefing when the law changes, not on a calendar reminder.

Two things to avoid. Do not build the session around fear, because the recruitment pitch already arrives dressed as help and a frightened employee is a quiet one. And do not fold this into the phishing and employee training module without flagging that it is a different behaviour, or staff will file it mentally under “spot the fake email” and forget it.

If your awareness programme is still being built, our guide to cybersecurity awareness training for Singapore businesses covers the wider syllabus, and the top ten cybersecurity mistakes employees make covers the accidental end of the spectrum that this article deliberately leaves alone.

What Should You Do If You Suspect an Employee Has Been Recruited?

Treat it as a police matter first and an employment matter second. Facilitating a scam is a criminal offence in Singapore, not an internal policy breach, and a well-meant internal investigation can contaminate evidence and expose the organisation. Report it through the police, or call the ScamShield Helpline on 1799 if you are unsure whether what you are looking at is a scam at all.

Do not confront the individual with an accusation, do not ask them to explain themselves in writing, and do not delete or alter records that may be relevant. Preserve what you already hold, restrict any company access the situation genuinely warrants, and take advice before acting on the employment relationship. Presumption of innocence is not a courtesy here, it is the correct operating assumption.

This is a different playbook from a technical breach. If an attacker is inside your systems, follow your cyber incident response plan instead. And if the person turns out to have been drawn in through a relationship rather than a cash offer, our explainer on internet love scams describes that route, which ends in the same place by a much slower road.

Conclusion

The recruitment side of scams is the half of the problem that corporate training has not caught up with. It costs a syndicate S$10 to S$20 to buy a piece of somebody’s identity, it happens entirely off your network, and the person who says yes is not being tricked. That combination makes briefing the only control available, and it makes the briefing unusually easy to write, because the facts are public, dated and specific.

Start with one sentence your staff can remember, put accurate penalties next to it, and make sure no single person’s legal trouble can stop your company filing a return.

If you want that session run for you, CFCI’s cybersecurity awareness training for Singapore organisations is built for non-technical teams across operations, finance, HR and legal. We will tell you honestly if a short internal briefing would serve you better.

Frequently Asked Questions

What is a scam mule in Singapore?

A scam mule is someone who facilitates a scam by giving away a bank or payment account, a SIM card or Singpass credentials, or by helping to collect and transfer money, gold or valuables. The Singapore Police Force uses the term for the facilitation layer of a syndicate rather than for the scammers who contact victims directly. Mules are frequently recruited with small cash payments, which is what separates the behaviour from being deceived by a phishing message.

Is it illegal to register a SIM card or open a bank account for someone else in Singapore?

Yes, where you know or have reasonable grounds to believe the facility will be used unlawfully. Handing over a SIM card registered in your name is an offence under section 39B of the Miscellaneous Offences (Public Order and Nuisance) Act 1906, punishable by a fine of up to S$10,000, imprisonment of up to three years, or both. Allowing an account to be used to move criminal proceeds can also engage the money-laundering offences added to the CDSA in February 2024.

What should an employer include in a staff briefing about scam mule recruitment?

Cover three things: what is actually asked for (a SIM card, a bank or payment account, a Singpass or Corppass login), what the law says about handing any of them over, and one plain rule staff can remember. The rule most organisations settle on is that no legitimate employer, agent, bank or government agency ever needs a SIM card, a bank account or a Singpass login registered in someone else's name. Add a named internal contact so a worried employee has somewhere to go before the police do.

Can an employee be restricted from banking or Singpass, and does that affect the business?

Yes. Under the facility restriction framework announced by the Singapore Police Force, MAS, IMDA and GovTech in September 2025, people who have been warned, fined, prosecuted or convicted for mule offences, and some under investigation, can be restricted from digital banking, card and ATM transactions, and from subscribing to new mobile lines, with Singpass and Corppass restrictions in a later phase. Restriction periods are calibrated to the assessed risk and appeals are handled by the police. If that person uses Corppass on your organisation's behalf, you will need a second authorised user.

Ready to secure your future?

Join a free info session to meet the team, walk through the curriculum and find the right path for you. No IT background needed.

Chat with us