Case Library / Vishing (Voice Phishing) / Singapore Anti-Scam Centre / Police Impersonation Scam: "Jane" Loses S$1.2 Million (2024-2025)

Singapore Anti-Scam Centre / Police Impersonation Scam: "Jane" Loses S$1.2 Million (2024-2025)

A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre officer and then police "Inspector Chong" convinced her she was linked to money laundering, coaching her to lie to the real Anti-Scam Centre and extracting funds via bank transfers and four in-person cash handoffs.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Starting 11 December 2024, a woman in her 50s working in Singapore's finance sector received a cold call from a person claiming to be "Jenny Koo," an officer of the Singapore Police Force's Anti-Scam Centre (ASC), alleging her NRIC had been used to register a SIM card for sending spam. The call was redirected to "Inspector Yang," who used a fake, self-destructing "police pass" image and simulated background radio chatter to appear legitimate, then accused her of money laundering via a bank account allegedly opened in her name by a corrupt bank branch manager, from which she supposedly took a 10% commission. He demanded her bank statements and four-times-daily WhatsApp location updates, warned her to tell no one, and on 13 December sent a forged police letter threatening 60 days' detention for non-cooperation. On 14 December the case was escalated to a "senior officer," "Inspector Chong," who told her she was needed to help "trap" the corrupt insider and instructed her to withdraw S$500,000 and move it into a newly opened account at a Chinese bank. Between 18-19 December she made nine transfers totaling S$180,000, each just under S$20,000, framed by the scammers as harmless "dummy" payments. Anticipating a genuine welfare check, the scammers coached her on what to tell the real ASC when it called; she followed the script and the real agency's verification call failed to break the spell. After the receiving bank suspended the account over suspicious activity, Chong redirected her to withdraw the remaining balance in cash and hand it, in person, to couriers he identified over the phone during four separate meetups in central Singapore between then and 3 January 2025. In total she handed over S$1.2 million, her life savings earmarked for a new home and retirement, before the scammers stopped responding on 24 January 2025. She filed a police report on 6 February 2025, and the Singapore Police Force facilitated a media interview with her (under the pseudonym "Jane") on 14 March 2025 to raise public awareness of the scam pattern.

How the Attack Worked

The scam followed a layered "authority escalation" script over roughly six weeks. It opened with a low-stakes, plausible pretext (an alleged NRIC-linked SIM card used for spam) delivered by a caller posing as an Anti-Scam Centre (ASC) officer ("Jenny Koo"), who then "transferred" the call to a second persona, "Inspector Yang," posing as a police investigator. Yang used a fake, self-destructing "police pass" image and background walkie-talkie chatter to simulate legitimacy, then escalated the accusation to money laundering via a bank account allegedly opened in the victim's name by a corrupt "bank branch manager." He demanded bank statements and four-times-daily WhatsApp whereabouts updates, both a surveillance and an isolation mechanism, and delivered a forged police letter threatening 60 days' detention for non-compliance. The case was then escalated again to a "senior officer," "Inspector Chong," who framed further compliance as the victim actively helping police "trap" the corrupt insider: she was told to withdraw S$500,000 and route it through a new account at a Chinese bank, with the initial outbound transfers reframed as harmless "dummy" or "bait" payments. Anticipating that the real ASC would eventually call the victim (as part of Singapore's genuine anti-scam intervention process), the scammers pre-coached her on exactly what to say to the real officers so she would deny being scammed and vouch for her own compliance, defeating the one built-in circuit-breaker in the system. When the mule account was frozen by the receiving bank, the scam pivoted from wire transfers to physical cash extraction: the victim withdrew the remaining balance in cash and met an in-person "officer," directed live by "Inspector Chong" over the phone, across four handoffs in public locations in central Singapore. The scheme ended when the scammers stopped responding once the victim's funds were exhausted.

The Lure & the Tell

Lure: a credible-sounding, sequential chain of impersonated authorities, a generic "Anti-Scam Centre" officer, then a "police inspector" with a fake credential image and simulated radio chatter, then a "senior inspector", each stage adding legitimacy, urgency, and a plausible reason (helping catch a corrupt bank insider) for the victim to keep complying, reinforced by a forged detention-threat letter and demands to prove her innocence by moving money. Tell signs, visible with hindsight and central to the public-awareness message: a "police pass" that could only be viewed once and then vanished (unverifiable by design); a real police force or bank that would never ask for round-the-clock WhatsApp location updates or demand secrecy about an "investigation"; instructions to lie to a real government hotline that called to check on her; and being told to open an unfamiliar overseas-bank account and hand physical cash to strangers in public as part of a supposed police operation, none of which any genuine law-enforcement or banking process requires.

Outcome

The victim lost her full S$1.2 million in savings, intended for a new home and retirement, before realizing she had been scammed when the fraudsters stopped responding on 24 Jan 2025; she filed a police report at Pasir Ris Neighbourhood Police Centre on 6 Feb 2025. No arrests, prosecutions, or fund recovery tied specifically to this case were reported in available coverage. The Singapore Police Force facilitated a media interview with the victim (under the pseudonym "Jane") on 14 March 2025 to publicize the case as an example of the broader "Government Officials Impersonation Scam" (GOIS) trend, which SPF statistics show accounted for 1,504 reported cases and at least S$151.3 million in losses in Singapore in 2024 alone.

Why It Matters

The case is a well-documented illustration of how a multi-persona, escalating "police/government-official" vishing script can defeat even the intended safety net of a genuine anti-scam agency's callback: the scammers pre-coached the victim to lie to the real Anti-Scam Centre when it called to check on her, neutralizing the exact intervention mechanism Singapore built to catch such scams in progress. It also shows the tactic's effectiveness against a financially literate professional when combined with exploitation of personal vulnerability (bereavement, illness, work overload) and demonstrates the hybrid remote-to-physical pattern increasingly used in Southeast Asian impersonation scams: online/phone grooming culminating in in-person cash handoffs to couriers, which sidesteps bank transfer-monitoring controls entirely. Singapore's police and monetary authority have flagged this as part of a fast-growing scam category (1,504 cases, over S$151.3 million lost in 2024) warranting sustained public advisories.

Defenses

Singapore Police Force, MAS, and ScamShield guidance issued around this case class stresses: genuine police/Anti-Scam Centre officers and banks never ask victims to transfer money, withdraw cash, open new bank accounts, or hand over funds to "prove innocence" or assist an "investigation"; they never conduct investigations over WhatsApp or demand round-the-clock whereabouts updates; any request for secrecy/confidentiality ("don't tell anyone, case is classified") is a red flag intended to isolate the victim from family, bank staff, or real verification; independently call back government agencies via numbers looked up separately (e.g., 1800-722-6688 anti-scam helpline), never via a number or "transfer" provided by the caller; be skeptical of self-destructing/one-time-view "credential" images, which cannot be verified after viewing; banks should flag rapid new-account creation followed by structured sub-threshold outbound transfers and cross-border transfers to accounts inconsistent with customer profile; family/proxy check-ins are valuable when a person is isolated, grieving, ill, or overworked, since scammers deliberately target reduced capacity to scrutinize claims.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target profiling: The scammers opened the call already able to cite the victim's NRIC number and personal details accurately, consistent with the pattern ScamShield's own guidance warns about, where fraud rings work from personal data obtained via breach dumps, leaked databases, or commercial data brokers rather than through direct research on a specific target, and use it to sound credible from the first call.
Countering Stage 1: Personal data circulating through breach dumps and data-broker markets is largely outside an individual's control and very hard to eliminate at a population scale; the realistic control is public awareness that a caller correctly stating your NRIC or personal details is not, by itself, proof they are a genuine official, which is the core message of Singapore's ScamShield and SPF advisories.
2
Initial low-stakes pretext contact: A caller posing as "Jenny Koo," an Anti-Scam Centre officer, opened with a plausible, low-alarm claim (an NRIC-linked SIM card used for spam) rather than an immediate accusation, building initial cooperation before redirecting the call to a second, more threatening persona.
Countering Stage 2: Treating any unsolicited call from a self-identified government or Anti-Scam Centre officer as unverified by default, and independently calling back only through a number looked up separately (such as the 1800-722-6688 anti-scam helpline or 1799 ScamShield line), removes the scammer's ability to control the channel from the first contact.
3
Escalation with fabricated authority props: A second caller, "Inspector Yang," posing as police, used a self-destructing one-time-view "police pass" image and simulated background radio chatter, both low-cost ways to simulate legitimacy over a voice or chat channel without any real credential ever being verifiable, then escalated the accusation to money laundering involving a named, seemingly specific bank employee.
Countering Stage 3: Skepticism toward credentials that cannot be independently re-checked, such as a one-time-view "police pass" image or staged background sound effects, since genuine police identification can always be verified through an official channel rather than trusted on the strength of a single unverifiable artifact.
4
Isolation and surveillance demands: The scammers demanded bank statements and four-times-daily WhatsApp whereabouts updates, warned the victim to tell no one, and delivered a forged police letter threatening 60 days' detention, combining surveillance, secrecy, and fear to cut the victim off from outside verification.
Countering Stage 4: Recognizing that no genuine police force or bank ever demands round-the-clock whereabouts reporting, secrecy about an ongoing case, or bank statements sent over WhatsApp, and treating any such demand, especially a request for confidentiality from family, as the clearest available red flag.
5
Escalation to a senior persona and financial staging: A third caller, "Inspector Chong," posing as a senior officer, reframed continued compliance as the victim heroically helping to "trap" a corrupt insider, then directed her to withdraw S$500,000 and open a new account at a Chinese bank to route funds through, a step that gave the scammers a receiving account fully under their control.
Countering Stage 5: No legitimate government process ever asks a private citizen to withdraw savings and route them through a newly opened account to help "trap" a suspect, and banks can flag the specific pattern of a new account opened shortly before receiving a large inbound transfer as a scam indicator worth a manual hold.
6
Pre-coaching against the real safety net: Anticipating that Singapore's genuine Anti-Scam Centre would eventually call the victim as part of its own intervention process, the scammers scripted in advance what she should say to deny being scammed, defeating the one built-in circuit-breaker the system had for catching the fraud in progress.
Countering Stage 6: Because scammers may pre-coach victims to defeat a scripted verification call, genuine anti-scam callback processes are strongest when paired with an independent channel the scammer cannot anticipate, such as a family member or bank staff checking in directly, rather than relying solely on the victim's own answers during the call.
7
Structured extraction via bank transfer: Between 18 and 19 December, the victim made nine transfers totaling S$180,000, each just under S$20,000 and framed by the scammers as harmless "dummy" payments, a pattern consistent with structuring transfers to stay under thresholds that might otherwise trigger scrutiny.
Countering Stage 7: Banks and regulators can flag rapid new-account creation followed by multiple same-day or next-day transfers just under common reporting thresholds, the structuring pattern MAS and SPF advisories specifically warn about, and place a hold pending manual review before funds move further.
8
Pivot to in-person cash extraction and payout: After the receiving bank suspended the account over suspicious activity, the scammers redirected the victim to withdraw the remaining funds in cash and hand them, in person, to couriers identified live over the phone, across four separate meetups in central Singapore, extracting the balance of the S$1.2 million total once the banking channel was closed off.
Countering Stage 8: In-person cash handoffs to unknown couriers directed live by phone bypass banking controls entirely, so the most effective control at this final stage is the same public-awareness message Singapore's police built this case's media briefing around: no genuine investigation is ever conducted by handing physical cash to a stranger in public, and reaching a trusted family member or the police before any handoff is the last available intervention point.
Quick Facts
Victim
Individual Singaporean woman, referred to by the pseudonym "Jane," a financial-sector professional in her 50s; her real identity was not disclosed by police or media
Location
Singapore
Date
2024-12-11 to 2025-01-24 (scam period); police report filed 2025-02-06; case publicized by Singapore Police Force at a media briefing on 2025-03-14, reported by CNA/Straits Times 2025-03-17/18
Impact
Total reported loss: S$1.2 million (~US$900,000), described by the victim as her life savings intended for a new home and retirement. Reported breakdown: S$500,000 initially withdrawn from her own bank and moved into a new account she was told to open at a Chinese bank; of that, S$180,000 (~US$135,000) was sent out in nine transfers between 18-19 Dec 2024, each just under S$20,000 (apparently structured to stay under reporting/scrutiny thresholds); after the Chinese bank suspended the account over suspicious activity, she withdrew the remaining balance in S$100 notes and handed cash to in-person "couriers" across four separate meetups in central Singapore (the last on 3 Jan 2025), with cumulative withdrawals and handovers over the full two-month period totaling the reported S$1.2 million. No recovery or restitution was reported in connection with this case as of the March 2025 media briefing.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Financial Services & Insurance
Threat Actor
Organized Crime
Related

Related Cases

NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case

A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into…

Incident 2024Read →

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…

Incident 2024Read →

Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)

A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…

Incident 2024Read →