Singapore's Parliament is moving to close a significant loophole in its fraud defences by criminalising the supply and use of online account mules—individuals who provide their personal details to enable fraudulent operations across digital platforms. The Scams (Countermeasures) and Other Matters Bill, introduced on 4 August, represents an escalation in the city-state's battle against an epidemic of criminal activity that has consumed more than S$4 billion from victims since 2019. While existing legislation addresses traditional money mules and SIM card providers, the new framework extends enforcement powers to social media giants and marketplace platforms including Meta, TikTok, Telegram, Carousell and Instagram, where scammers have increasingly operated with relative impunity.

The legislative push comes amid alarming statistics that underscore the scale of Singapore's scam crisis. In 2025 alone, scams accounted for three in every five police reports, with total losses reaching S$913.1 million. Government official impersonation scams—a particularly insidious variant exploiting public trust—more than doubled in frequency, from 1,504 cases in 2024 to 3,363 in 2025, making it the fifth most prevalent scam category. These figures reveal not merely a public order problem but a fundamental threat to citizen confidence in digital transactions and government institutions themselves. For Malaysia and other regional economies facing similar challenges, Singapore's legislative response offers a blueprint for addressing the digital criminal ecosystem that respects no borders.

Under the proposed amendments, individuals who knowingly provide personal information to create fraudulent accounts will face substantial penalties: fines reaching S$10,000, imprisonment up to three years, and corporal punishment of up to 12 strokes of the cane. Those who supply, receive, or possess such accounts for criminal purposes face equivalent sanctions. This represents a significant hardening of the law against what might appear to be passive participation but which fundamentally enables large-scale fraud. The distinction is important: rather than treating account mule operators as mere facilitators, the law now recognises them as active conspirators whose involvement directly enables victimisation. This philosophical shift has implications for how Southeast Asian jurisdictions conceptualise complicity in digital crimes, moving beyond traditional accomplice doctrine toward direct liability for enabling infrastructure.

Perhaps more significantly for digital platform governance, the Bill dramatically increases maximum penalties for non-compliant service providers from S$1 million to S$10 million, with daily fines for continuing violations rising from S$100,000 to S$300,000. These escalations follow Meta's mixed record in responding to Singapore's previous implementation directives issued in September 2025 and January 2026. While police indicated that these directives had reduced impersonation scams on Facebook, the subsequent explosion in government official impersonation cases suggests that scammers have simply migrated tactics or that platform compliance remains insufficient. The tenfold increase in penalties signals Singapore's determination to shift responsibility decisively toward technology companies, effectively making non-compliance commercially untenable and forcing genuine investment in anti-fraud infrastructure rather than superficial compliance.

A critical innovation in the Bill addresses the sophisticated operational methods now employed by scam syndicates, particularly their integration of artificial intelligence. Police have observed that criminals can now generate fraudulent sites, accounts, and advertising at such velocity that human content moderation teams cannot keep pace. The legislation therefore authorises police to issue anti-scam directions through automated systems, including AI-powered tools, enabling detection and response at machine speed. Safeguards embedded in the framework are intended to prevent discriminatory or inaccurate implementation, though the real-world effectiveness of such guardrails remains to be tested. For Malaysia, this represents an important acknowledgment that combating 21st-century fraud requires 21st-century investigative capabilities rather than traditional manual processes.

The Bill introduces three distinct police powers targeting service providers. The disclosure order compels financial institutions, telecommunications companies, and online platforms to supply information on specified accounts and scam-related transactions. The account disabling order permits police to temporarily suspend suspect accounts for up to 60 days, preventing scammers from further exploiting them. These mechanisms support Singapore's developing National Scams List, a centralised intelligence system designed to enable real-time information-sharing between government agencies and private sector partners. The concept is genuinely innovative: by pooling data on culprit identities, compromised bank accounts, phone lines, and fraudulent online accounts, stakeholders can interdict fund flows before money moves through the system, attacking scam economics at their source rather than pursuing perpetrators after damage occurs.

The facility restriction framework represents an even more ambitious intervention in individual liberties, placing identified money mules, SIM card mules, and corporate entities under restrictions on accessing financial, telecommunications, and government services. As of 30 June, the framework encompassed 1,423 money mules, 1,439 SIM card mules, and 53 corporate mules. The proposed Bill formalises what has hitherto been voluntary compliance by introducing the service limitation order, enabling police to restrict service access for up to three years. This approach—leveraging the infrastructure of financial and digital systems to exclude suspected participants—effectively weaponises the very platforms that criminals exploit, creating a form of civil disability tied to scam activity. Whether this represents proportionate and necessary law enforcement or an expansion of police power into economic ostracism will likely generate constitutional scrutiny.

For Malaysian policymakers observing these developments, several lessons warrant attention. Singapore's experience demonstrates that scams thrive at the intersection of regulatory fragmentation and technology company incentives misaligned with public safety. The city-state's response—escalating penalties, demanding corporate accountability through massive fines, automating enforcement, and restricting services to suspected participants—represents a comprehensive ecosystem approach rather than isolated criminal sanctions. However, the approach also raises questions about due process, particularly regarding service limitation orders issued without necessarily resulting in criminal conviction, and about whether such mechanisms effectively deter sophisticated syndicates with international reach or merely displace activity to less-regulated jurisdictions.

The Bill's emphasis on real-time information-sharing and integrated government-private sector coordination reflects recognition that scam prevention cannot be siloed within law enforcement. Banks, telcos, social media platforms, and payment service providers all possess critical data that, when aggregated and analysed, reveals patterns and networks invisible to individual organisations. Singapore's National Scams List concept—enabling automated sharing of account information, phone numbers, and culprit identities—approximates an early warning system that could theoretically prevent transactions before they occur. Yet such systems also concentrate enormous data in police hands and create potential for mission creep or abuse if oversight mechanisms prove inadequate. The trade-off between security and privacy inherent in these mechanisms deserves careful evaluation as other jurisdictions contemplate similar legislation.

The practical effectiveness of these measures will ultimately depend on international cooperation, particularly given that many scam syndicates operate across multiple countries and employ money mules and account providers scattered throughout Southeast Asia and beyond. A determined criminal organisation can potentially circumvent service limitation orders by operating through new accounts, exploit jurisdictional gaps by routing funds through less-regulated banking systems, or relocate operations entirely. Singapore's approach therefore requires complementary action from regional partners to prevent scam activity simply transferring rather than diminishing. For Malaysia, coordinating with Singapore and other ASEAN nations on intelligence-sharing, mutual legal assistance, and harmonised penalties could multiply the deterrent effect of any individual nation's legislation. Conversely, legislative islands of toughness surrounded by jurisdictions with lower barriers may prove less effective than comprehensive regional governance architecture.

The Scams (Countermeasures) and Other Matters Bill ultimately reflects a mature understanding that digital-age crime requires digital-age responses. By targeting account infrastructure, automating enforcement through AI systems, imposing severe financial penalties on platforms, and restricting services to suspected participants, Singapore is attempting to fundamentally alter the economics and logistics of scamming. Whether this represents a durable solution or merely the current iteration in an endless arms race between law enforcement and criminal innovation remains uncertain. What appears clear is that scams have become such a dominant form of victimisation—representing three-fifths of police reports and losses exceeding S$900 million annually—that measured responses are insufficient. Singapore's escalation signals that digital fraud has been elevated to a national security concern demanding commensurate legislative and enforcement resources.