
On August 2026, the Singapore Police Force issued three Codes of Practice under the Online Criminal Harms Act, addressed big players like WhatsApp, Telegram, WeChat, Apple, Google, TikTok, Carousell and the Facebook-owned marketplace and business page products. Not "platforms" in the abstract. But established names with a history of data privacy violations.
That specificity is the story. Most regulatory responses to scam epidemics arrive as principles: platforms should act responsibly, should verify users, should protect consumers. Singapore's codes read more like a systems spec.
Messaging apps must get consent before an unknown contact adds someone to a group. Social platforms must check advertiser identities against government records before an ad runs, not after it's reported. E-commerce platforms must apply the same advertiser checks, plus new consent friction for logins from unrecognised devices. Every requirement maps to a named fraud pattern SPF has evidently already studied in detail: unknown-contact investment scams, government impersonation, unlicensed financial advertising. Despite all these, lax compliance in these platforms has led to repeated violations that threaten to harm vulnerable groups, including minors.
The number attached to that specificity is worth sitting with. WhatsApp and Telegram alone accounted for roughly 23% of Singapore's scam cases in 2025. Facebook, Instagram and TikTok made up around 30%, Facebook carrying about 18 points of that on its own. SPF didn't regulate "social media" as a category. It regulated the two platforms and the seven services actually carrying the fraud volume, and calibrated obligations to match.
None of this works without something most jurisdictions in the region don't yet have: a police force that can name the platform, the fraud typology, and the percentage of national case volume attributable to it, and do so with enough confidence to write it into a legal instrument.
This is the output of sustained casework, fed by Singapore's Anti-Scam Command and its established data-sharing arrangements with the banks and telcos that see the transaction and communication layers scammers actually use.
Compare that to how "combat online scams" mandates typically get written elsewhere in Southeast Asia: broad obligations on regulated entities, thinner requirements on the platforms where the initial contact and trust-building actually happen. Singapore's codes work because SPF could point to the unknown-contact vector, the advertiser-verification gap, and the device-login weakness as three distinct, evidenced failure points, each traceable to specific incident data. A jurisdiction without that granularity of case attribution will end up writing softer codes, not because its lawmakers are less committed, but because it can't yet substantiate a code this specific.
The gap Singapore closed wasn't legislative, it was informational. SPF could name a platform, a fraud typology, and a percentage of national case volume because the data-sharing arrangement with banks and telcos already existed before the codes were drafted. Most institutions in the region are still operating without that upstream visibility, which means even a well-intentioned regulator can't write anything more specific than "platforms should act responsibly," because nobody can hand them the numbers to do otherwise.
If your institution can't currently say which channel, which typology, and what percentage of loss is tied to a given fraud pattern, dated close enough to still be true, you're not positioned to feed a regulator the granularity Singapore's police force had. We work with institutions on building that visibility before the losses force the question, not after. That's the difference between reacting to a syndicate that's already moved on and catching the pattern the week it starts.
Connect with us to explore the impact here.
It's not that we should "regulate platforms harder." It's that platform-level codes are only as good as the fraud intelligence behind them, and that intelligence has to be updated enough to justify a 20 to 30% attribution figure in a legal document, not a retrospective annual report.
Institutions that want their own regulators to move this precisely need to be feeding comparable granularity upstream: which channel, which typology, which percentage of loss, dated close enough to the drafting window to still be true. Singapore's codes are a downstream result of that kind of visibility. The upstream work is the part worth replicating.
We're seeing the same scams in inner ASEAN that Singapore has just banned, usually within weeks of showing up on Singapore-facing platforms. The same syndicates, same scripts, just a different country's phone numbers.
Singapore could write a rule this specific because its police, banks and telcos already share data before problems happen, not after. The rest of the region still finds out about a scam pattern when a bank reports it, weeks after the money's gone. ASEAN is still playing cat-and-mouse while Singapore has moved to preemptive responses.
Copying Singapore's law changes nothing on its own. What has to come first is the same thing Singapore built first: banks, telcos and platforms actually sharing intelligence in real time, instead of comparing notes after the loss is already booked.
If your institution isn't set up to see a fraud pattern the day it starts, this is the year to fix that, before your regulator starts breathing down on everybody’s necks..
Singapore didn't get this advanced by accident. It got precise because different institutions — enforcement, regulators, platforms and telcos — were already comparing intelligence before the codes were being drafted. That's the part nobody can legislate into existence overnight. Cross industry coordination is something the rest of ASEAN is still figuring out, and this is the gap that makes it appealing for scammers to strike.
Everyone else in the region is still working from the version of the story that arrives after the money's gone: a bank flags a pattern, a report gets filed, a regulator eventually writes something broad enough to cover last quarter's fraud but not next quarter's.
Singapore wrote legislation that named seven platforms and three failure points because its casework was current enough to survive the drafting process. Most jurisdictions in ASEAN aren't short on political will. They're short on data that's still true by the time anyone acts on it.
That's the gap Level Five sits in. We are actively building the visibility and platform that makes a regulation like this possible before the losses justify it retroactively. From onboarding to settlement, we intend to grant institutions complete visibility.
So the real question for anyone reading this from inside a bank, a telco, or a ministry: when the next scam pattern shows up on a Singapore-facing platform, how many weeks will it take before you see it too?
Relevant resources:
https://www.regulationasia.com/articles/singapore-tightens-platform-rules-to-combat-online-scams