Singapore Is Literally Training People to Get Scammed

Singapore Is Literally Training People to Get Scammed

Singapore is using simulated scam calls to help people recognize impersonation tactics. Image: Generated via Google’s Nano Banana

Singapore is using simulated AI-enabled scam calls to train the public, offering IT leaders a new model for social engineering security training.

Written By
Matt Gonzales
Matt Gonzales
Aug 14, 2026

Singapore has decided that one way to teach people how not to fall for scams is to let them experience one first. A simulated one, thankfully.

Singapore’s Cyber Security Agency is running a six-month National Simulated Scams Exercise, in which volunteers receive simulated robocalls designed to mimic government impersonation scams. The pilot runs through Aug. 31 and is part of Singapore’s broader push to make its population more resilient to increasingly sophisticated digital fraud.

The experiment raises a useful question for businesses, too: If employees can be fooled by increasingly polished calls, messages, deepfakes, and impersonation attempts, is an annual security-awareness course really enough?

Singapore wants people to experience a scam before the real one arrives

Singapore’s Cyber Security Agency, with support from the Ministry of Home Affairs, launched the exercise on March 1. Participation is voluntary, but those who sign up don’t know exactly when the simulated scam will arrive.

At some point during the six-month exercise, participants receive robocalls that mimic Government Official Impersonation Scams (GOIS). According to CSA’s description of the exercise, the controlled simulation is intended to let people experience scammers’ techniques firsthand and learn what to do when they encounter similar tactics outside the exercise.

The experiment isn’t limited to yesterday’s scam tactics. In a July update on Singapore’s AI-driven threat landscape, CSA said the pilot includes AI-enabled government impersonation scam calls. That matters because the scam itself increasingly resembles a conversation rather than a suspicious link.

Voice-based social engineering can put victims under pressure in real time, exploiting authority, urgency, and fear before they have time to verify what they’re hearing. Security researchers have also found increasingly sophisticated tooling designed specifically for these attacks.

For example, TechRepublic previously covered phishing kits built for voice-based scammers that can provide attackers with real-time information as they try to persuade victims to approve multifactor authentication requests. Singapore’s exercise effectively gives participants a fire drill for that moment.

Advertisement

The scam problem is still expensive

Singapore has good reason to experiment.

According to Singapore Police’s 2025 scam and cybercrime figures, the country recorded 37,308 scam cases in 2025, with victims losing approximately S$913.1 million. Both figures declined from the previous year, but the losses still illustrate the enormous financial consequences of successful scams.

Government impersonation scams moved in the opposite direction.

Singapore’s Annual Scams and Cybercrime Brief 2025 shows GOIS cases more than doubled from 1,504 in 2024 to 3,363 in 2025, while reported losses climbed from S$151.3 million to S$242.9 million. The basic technique exploits something no software patch can completely remove: trust.

Scammers may pose as banks, government agencies, police officers, regulators, or other seemingly authoritative organizations. Their goal is often to create enough urgency or fear that the victim acts before independently checking the story.

That’s why technical defenses alone haven’t made the problem disappear. As TechRepublic previously examined in its analysis of Singapore’s S$913 million scam problem, even longstanding identity requirements for SIM registration haven’t eliminated telecom-enabled fraud. Attackers adapt around controls rather than politely crashing into them.

Must-read security coverage

What IT leaders can borrow from Singapore’s experiment

Businesses don’t need to start prank-calling their entire workforce tomorrow morning.

But Singapore’s experiment points toward a useful principle for security teams: People may learn more from safely experiencing an attack than from being told what one looks like. Traditional phishing simulations already use that idea. The difference is that the threat surface has expanded well beyond the inbox.

An employee might now receive a WhatsApp message supposedly from an executive, a convincing phone call from “IT,” a video call featuring a digitally manipulated face, or a request presented as a confidential assignment from senior management.

Advertisement

That’s not hypothetical. In a 2026 advisory on executive impersonation scams, Singapore Police warned that criminals had impersonated company executives on WhatsApp and, in some cases, used digitally altered appearances during video calls. Victims were told they were working on confidential projects and instructed not to discuss them with colleagues, cutting off one of the easiest ways to discover the deception.

For IT and security leaders, that suggests simulation programs should test more than whether an employee clicks a suspicious email.

Teams could practice scenarios involving:

  • unexpected calls from supposed IT staff asking for credentials or MFA approval;
  • urgent messages from executives requesting payments or sensitive information;
  • requests to move a conversation from an official channel to WhatsApp or another messaging service;
  • supposed regulators or law-enforcement officials demanding immediate action;
  • voice or video impersonation intended to override an employee’s normal verification process.

The objective isn’t to catch employees making mistakes. It’s to build a reflex: Stop, verify, and use a second channel before acting.

That becomes more important as social engineering grows more interactive. TechRepublic has reported on the surge in social engineering attacks, including attackers posing as help-desk or IT personnel to exploit trust and urgency and persuade employees to weaken authentication controls.

Security training may need to feel more like a fire drill

There’s an obvious limitation to Singapore’s approach: Participants volunteered.

Employees in the real world don’t get to opt in before a criminal targets them. Nor does recognizing one simulated government scam guarantee that someone will spot the next fake CEO, supplier, help desk worker, recruiter, or bank representative. But the underlying idea is harder to dismiss.

Organizations regularly rehearse fires, evacuations, outages, incident-response procedures, and disaster-recovery plans because knowing a procedure isn’t the same as executing it under pressure.

Social engineering may deserve the same treatment. Instead of asking whether employees completed their annual cybersecurity module, security leaders may increasingly need to ask whether employees have practiced responding to the kinds of attacks they’re actually likely to encounter.

Singapore is betting that experiencing the trick once, in a controlled environment, can make the real trick easier to recognize.

Advertisement

For businesses facing AI-assisted impersonation, voice phishing, deepfakes, and increasingly personalized fraud, that may be the more useful lesson: Don’t just teach employees what a scam looks like. Give them practice saying no to one.

Related reading: For another sign of how technology is reshaping Singapore, the country recently raised its 2026 growth forecast as booming AI demand fuels electronics exports and manufacturing.

Matt Gonzales

Matt Gonzales is a technology journalist, editor, and content strategist with more than a decade of experience covering emerging technologies, enterprise IT, cybersecurity, artificial intelligence, and workplace innovation. As Managing Editor for eWeek and TechRepublic, he leads editorial strategy and newsroom operations while helping business and IT leaders navigate an evolving technology landscape. Throughout his career, Matt has held leadership roles overseeing content development, editorial planning, and newsroom operations across digital publications and enterprise media organizations. Before joining TechnologyAdvice, he served as an editor at SHRM, where he covered workplace trends and emerging technologies, and as Lead Writer and Editor for Marine Corps Systems Command, where he reported on defense technologies, innovation initiatives, and government technology programs. Matt's expertise spans cybersecurity, enterprise technology, AI, B2B software, technical writing, and digital publishing. He has reported on major technology developments, including the rapid evolution of generative AI, helping readers understand both the opportunities and risks associated with emerging technologies. His work combines deep research, editorial rigor, and practical business insights to make complex technical topics accessible to a broad audience. An award-winning journalist, Matt has earned recognition for excellence in reporting and editorial leadership. He holds a Bachelor of Science in Communication with a concentration in Journalism from East Carolina University and continues to focus on delivering trusted analysis and actionable insights for technology, cybersecurity, and business professionals.