Singapore has decided that one way to teach people how not to fall for scams is to let them experience one first. A simulated one, thankfully.
Singapore’s Cyber Security Agency is running a six-month National Simulated Scams Exercise, in which volunteers receive simulated robocalls designed to mimic government impersonation scams. The pilot runs through Aug. 31 and is part of Singapore’s broader push to make its population more resilient to increasingly sophisticated digital fraud.
The experiment raises a useful question for businesses, too: If employees can be fooled by increasingly polished calls, messages, deepfakes, and impersonation attempts, is an annual security-awareness course really enough?
Singapore wants people to experience a scam before the real one arrives
Singapore’s Cyber Security Agency, with support from the Ministry of Home Affairs, launched the exercise on March 1. Participation is voluntary, but those who sign up don’t know exactly when the simulated scam will arrive.
At some point during the six-month exercise, participants receive robocalls that mimic Government Official Impersonation Scams (GOIS). According to CSA’s description of the exercise, the controlled simulation is intended to let people experience scammers’ techniques firsthand and learn what to do when they encounter similar tactics outside the exercise.
The experiment isn’t limited to yesterday’s scam tactics. In a July update on Singapore’s AI-driven threat landscape, CSA said the pilot includes AI-enabled government impersonation scam calls. That matters because the scam itself increasingly resembles a conversation rather than a suspicious link.
Voice-based social engineering can put victims under pressure in real time, exploiting authority, urgency, and fear before they have time to verify what they’re hearing. Security researchers have also found increasingly sophisticated tooling designed specifically for these attacks.
For example, TechRepublic previously covered phishing kits built for voice-based scammers that can provide attackers with real-time information as they try to persuade victims to approve multifactor authentication requests. Singapore’s exercise effectively gives participants a fire drill for that moment.
The scam problem is still expensive
Singapore has good reason to experiment.
According to Singapore Police’s 2025 scam and cybercrime figures, the country recorded 37,308 scam cases in 2025, with victims losing approximately S$913.1 million. Both figures declined from the previous year, but the losses still illustrate the enormous financial consequences of successful scams.
Government impersonation scams moved in the opposite direction.
Singapore’s Annual Scams and Cybercrime Brief 2025 shows GOIS cases more than doubled from 1,504 in 2024 to 3,363 in 2025, while reported losses climbed from S$151.3 million to S$242.9 million. The basic technique exploits something no software patch can completely remove: trust.
Scammers may pose as banks, government agencies, police officers, regulators, or other seemingly authoritative organizations. Their goal is often to create enough urgency or fear that the victim acts before independently checking the story.
That’s why technical defenses alone haven’t made the problem disappear. As TechRepublic previously examined in its analysis of Singapore’s S$913 million scam problem, even longstanding identity requirements for SIM registration haven’t eliminated telecom-enabled fraud. Attackers adapt around controls rather than politely crashing into them.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
What IT leaders can borrow from Singapore’s experiment
Businesses don’t need to start prank-calling their entire workforce tomorrow morning.
But Singapore’s experiment points toward a useful principle for security teams: People may learn more from safely experiencing an attack than from being told what one looks like. Traditional phishing simulations already use that idea. The difference is that the threat surface has expanded well beyond the inbox.
An employee might now receive a WhatsApp message supposedly from an executive, a convincing phone call from “IT,” a video call featuring a digitally manipulated face, or a request presented as a confidential assignment from senior management.
That’s not hypothetical. In a 2026 advisory on executive impersonation scams, Singapore Police warned that criminals had impersonated company executives on WhatsApp and, in some cases, used digitally altered appearances during video calls. Victims were told they were working on confidential projects and instructed not to discuss them with colleagues, cutting off one of the easiest ways to discover the deception.
For IT and security leaders, that suggests simulation programs should test more than whether an employee clicks a suspicious email.
Teams could practice scenarios involving:
- unexpected calls from supposed IT staff asking for credentials or MFA approval;
- urgent messages from executives requesting payments or sensitive information;
- requests to move a conversation from an official channel to WhatsApp or another messaging service;
- supposed regulators or law-enforcement officials demanding immediate action;
- voice or video impersonation intended to override an employee’s normal verification process.
The objective isn’t to catch employees making mistakes. It’s to build a reflex: Stop, verify, and use a second channel before acting.
That becomes more important as social engineering grows more interactive. TechRepublic has reported on the surge in social engineering attacks, including attackers posing as help-desk or IT personnel to exploit trust and urgency and persuade employees to weaken authentication controls.
Security training may need to feel more like a fire drill
There’s an obvious limitation to Singapore’s approach: Participants volunteered.
Employees in the real world don’t get to opt in before a criminal targets them. Nor does recognizing one simulated government scam guarantee that someone will spot the next fake CEO, supplier, help desk worker, recruiter, or bank representative. But the underlying idea is harder to dismiss.
Organizations regularly rehearse fires, evacuations, outages, incident-response procedures, and disaster-recovery plans because knowing a procedure isn’t the same as executing it under pressure.
Social engineering may deserve the same treatment. Instead of asking whether employees completed their annual cybersecurity module, security leaders may increasingly need to ask whether employees have practiced responding to the kinds of attacks they’re actually likely to encounter.
Singapore is betting that experiencing the trick once, in a controlled environment, can make the real trick easier to recognize.
For businesses facing AI-assisted impersonation, voice phishing, deepfakes, and increasingly personalized fraud, that may be the more useful lesson: Don’t just teach employees what a scam looks like. Give them practice saying no to one.
Related reading: For another sign of how technology is reshaping Singapore, the country recently raised its 2026 growth forecast as booming AI demand fuels electronics exports and manufacturing.