Stay informed with ICICI Bank Singapore’s Safe Banking guidelines. Learn how to protect your personal information, identify scams and bank securely through digital and branch channels.
Suitable For
Learn how to spot and prevent online frauds
Protect your banking credentials and devices
Ensure safe transactions across all banking channels.
1. Phishing
Phishing is a problem faced by banks across the world. It is an attempt to 'fish' for your banking details. Phishing could be an e-mail which appears to be from a known institution like a bank or a popular website.
How does phishing happen?
Phishers have refined their methods to launch sophisticated attacks and use advanced social engineering techniques to dupe online banking users. They use a combination of e-mail phishing, vishing (voice phishing) and smishing (SMS phishing) to get customer details like account number, login ID, login and transaction passwords, mobile number, address, CVV number, date of birth, passport number etc. Please note that banks will never ask for confidential data like login ID, transaction password, One Time Password (OTPs) etc.
How to stay safe from phishing?
1. Do not open spam e-mails. Be especially cautious of e-mails that:
2. Do not click on links or download files or open attachments in e-mails from unknown senders. Be cautious even if the e-mail appears to come from an enterprise that you do business with. It is a good practice to call up the concerned person for confirmation if the e-mail is unexpected.
3. Communicate personal information only via secure websites. When conducting online transactions, check for a sign that the website is secure, such as:
Six signs to spot phishing instead of falling for it:
By keeping these six signs in mind and always remaining vigilant, you can avoid falling for phishing scams. Refer to more safety tips at the links below:
If you have any doubt or want to report any suspicious / phishing e-mail / call / transactions, call us immediately at 8001012553 (If you are calling from Singapore) or (+65) 67239009 (if you are calling from outside Singapore), 7 days a week, from 8:00 a.m. to 6:00 p.m. or e- mail us at sg.service@icicibank.com.
2. Spear Phishing
Spear phishing is a type of e-mail spoofing fraud that targets a specific organisation, seeking unauthorised access to confidential data. Spear phishing is executed through an e-mail that appears to come from a trusted source – either a known business partner or often someone in the same company, a superior in many cases. The e-mail can also appear to be sent by a close relative. The subject line is customised / personalised and often will be of relevance to either current projects within the company or may be related to family matters. The data violation occurs when the user opens the e-mail, clicks on the link and Trojan software or malware gets downloaded on their device or a form appears on the screen, in which data needs to be filled in by the user. This information is confidential and could be useful for accessing and carrying out transactions using the organisation’s internal data and applications.
3. Spoofing
Website spoofing is the act of creating a website as a hoax, with the intention of perpetrating fraud. To make spoof sites appear legitimate, phishers use the names, logos, graphics and even the code of actual websites. They can even fake the URL that appears in the address field at the top of the browser window and the lock icon that stands for security.
How do the fraudsters operate?
Fraudsters send e-mails with a link to a spoofed website asking you to update or confirm account related information. This is done with the intention of obtaining sensitive account related information like your Net Banking User ID, password, PIN, Debit Card / Bank Account Number, Card Verification Value (CVV) etc.
Here are some precautions for safe and secure mobile banking:
Safety Tips for Handling Cash
Safety Measures for Cheque Books
Fraudsters use Short Message Service (SMS) phishing campaigns to target a bank’s customers. In an SMS phishing campaign, fraudsters send fraudulent SMS messages to some customers of a bank using an alphanumeric sender ID (‘alpha tag’) that appears to be from the bank. The spoofed SMS alpha tag causes the victims’ mobile phones to place both phishing and legitimate SMS messages from the bank in the same SMS conversation thread. This gives perceived legitimacy to the phishing SMS messages and increases the likelihood of victims being tricked into accessing the malicious link in the message.
When the victim clicks on the link, he/she is directed to a fraudulent website requesting for user credentials (i.e., username, password, One Time Password etc.). With these stolen credentials, the fraudster can conduct fraudulent activities such as setting up of soft token on the fraudster’s mobile device. Once the soft token is set up, the fraudster then proceeds with the addition of new payees and performing unauthorised fund transfers.
As the number of scam cases are on the rise, it is crucial to be vigilant and rational when remitting funds overseas. Please do not proceed with the remittance transaction if you do not know the identity of the beneficiary or are unsure on the purpose of the remittance. If you believe that you are a victim of scam/fraud, call us immediately at 8001012553 (If you are calling from Singapore) or (+65) 67239009 (if you are calling from outside Singapore), 7 days a week, from 8:00 a.m. to 6:00 p.m. or e- mail us at sg.service@icicibank.com.
Smartphones have features that allow data synchronisation between the mobile device and online storage or cloud services in near real time. Information that could be synchronised includes SMS, email, etc.
In the case of smartphone users who have enabled the data synchronisation feature, sensitive information sent via SMS or e-mails by financial institutions (FIs), such as one-time passwords (OTPs), etc. can be accessed by criminals if their login credentials to the online storage or cloud service have been compromised. Exposed OTPs, together with online banking credentials or Credit Card information that has been harvested from users, can potentially be used by criminals to carry out fraudulent financial transactions.
Users are advised to secure their mobile devices and related online accounts. To mitigate the impact of such cybercrimes, user can adopt good cyber hygiene measures, such as:
If you have any doubt or want to report any suspicious / phishing e-mail / call / transactions, call us immediately at 8001012553 (If you are calling from Singapore) or (+65) 67239009 (if you are calling from outside Singapore), 7 days a week, from 8:00 a.m. to 6:00 p.m. or e- mail us at sg.service@icicibank.com.
Reports have indicated that over 533 million Facebook users' data was recently leaked online, including data from over 3 million users based in Singapore. The leaked information comprised mainly the Facebook users' mobile number, profile name, profile ID and location. Some users' date of birth and e-mail ID were also included.
Threat actors may use the leaked information to conduct phishing and other social engineering attacks, with chances of such attacks being higher in a ‘Work from Home’ scenario. Facebook users should remain vigilant and look out for unsolicited phone calls and messages sent over SMS and instant messaging applications such as WhatsApp.
Threat actors may also use Caller ID spoofing technology to impersonate the Facebook user and conduct further attacks, such as:
Users should watch out for possible phishing campaigns arising from this leak. Practising the cyber hygiene measures given below can help mitigate the impact:
If you have any doubt or want to report any suspicious / phishing e-mail / call / transactions, call us immediately at 8001012553 (If you are calling from Singapore) or (+65) 67239009 (if you are calling from outside Singapore), 7 days a week, from 8:00 a.m. to 6:00 p.m. or e- mail us at sg.service@icicibank.com.
You might receive phishing SMSes and e-mails that appear to be sent by ICICI Bank Singapore Branch, which ask you to click on a link to verify your account, receive an incoming payment or prevent deactivation of your account. When you click on the link in such e-mails, you will be directed to a fraudulent website. Please note that ICICI Bank Singapore Branch does not reach out to clients and request for passwords and login details over phone calls, SMS or e-mails. Please do not click on the links in such SMSes or e-mails.
Cyberattacks on corporates have increased steadily in recent years. With criminals constantly devising new ways to steal information and money, one of the newest emerging threats is ‘Business E-mail Compromise’, also known as ‘CEO Fraud’ or ‘Chairman Fraud’. The most frequent targets of this scam are small and medium-sized businesses, that can lose huge sums because of one e-mail.
Fraudsters usually employ social engineering techniques and other cyberattacks such as installing malware to compromise and infiltrate the company’s system and endpoint devices. After gaining access to the senior executive’s or CEO’s e-mail account, the fraudster then studies his/her day-to-day activities and interactions. Next, the fraudster uses the compromised e-mail account or a lookalike e-mail account to send an e-mail to trick the company’s employees, customers or business partners, asking them to make a payment to a rogue account or to a purchase of gift card / voucher. A common tactic is to imitate the manner in which the senior executive / CEO sends payment instructions or replies to ongoing email conversations, in order to make the request appear credible.
How can you protect your business?
Call us immediately at 8001012553 (If you are calling from Singapore) or (+65) 67239009 (If you are calling from outside Singapore), 7 days a week, from 8:00 a.m. to 6:00 p.m. or e- mail us at sg.service@icicibank.com if you notice unknown transactions appearing in your account.
Criminals / fraudsters may call and trick you into believing that they are bank officers, government officials or the police. The caller ID on your mobile phone may even appear as ‘999’. Criminals typically use scare tactics to threaten you and make you believe that you have committed a crime. They may then ask you to give them your online banking credentials so that they can “check” your online accounts. If you do so, the criminals will be able to log into your online banking accounts and wipe out all the money in your bank accounts.
For example, the Immigration and Checkpoints Authority of Singapore (ICA) has recently issued a public advisory on this type of scam. You may refer to it at the link below:
Here are some tips to protect yourself from bogus phone calls. Always keep the following in mind:
ICICI Bank Limited would like to alert customers and members of the public to the rise in scams involving social media advertisements and chat groups that offer purported opportunities to learn investing or trading.
Fraudsters may impersonate legitimate financial institutions and invite individuals to join online groups where they share investment tips, trading recommendations, or purported investment opportunities. These scams are often designed to gain trust and induce victims to transfer funds or disclose personal information.
Please note that ICICI Bank Singapore Branch does not provide investment or trading services to retail customers. Customers are advised to exercise caution when responding to investment related advertisements, messages, or invitations received through social media and messaging platforms.
To protect yourself:
If you encounter any suspicious communication purporting to be from ICICI Bank Limited, please contact us immediately using the contact details below. If you suspect that you have fallen victim to a scam, you should also lodge a police report as soon as practicable.
Singapore: 8001012553
Overseas: +65 67239009
Operating Hours: Daily, 08:00 hours to 18:00 hours SGT
E-mail: sg.service@icicibank.com
Do not respond or click on any links. Forward phishing emails to antiphishing@icicibank.com and report calls to 8001012553.
Install anti-malware apps, disable Bluetooth and Wi-Fi when not in use, avoid saving passwords and download apps only from verified app stores.
Yes. Stay informed about ongoing phishing, spoofing and remittance scams via the ‘Safe Banking Updates’ section on the ICICI Bank Singapore website.
Contact ICICI Bank immediately at sg.service@icicibank.com or through our 24X7 helpline. Our team will secure your account and guide you through the recovery process.