Urgent.News

600+ sources. One page. See who else covered it.

Editions

World

251 victims, S$1.2 million gone: The iMessage courier scam that bypasses Apple’s built-in protection

At least 251 people have lost more than S$1.2 million to courier impersonation scams sent via Apple iMessage since late June, with scammers exploiting a security feature to make phishing links clic... This article ( 251 victims, S$1.2 million gone: The iMessage courier scam that bypasses Apple’s built-in protection ) first appeared on The Independent Singapore News .

251 victims, S$1.2 million gone: The iMessage courier scam that bypasses Apple’s built-in protection

The Singapore Police Force has issued an urgent warning regarding a surge in courier impersonation phishing scams conducted through Apple iMessage. Since June 24, 2026, at least 251 cases have been reported, resulting in total losses exceeding S$1.2 million. Apple iMessage has a built-in protection feature that blocks links from unknown senders by default.

However, scammers have devised a method to circumvent this security measure. Instead of sending direct links, they prompt victims to reply with a simple "Y" or "1" to acknowledge receipt of the message. This action removes the blocking mechanism, allowing the phishing link in the initial message to become clickable. The fraudulent messages appear to originate from foreign numbers, such as +212 (Morocco), +63 (Philippines), and +44 (United Kingdom), or from email addresses consisting of random alphanumeric strings.

However, they are crafted to mimic legitimate courier companies such as DHL, NinjaVan, J&T Express, and SingPost. The message claims that a parcel cannot be delivered due to an invalid address and urges the recipient to update their details via the provided link before a specified deadline. Clicking on the link redirects the victim to a fraudulent website that closely resembles the genuine courier's website.

The aim is to trick the victim into providing their card details or internet banking credentials, thereby enabling the scammers to carry out unauthorized transactions. In some instances, victims are also coerced into providing One-Time Passwords (OTPs), which could allow scammers to link the victim's credit card to Google Pay or Apple Pay, or provision their digital banking tokens to unfamiliar devices.

It is important to note that courier companies do not utilize Apple iMessage to communicate with customers. Genuine communications are sent via registered SenderIDs, which can be verified on the SMS Registry website (smsregistry.sg/web/sid-query) or through direct contact via phone call, SMS, or WhatsApp. Unless the parcel is cash-on-delivery or necessitates GST payment, delivery drivers will never request payment from recipients.

Written by urgent.news from The Independent Singapore's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theindependent.sg →

More in World

Alpen Flagship Store Opens in Osaka

Major sporting goods retailer Alpen is opening Alpen OSAKA, one of the largest sports and lifestyle stores in the Kansai region, at the former Uniqlo site in Osaka's Chayamachi district, with six…

More from Friday 7 August →