Singpass passkey that offers digital keys to counter scams now available to Android users
Singapore has introduced a new digital security feature for Android users, building on the existing Singpass authentication system. This new passkey feature aims to protect users from phishing scams that have cost millions in losses. Passkeys work through a pair of unique encryption keys – one on the user's phone and one on Singpass' backend server – granting access only to legitimate websites.
Unlike passwords or QR codes, passkeys cannot be shared or exploited and are useless on fake websites. Since Sept 9, Android users will receive notifications in the Singpass app to create their passkeys via a provided banner. Approximately 800,000 iPhone users have already created passkeys since July. To use passkeys, Android users must update their Singpass app and follow the instructions to enable them.
Once registered, users can log into supported websites by scanning their face or fingerprint or entering a six-digit passcode. Laptops and desktops will receive passkey support by the end of 2026. Passkeys comply with Fido Alliance's open standards, widely adopted by tech companies and government bodies worldwide. Phishing cases in Singapore decreased by 16.8% from 3,772 in 2025 to 3,104 in the first half of 2026, with losses falling from $30 million to $9.6 million.
Written by urgent.news from Straits Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Singpass passkeys available to Android users from Sep 9 channelnewsasia.com