The Singapore Police Force released footage on 16 May 2026 of a Zoom video conference that never took place. Synthetic likenesses of Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah and representatives of the Monetary Authority of Singapore discussed the Strait of Hormuz and requested urgent funding. One victim transferred at least S$4.9 million — about US$3.8 million — making the Singapore deepfake Zoom scam the largest single deepfake-enabled loss the country has documented.
On 17 August 2026 the same police force issued three Codes of Practice under the Online Criminal Harms Act, requiring Facebook, Instagram and TikTok to verify advertiser identities by 31 January 2027. There was no advertisement anywhere in this attack. It arrived by WhatsApp and email, and the deepfake ran inside Zoom — which is not one of the seven services the new conferencing code designates.
- At least S$4.9 million (about US$3.8 million) was lost by a single victim, with the final transfer on 14 May 2026.
- The Singapore Police Force named three artefacts in the footage: audio out of sync with lip movement, all speech from a single account rather than per participant, and a distorted background with a partially obscured Zoom logo. Two are cosmetic; one is architectural.
- Of the six stages in the attack chain, the three new codes reach one — the opening WhatsApp impersonation, which the anti-spoofing requirement targets directly by 30 September 2026.
- Zoom is not among the seven designated messaging and conferencing services, and email is designated by no code at all. Both carried this attack.
- Government officials impersonation scams rose 123.6% to 3,363 cases in 2025 and losses on that type rose 60.5% to about S$242.9 million, in a year when total scam cases fell 27.6% and total losses fell 17.9%.
- Volume-weighted designation protects the mean, not the tail. Email carried 934 of 37,308 scam cases; in this one case it helped carry roughly half a percent of the nation's annual scam losses.
Executive summary
On 16 May 2026 the Singapore Police Force published footage from a Zoom video conference that never happened. In it, synthetic likenesses of Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah and representatives of the Monetary Authority of Singapore discussed the Strait of Hormuz and asked a business professional for urgent funding. The victim transferred at least S$4.9 million, roughly US$3.8 million. It is the largest single deepfake-enabled loss Singapore has documented.
Three months later, on 17 August 2026, the same police force issued three new Codes of Practice under the Online Criminal Harms Act. Their flagship measure is advertiser identity verification: by 31 January 2027, Facebook, Instagram and TikTok must check advertisers against Government-issued records before those advertisers can reach Singapore users. It is a serious instrument, and it is well aimed at the surface it addresses.
It would not have touched this attack. There was no advertisement at any point in the chain. The approach came over WhatsApp, the pretext arrived by email, and the deepfake ran inside a Zoom call — and Zoom is not one of the seven services designated under the new Messaging and Conferencing Code. This article sets out what the police actually published, what the codes actually cover, and why the gap between them is not an oversight but a predictable consequence of calibrating regulation to case volume when catastrophic losses live in the tail.
- Classification: government-official impersonation, deepfake-enabled authority attack, single-victim catastrophic loss.
- Confirmed loss: at least S$4.9 million (about US$3.8 million) from one victim; final transfer 14 May 2026.
- Named regulator: Singapore Police Force, with the Monetary Authority of Singapore named in the code's licensing requirement.
- The detection claim we are not making: DuckDuckGoose has not analysed the footage. Everything technical below comes from what the SPF itself published about the artefacts, and is labelled as such.
- The finding: of the six stages in this attack chain, the three new codes reach exactly one.
The Singapore Police Force released footage on 16 May 2026 of a fabricated Zoom video conference in which deepfakes of Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah and representatives of the Monetary Authority of Singapore solicited “urgent funding assistance” tied to the Strait of Hormuz. One victim transferred at least S$4.9 million. Three months later, on 17 August 2026, the SPF issued three new Codes of Practice under the Online Criminal Harms Act — and the channel this attack actually travelled through is not among the services they designate.
What the Singapore Police Force actually published
Most coverage of this case reported the number. The more useful document is the police advisory itself, because the SPF did something unusual: it released footage from the fraudulent conference and named the specific things that were wrong with it.
Per the SPF advisory of 16 May 2026, the fabricated conference featured impersonations of the Secretary to the Cabinet, Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah and representatives of the Monetary Authority of Singapore. It also featured figures presented as Canada's foreign minister, a senior diplomatic adviser to the President of the UAE, and executives of BlackRock and the Dubai International Financial Centre. The subject under discussion was the situation in the Strait of Hormuz, and the ask was urgent funding assistance.
The three artefacts the police identified in the footage were these. First, speech did not synchronise with the speakers' lip movements, which the advisory attributes to inauthentic audio layered over video. Second, all speech was broadcast through a single account rather than from each participant individually. Third, the background was distorted and the Zoom logo partially obscured in a way that did not align with the foreground.
That second artefact is the interesting one, and it is not a rendering flaw. It is an architectural signature. A genuine multi-party video call carries one audio and video stream per participant, each with its own endpoint, codec behaviour and network fingerprint. A fabricated conference assembled outside the platform and played into it collapses to a single stream, because there is only one thing actually connecting. That is a property of how the attack must be constructed, not a mistake the attacker made.
The SPF paired the artefacts with a public advisory it calls the 3A approach — assess the message, analyse the audio-visual elements, and verify through official channels, with the 24/7 ScamShield helpline on 1799. We will come back to why the second A is the weakest of the three.
Timeline of events
The case does not begin in May 2026. Singapore has been escalating against government-official impersonation on platform surfaces since 2024, and the sequence matters for understanding what the August codes were responding to.
Table 1: Timeline from the first OCHA designations to the compliance deadlines set by the August 2026 codes.
Anatomy of the attack chain
Reconstructed from the police advisory and corroborating reports, the attack ran six stages. The structure is worth reading closely, because the deepfake sits in the middle of it rather than at either end.
Six stages, and not one of them is an advertisement
Reconstructed from the Singapore Police Force advisory of 16 May 2026 and corroborating reports. The deepfake did not open the attack and it did not close it — it sat in the middle, manufacturing the authority that made the transfer instruction plausible.
The flagship remedy in the 17 August codes is advertiser identity verification. There is no advertisement at any stage of this chain. The measure and the attack do not meet.
Stage 2 deserves more attention than it usually gets. The victim signed a non-disclosure agreement and handed over a copy of their identity document before any synthetic media appeared. The NDA is not a legal instrument here; it is a control-suppression device. The one defence that reliably defeats an authority attack is asking somebody else, and the NDA is engineered specifically to make asking somebody else feel like misconduct. By the time the deepfake arrives, the target has already been isolated.
Stage 4 is where the synthetic media does its work, and its job is narrower than it appears. The deepfake never asks for money. It establishes that the request is real. The actual instruction comes at stage 5, from a person posing as a lawyer, through an ordinary channel. This division of labour is characteristic and it has a practical consequence: an organisation that screens payment instructions for synthetic media will find nothing, because the instruction was never synthetic. The synthesis happened one step upstream, in the meeting that made the instruction credible.
The SPF's own 2025 statistics show why this pattern is expensive. Across all scam types, the brief records that 81.8% of reported scams in 2025 involved self-effected transfers, meaning scammers “did not gain direct control of the victims' accounts but manipulated them into performing monetary transactions through deception and social engineering.” The money moves because the victim moves it. Every control that assumes an intruder is looking in the wrong place.
What is a deepfake-enabled authority attack?
A deepfake-enabled authority attack is a fraud in which synthetic audio or video is used not to issue an instruction, but to manufacture the authority that makes a separate, conventional instruction credible. The synthetic media appears in a trust-establishing interaction — a meeting, a call, a briefing — and the payment request arrives afterwards through an ordinary channel such as email, a phone call or a messaging app.
This distinguishes it from the better-known deepfake fraud pattern, in which a cloned voice or face directly instructs a transfer. Both are impersonation, but they fail different controls. Direct-instruction attacks can in principle be caught at the point of payment authorisation. Authority attacks cannot, because at the point of payment there is nothing synthetic left to detect. The relevant artefact existed days earlier, in a meeting that no financial control was watching and that typically leaves no retained recording.
The Singapore case is a clean example. The fabricated Zoom conference established that a funding request connected to the Strait of Hormuz was genuine and sanctioned at the highest level of government. The transfer instruction that followed came from a person claiming to be a lawyer, promising reimbursement within 15 days. Had the victim's bank screened that instruction with perfect synthetic-media detection, it would have found a real human making a real request — and the S$4.9 million would still have left.
The three Codes of Practice, and what they designate
The August 2026 package is a substantial piece of regulation, and the analysis below is not an argument that it is weak. It is an argument about coverage. The critical structural fact is that obligations under the Online Criminal Harms Act attach to designated services, named individually. A service that is not designated carries no obligation, however similar it is to one that is.
Table 2: The three Codes of Practice issued by the Singapore Police Force on 17 August 2026, as set out in the SPF release.
Read that middle row again. The code is titled for messaging and conferencing. It designates two conferencing services: Apple FaceTime and Google Meet. It does not designate Zoom — the platform inside which Singapore's largest documented deepfake fraud was staged, and the platform whose logo appears, partially obscured, in the footage the police themselves released. We verified the designated list against the SPF release and independently against trade coverage of the same announcement; both give the same seven services.
There may be a defensible administrative reason for this. Designation under the OCHA appears to follow measured scam volume on a service, and Zoom does not feature in the SPF's own breakdown of contact methods. That is a coherent basis for a designation regime. It is also precisely the mechanism by which the channel used in the largest single loss ends up outside the instrument.
The penalty question: S$1 million or S$10 million?
Sources conflict on the maximum penalty, and rather than pick one we set both out. The conflict is not a reporting error so much as two regimes being described in the same documents.
Table 3: The two penalty tiers described in the August 2026 material. Which applies at the 31 January 2027 deadline is not resolved on the public record we could read.
For a compliance reader the practical answer is that the difference is unlikely to change behaviour. Both tiers are large enough that a designated platform will treat the deadline as real, and the daily continuing-offence component in either version is the part with teeth. We flag the discrepancy because a post that names real penalties on real companies should not quietly round them.
Mapping the codes onto the attack chain
With the designated lists established, the codes can be mapped stage by stage against the chain that produced the S$4.9 million loss. The result is not uniformly negative, and the one green row matters.
Which of the three new codes reaches which stage of the attack
The Codes of Practice issued on 17 August 2026 designate named services, and their obligations attach to those services only. Mapped against the six stages of the S$4.9m chain, the codes land squarely on stage 1 and miss everything after it. Watch stages 3 and 4 — the pretext and the deepfake itself both travelled over channels that no code designates.
Facebook · Instagram · TikTok
7 designated services
Carousell · FB Marketplace · FB Business Pages
One row is green. The anti-spoofing requirement genuinely targets stage 1, and it is the earliest deadline in the package — 30 September 2026. Everything the deepfake actually did happens in rows the codes do not reach.
Stage 1 is genuinely covered, and covered well. The attack opened with a WhatsApp profile impersonating the Secretary to the Cabinet. WhatsApp is a designated service, and the specific obligation to prevent spoofing of the Singapore Government through profile names and pictures is aimed exactly at that move. It also carries the earliest deadline in the whole package, 30 September 2026 rather than 31 January 2027, which suggests the SPF regards it as the highest-urgency item. On the evidence of this case, that judgment looks right.
After stage 1, coverage stops. No code addresses a victim signing an NDA and surrendering an identity document. Email, which carried the forged letter of guarantee, is designated by none of the three codes. Zoom, where the deepfake operated, is designated by none of them either. The transfer at stage 6 is a banking and anti-money-laundering matter addressed by different instruments entirely.
And the flagship measure — advertiser identity verification, the requirement that generated most of the coverage — maps to no stage of this chain at all, because there was no advertisement in it.
Volume-weighted regulation and the loss tail
The obvious response is that the codes were not written for this case, and that is correct. They were written for the distribution, and the distribution is dominated by advertising and social-platform contact. The SPF's own numbers make the case plainly: online platforms were used to reach victims in 84.1% of all scam cases in 2025, Meta platforms were involved in 35.4%, and Facebook alone accounted for 18.0%. Designating the highest-volume surfaces is rational.
It also works. The same brief reports that scam cases involving providers already designated under the OCHA “declined significantly by 36.5%” in 2025, while total scam cases fell 27.6% to 37,308 and total losses fell 17.9% to about S$913.1 million. This is an instrument with evidence behind it, which is rarer in platform regulation than it should be.
The problem is what volume-weighting does to the tail.
Table 4: Contact methods used by scammers in 2025, from the SPF Annual Scam and Cybercrime Brief 2025, mapped against the designated-service codes. Email accounts for 934 of 37,308 scam cases; video conferencing does not appear in the breakdown at all.
Email carried the forged government guarantee in this case, and email accounts for 934 of 37,308 scam cases — 2.5% of the total. Video conferencing does not appear in the SPF's contact-method breakdown as a category. On volume, both are rounding errors. On this single case, they carried roughly half a percent of the entire nation's annual scam losses into one corporate bank account.
That is the structural point. A designation regime driven by case counts will always be strongest where losses are numerous and small, and weakest where they are rare and enormous. The two are not the same problem and they do not respond to the same control. Government officials impersonation scams illustrate the divergence: the brief records that the number of cases “more than doubled, by 123.6% to 3,363 cases in 2025, from 1,504 cases in 2024” while the amount lost “increased significantly by 60.5% to about $242.9 million in 2025, from about $151.3 million in 2024” — the second-highest loss of any scam type, in a year when scams overall were falling on both counts.
Note also what the same brief says about how those scammers made contact: “Phone calls and WhatsApp were the most common channels used by government officials impersonation scammers to contact potential victims,” with impersonation through calls accounting for 91.7% of cases in one of the two notable 2025 variants. The Zoom case is a channel outlier inside the very category that is growing fastest. Outliers in a growing category are not usually the last of their kind.
Why the artefacts the police published are the wrong layer to defend at
The SPF's 3A advice asks the public to analyse audio-visual elements — in practice, to notice the three artefacts named in the advisory. As public guidance for an attack already in progress, that is reasonable and better than nothing. As a control, it has a short lifespan, and it is worth being specific about why.
Table 5: The three artefacts named in the SPF advisory of 16 May 2026, and how durable each is as a detection signal.
Two of the three are cosmetic and will not survive the next iteration. Advice built on them expires with them, which is the recurring problem with teaching people to spot fakes by eye: the advice is public, so the attacker reads it too, and the specific tells named in a police advisory become a checklist of things to fix. The rate at which they get fixed is not uniform either — some generators are already considerably harder to detect than others, and the cosmetic tells disappear first because they are the ones users complain about.
The middle row is different in kind. Single-account audio for a multi-party conference is not a flaw in the fake; it is a consequence of how a fake conference has to be delivered. Signals of that type — stream topology, per-participant endpoint behaviour, whether the audio and video for a given speaker plausibly originate from the same device — are expensive to defeat because defeating them means building the thing rather than rendering a picture of it. This is the layer worth instrumenting, and it sits with the conferencing platform and the enterprise, not with the individual squinting at a screen. Per-participant stream analysis of the kind DuckDuckGoose's DeepDetector and Waver perform on video and audio respectively is only useful if something is actually watching the call, which today almost nothing is.
This is the same structural argument that applies to injection attacks that feed synthetic video directly into a verification pipeline: the durable signals are the ones tied to how the media had to be delivered, not to how convincing it looks. It is also why the artefacts generators miss are more interesting than the artefacts they currently produce.
What this means for banks, IDV providers and enterprises
Three practical implications follow, and none of them is “buy detection for your payment flow”.
The regulated surface is not the exposed surface
If you operate in Singapore, your compliance obligations from 31 January 2027 concern advertising on three named platforms. Your exposure concerns whatever channel your counterparties actually use to establish trust before instructing payments. For most organisations those are different sets, and the second is larger. Treating the code as a map of your risk is a category error — it is a map of three platforms' obligations.
Authority attacks defeat payment-time controls by construction
Because the synthetic media appears in a meeting rather than in an instruction, controls placed at authorisation cannot see it. The control that works is out-of-band verification of the authority, not the instruction: an independently sourced callback to the organisation supposedly making the request, through a number or channel obtained independently of the request itself. In this case that would have meant calling a published government line rather than the lawyer. The NDA at stage 2 exists to make exactly that step feel like a breach of confidence, which is a good reason to make it mandatory and non-discretionary rather than encouraged.
Video conferences are now an unmonitored high-trust channel
Organisations log email, screen advertising, monitor payment flows and increasingly verify identity at onboarding through video KYC flows that are themselves under attack. Almost nobody applies any assurance to an ad-hoc video call, which is precisely why the channel is attractive. The gap is not that the technology to check a call does not exist; it is that a call is treated as self-authenticating in a way no other channel has been for twenty years. The relationship between what a liveness check proves and what deepfake detection proves is worth understanding before assuming an existing control covers this — they answer genuinely different questions.
The regulatory direction of travel supports this reading rather than contradicting it. Singapore's trajectory — two Implementation Directives to Meta, then a code with pre-publication advertiser verification — is a move from post-hoc takedown toward identity assurance before publication, which is the same direction deepfake regulation is moving generally and consistent with the transparency architecture in AI Act Article 50 and eIDAS 2. The Warsaw Court of Appeal reached a comparable conclusion about pre-publication inspection of advertising in the Brzoska litigation against Meta, and the Sapphire Network investigation traced an industrial deepfake ad supply chain in which every existing control fired only at the final stage. Singapore's codes are the strongest attempt yet to move that control upstream. They just move it upstream on the advertising surface, and this attack was not on the advertising surface.
Claim-level provenance
Because this article names heads of state, a named regulator, named platforms and a specific loss figure, here is where each load-bearing claim comes from and whether we read the document ourselves. Claims we could not verify to primary standard are marked as such rather than smoothed over.
Table 6: Provenance for each load-bearing claim in this article. Four separate Singapore Police Force documents were read directly.
What to do now
- Make out-of-band verification of authority mandatory, not encouraged. Any payment instruction that traces back to a meeting, briefing or call requires an independently sourced callback to the requesting organisation before authorisation. Independently sourced means the contact details do not come from the request.
- Write NDAs out of the verification exception. A confidentiality request is not a reason to skip verification. Say so in the policy, because attackers rely on the ambiguity.
- Treat ad-hoc video calls as an unassured channel. For any call that could originate a financial or legal commitment, establish beforehand how participants will be authenticated, and prefer scheduled invitations through your own tenant over links arriving by message or email.
- If you are a designated platform, read the deadline as two deadlines. Anti-spoofing lands 30 September 2026; the advertiser-verification and MAS licensing gate lands 31 January 2027. The earlier one is the one aimed at the opening move in this case.
- Do not read the code as a risk assessment. It designates three social platforms, seven messaging and conferencing services and three marketplaces. Your exposure includes every channel that is not on those lists, starting with email and ad-hoc conferencing.
Frequently Asked Questions
How much was lost in the Singapore deepfake Zoom scam?
At least S$4.9 million, roughly US$3.8 million, from a single victim, with the final transfer made on 14 May 2026. The figure is consistent across the South China Morning Post, Mothership and VnExpress International. The Singapore Police Force advisory describes the scam but does not itself state the amount.
Which officials were impersonated in the deepfake Zoom call?
According to the Singapore Police Force, the fabricated conference featured impersonations of the Secretary to the Cabinet, Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah and representatives of the Monetary Authority of Singapore, alongside figures presented as Canada's foreign minister, a senior adviser to the President of the UAE, and executives of BlackRock and the Dubai International Financial Centre.
What do Singapore's new Codes of Practice require, and when?
The Social Media Code requires Facebook, Instagram and TikTok to verify advertiser identity against Government-issued records, to block financial-services advertising from advertisers not licensed by the Monetary Authority of Singapore, and to prevent and remove suspected scam advertising, by 31 January 2027. A new Messaging and Conferencing Code covering seven services requires prevention of Singapore Government spoofing through profile names and pictures by 30 September 2026. An enhanced E-Commerce Code covers three marketplace surfaces.
Would the new codes have prevented this scam?
Only its opening move. The attack began with a WhatsApp profile impersonating the Secretary to the Cabinet, which the anti-spoofing requirement targets directly. Everything after that fell outside the codes: no code designates email, which carried the forged letter of guarantee, and Zoom — where the deepfake operated — is not among the seven designated messaging and conferencing services. The advertiser-verification requirement that received most of the coverage is not engaged at all, because no advertisement was involved.
How can a deepfake video call be detected?
The Singapore Police Force named three artefacts in the footage it released: audio not synchronised to lip movement, all speech broadcast from a single account rather than from each participant, and a distorted background with a partially obscured platform logo. The first and third are cosmetic and cheap for an attacker to remove. The second reflects how a fabricated conference has to be delivered — only one endpoint genuinely connects — and signals of that kind, tied to stream topology rather than image quality, are considerably more durable. Detecting them requires something to be analysing the call, which for most organisations is not currently the case.
Were there any arrests?
Fintechnews Singapore reported in May 2026 that two Singaporeans were arrested in connection with facilitating the corporate bank account used to receive the funds. We found this in one outlet only and have not seen it confirmed by a police release, so it should be treated as unconfirmed.
Methodology and sources
Four Singapore Police Force documents were read directly: the advisory of 16 May 2026 on the fabricated Zoom conference, the release of 17 August 2026 issuing the three Codes of Practice, the Annual Scam and Cybercrime Brief 2025 in full, and the accompanying Police Life summary. Every statistic attributed to the SPF in this article was taken from those documents rather than from reporting about them, and the figures quoted in quotation marks are verbatim.
The loss figure, the attack chain details not covered by the police advisory, and the reported arrests come from named news sources, each of which we opened and read. Where sources disagree — the applicable penalty cap — both readings are presented rather than one being selected. Where a claim rests on a single outlet — the arrests — it is labelled as unconfirmed both in the body and in Table 6.
DuckDuckGoose has not analysed the footage released by the Singapore Police Force. No detection output, confidence score or artefact finding in this article is ours; the three artefacts discussed are the ones the SPF published, and the analysis of their durability is an argument about attacker cost, not a detection result.
Last update: Q3 2026.














