Scammed Through a Phishing Link? How the Shared Responsibility Framework Works

By The Ledger desk · Last verified 28 September 2026

Since 16 December 2024, Singapore’s Shared Responsibility Framework has given banks and telcos set duties to protect customers from phishing scams. If your bank failed one of its duties, it bears the full loss. If the bank met its duties but your telco didn’t, the telco pays. If both met theirs, the loss is yours. The framework covers one kind of scam only: being tricked into entering your banking details on a fake website or app, leading to transactions you didn’t authorise.

Quick facts

  • In force since 16 December 2024, set by MAS and IMDA.
  • Covers banks, e-wallet providers and mobile network operators.
  • Covers phishing on fake digital platforms leading to unauthorised transactions.
  • Doesn’t cover malware scams or payments you authorised yourself.
  • Losses fall in order: bank first, then telco, then you.
  • Claims are investigated within 21 business days, or 45 for complex cases.

What does it cover?

Phishing scams where someone impersonates a legitimate business or government body and gets you to reveal your account credentials on a fake website or app, leading to transactions you didn’t authorise. It doesn’t cover malware scams, payments you made yourself (such as to a fake investment or a romance scammer), or phishing by non-digital means.

What must banks do?

  • Impose a 12-hour cooling-off period after a digital security token is activated or you log in on a new device, during which high-risk activities are blocked.
  • Run real-time fraud surveillance. If an account is being rapidly drained of a large sum, block the transactions until the customer confirms them, or notify the customer and hold them for 24 hours.
  • Provide a round-the-clock reporting channel and a self-service way to block access to your accounts immediately.

What must telcos do?

Among other duties, telcos must connect only to authorised aggregators for sending SMSes under registered sender IDs, which makes it harder for scammers to fake a bank’s name in your messages.

How do I make a claim?

Go to your bank, which is your single point of contact and coordinates with the telco. There are four stages: claim, investigation, outcome and recourse. Investigations take up to 21 business days for straightforward cases and 45 for complex ones.

What to do the moment you suspect a scam

  • Use your bank’s self-service kill switch or 24-hour hotline to block your accounts.
  • Make a police report.
  • Tell your bank everything: the link, the message, the times.
  • Keep screenshots of the messages and the fake site.

The WahLiao Verdict

The framework is a safety net with holes: if you authorised the payment, it won’t catch you. Never enter your banking details through a link in a message, and know where your bank’s kill switch is before you ever need it.

Questions people ask

I transferred money to a scammer myself. Am I covered?

No. The framework covers unauthorised transactions from phishing, not payments you authorised.

Does it cover e-wallets?

Yes, e-wallets issued by relevant payment service providers are covered, as well as full banks.

Why can’t I transfer money right after setting up a new phone?

That’s the 12-hour cooling-off period, one of the bank’s duties under the framework.

Who do I contact first?

Your bank or e-wallet provider, then the police.

Sources: Reed Smith on the framework’s scope and duties; Baker McKenzie on the fraud surveillance duty; Herbert Smith Freehills Kramer on the waterfall and claims; HSBC Singapore on bank duties. The Ledger explains; it does not advise.

Read next: Back to The Ledger

For what’s worth it this week, with the bill shown, read The WahLiao Week.