Fake FairPrice and Sheng Siong apps leave victims $403k poorer

Fake FairPrice and Sheng Siong apps leave victims $403k poorer
Images of the fake FairPrice Group app and a conversation between the victim and scammer.
PHOTO: Singapore Police Force

SINGAPORE - There is a variant of malware scams that involves fake Sheng Siong and FairPrice Group, the chain of supermarket and department stores, mobile applications, the police warned on Friday (Oct 6).

At least 11 victims have lost a total of $403,000 or more since September, the police added.

In such cases, victims would click on online advertisements - many of which are posted on Facebook - promoting food items such as rice, cookies and ducks.

The victim would then be directed to the WhatsApp messaging platform, where the "sellers" tell them to download an Android Package Kit (APK) - an app created for Android's operating system - over WhatsApp, so that the victims could place their orders. The victims may also be told to download the APK via third-party websites, instead of an official app store such as Google Play Store. The downloaded app would resemble the FairPrice Group or Sheng Siong apps.

Scammers can then access the victim's device remotely to steal banking credentials and passwords after the victim installs the APK file, as the installation includes granting the app accessibility services.

Victims would also be instructed to make a PayNow or bank transfer to pay for or make a deposit for their order, or to sign up as a member, or to pay for delivery. They would then discover unauthorised transactions from their bank accounts.

The police advised those who have already downloaded and installed such apps, or suspect that their phones are infected with malware to take the following steps:

  • Switch the phone to "flight mode". Ensure that Wi-Fi is switched off.
  • Run an anti-virus scan on the phone.
  • Check bank accounts, Singpass and CPF accounts for any unauthorised transactions via another device.
  • Report unauthorised transactions to the bank and relevant authorities, and lodge a police report.
  • Consider resetting your phone to factory settings and changing important passwords.

The police also urged the public to adopt the following measures:

  • Add the ScamShield and anti-virus applications to your device, and ensure its operating system and applications are updated regularly.
  • Disable "Install Unknown App" or "Unknown Sources" in your phone's settings and do not grant permission to pop-ups that request for access to your device's hardware or data.
  • Check for signs of scams with official sources such as the ScamShield Whatsapp bot, the Anti-Scam Helpline on 1800-722-6688 or visit www.scamalert.sg
  • Download and install applications from only official app stores, such as the Google Play Store for Android users. Be wary if you are asked to download unknown apps to buy items or services on social media platforms.
  • Report suspicious content or advertisements on social media sites. Block and report numbers linked to scams on Whatsapp.
  • Report fraudulent transactions to banks immediately.

Those with information on scams may call the police hotline on 1800-255-0000, or visit www.police.gov.sg/iwitness

For more information on scams, the public can visit www.scamalert.sg or call the Anti-Scam Helpline.

ALSO READ: Beware of malware: 43 people lose over $1.2m to travel package scams in September alone

This article was first published in The Straits Times. Permission required for reproduction.

This website is best viewed using the latest versions of web browsers.