You received a message that came from your bank telling you to verify your information. You clicked a link, was assured that your details will be kept confidential, and followed the instructions as directed. A few hours later, to your horror, a large sum of money is gone from your bank account. What can you do now?

Your first thought might be that nothing can be done. Like you, many scam victims immediately believe that once a transaction has been authorised and processed, there is nothing further that can be done to recover the money lost.

Fortunately, however, that is not always the case.

In Singapore, there are certain rules that determine who should bear scam-related losses. These include the E-Payments User Protection Guidelines (“EUP Guidelines”) and the Guidelines on Shared Responsibility Framework (“SRF Guidelines”). Under these guidelines, there are certain situations where it is the bank or the telecommunications provider (“Telco”) that should bear at least a portion of the scam-related loss instead of the bank account holder.

This article will cover when this is the case, when the law may be on your side, and the practical steps you should take once you realise that you may have fallen victim to a scam.

What should I do as soon as I discover the scam?

  • Contact the responsible Financial Institution (“FI”) immediately

      Most FIs like banks or non-bank payment service providers such as Grab or PayPal provide a “kill switch” or similar feature that allows you to quickly block further access by the scammer to your account.[1] This should be activated without delay.

      • Maintain all relevant records

      You should begin to accumulate and keep all the records and evidence related to the scam. This may include text messages, links, screenshots and transactions. Make sure that you capture details of the scam transaction as well, including information such as the affected bank account number, the recipient (whether by name or other credentials) and the transaction amount.

      Maintaining the relevant records and evidence of the scam transaction will help the FIs, the police and your lawyers understand the nature of the incident and how best to assist you.

      • Lodge a police report as soon as possible.

        Call 999 to lodge a police report as soon as practicable. Avoid using the online e-service to lodge your report, as it expressly states that the online e-service is most suitable for crimes that do not require immediate police action. You may also report the scam via the 1799 ScamShield Helpline.

        You may also refer to the ScamShield website for important information to include in the police report. This would include, among other things, the following types of information:

        • Details of the scam (e.g., date, time, mode of contact used, scammer’s contact information)
        • Supporting Evidence (e.g., screenshots of any messages or emails, documents such as receipts or invoices)
        • Reports to other organisations (e.g., mention if you have reported the scam to other authorities such as your bank, reference numbers of these reports)
        • Additional information (e.g., descriptions of the scammer, name/alias used, physical appearance, and steps you have taken to prevent further losses such as freezing accounts)

        What should I do next? What are the next steps?

        The 4 Stage Workflow recommended in the Guidelines provides a useful framework.

        1. Claim Stage

        You should first file a formal claim with your bank no later than 30 days after the initial notification alerts had been sent, coupled with the necessary information stipulated in Section 3.18 of the EUP Guidelines.

        The communication records must sufficiently demonstrate that (1) the scammer impersonated an entity, (2) intended to obtain your account credentials under false pretences and (3) directed you to a digital platform to enter your account details. This is required to establish the presence of a Seemingly Authorised Transaction.[2]

        1. Investigation Stage

        Next, the responsible FI will assess the claim, specifically, whether or not it involved a Seemingly Authorised Transaction.

        Where the claim is found to have involved a Seemingly Authorised Transaction, the FI will assess whether the loss arose from a scam involving impersonation. If the scam was perpetrated through SMS, the FI will refer the matter to the responsible Telco and they will investigate concurrently whether they have fulfilled their respective duties. Otherwise, the FI will investigate independently regarding their duties.

        When the claim does not involve a Seemingly Authorised Transaction, the FI will simply investigate according to its existing processes for unauthorised transactions.

        This investigation should be completed within 21 business days for straightforward cases or 45 business days for complex cases, such as ones where any party to the transaction is overseas and uncontactable during the investigation period.[3]

        1. Outcome Stage

        The responsible FI must then send you a written reply of the investigation outcome and the assessment of your responsibility as the account holder in the situation. The responsible FI will also be required to seek your acknowledgement of the outcome.

        If it is found that the FI breached its duties in the SRF Guidelines, the responsible FI is expected to bear the loss in full. If the Telco has breached its duties, the Telco is expected to bear the loss in full. Only in the event where neither the FI nor the Telco has breached their duties would the consume bear the loss in full.

        As a result, it is not always that the consumer must bear the loss in full. In this respect, it is recommended that you seek independent legal advice which may provide you with guidance on any potential breaches of the FI or Telco.

        1. Recourse Stage

        If you disagree with the assessment, or if the responsible FI has assessed that your claim falls outside the Guidelines, you may complain to the Monetary Authority of Singapore (“MAS”) or appeal to FIDReC. FIDReC’s assessment will include non-SRF related obligations, such as obligations under statute, common law, or duties under the EUPG.

        If you disagree with the Telco’s assessment of responsibility, you may write to IMDA, which will assess whether the responsible Telco has breached its duties under the SRF Guidelines.

        Note that if you dispute a transaction, the responsible FI must pause any related fees or penalties and must not report you to credit bureaus while they investigate. Further, they must clearly explain any charges or costs that may apply to the recovery of the unauthorised transaction amount.

        Will I have to bear the losses?

        As briefly described above, whether you will have to bear the loss depends on the type of transaction involved, namely authorised or unauthorised, and whether the relevant parties complied with their duties under the Guidelines.

        For unauthorised transactions, victims will generally not be required to bear the loss if the scam arose from any fraud, negligence, or failure on the part of the bank. This includes the bank’s employees, agents, or service providers, or the bank’s non-compliance with regulatory or security requirements imposed by the MAS. Even in situations where the loss is caused by an independent third party and the account holder has complied with their obligations, the bank is still expected to bear the loss. In such situations, account holders are also protected from liability for the first S$1,000 of loss.

        For Seemingly Authorised Transactions, victims may still be protected if the loss arose from the bank’s failure to comply with its duties under the Guidelines, including safeguards against fraudulent transactions, or from any action or omission by the bank that contributed to the loss.

        If the scam was carried out through SMS phishing, responsibility may instead fall on the telecommunications provider if the bank has fulfilled all of its duties and the loss arose from the telco’s failure to meet its own obligations under the Guidelines. Importantly, if the bank is required to bear the loss, it must do so even if the telco also failed in its duties. In cases where the phishing SMS was received on a mobile number that does not belong to the account holder, the telco may still be responsible if that number was designated to receive bank SMS alerts and the SMS directly led to the scam and resulting loss.

        Conclusion

        Scams are getting more sophisticated day by day, and it is not always easy to differentiate scams from genuine transactions. Here at Eugene Thuraisingam Asia LLC, we understand that things may be challenging if you happen to fall victim to a scam. We are present and here to help you navigate this difficult time with our experience and expertise.

        For further enquiries, feel free to reach out to us at +65 6557 2436. Our experienced lawyers will assist you as soon as we can.

        We are grateful for the assistance of Kristen Magnus, Aisyah Nur Humyra and Mahalakshmi Perumal in preparing the first draft of this article.


        [1] EPU Guidelines at [4.14].

        [2] Page 5 of the SRF Guidelines, definition of “seemingly authorised transaction”.

        [3] EUP Guidelines at [4.26].


         

        Our experienced criminal defence lawyers, fraud lawyers in Singapore, and corporate investigations lawyers regularly advise and represent clients in scam-related matters, fraud investigations, and complex regulatory proceedings.

        Share the Post: