Singapore company CFO nearly loses S$120,000 after scammers impersonate bosses on Teams

A Microsoft Teams screen on a smartphone illustrates how scammers exploit workplace trust — and the instinct to follow instructions from senior bosses. — Unsplash pic
By Malay Mail
First Published: Saturday, 19 Sep 2026 1:36 PM MYT
SINGAPORE, Sept 19 — A healthcare company’s chief financial officer nearly transferred S$120,000 (RM384,000) to scammers after they impersonated the firm’s chairman and managing director on Microsoft Teams.
The attempted fraud came amid a sharp rise in business e-mail compromise scams in Singapore, with losses reaching S$57.3 million (RM183.4 million) in the first half of 2026, up from S$19.5 million (RM62.4 million) a year earlier.
“Everything happened so quickly. The scammers acted with a sense of urgency that made my colleague anxious to get the job done,” Jane (not her real name), one of the company’s directors, was quoted as saying by The Straits Times in a report published today.
“The instruction was just to ‘do it now’,” the 72-year-old added, stressing that the urgency made it difficult for her colleague to stop and question the instructions.
According to the newspaper’s report, the incident began when the company’s chief financial officer was asked by people posing as the chairman and managing director to submit the firm’s financial statements through a Teams group chat.
The scammers then instructed her to transfer S$120,000 from the company’s bank account, but she only realised she had been tricked after speaking to the real managing director, who denied giving the instruction.
The fraudsters sounded legitimate and communicated well in English, making the request appear more convincing.
“When instructions appear to come from the two most prominent figures in the company, how do you reject that request?” Jane asked.
The company’s payment protocol ultimately prevented the loss, as payment slips had to be physically signed before any bank transfer could be authorised.
“If not for that, the S$120,000 would have been lost. And the scammers’ next request may be for a larger amount,” she said.
The company then instructed UOB to monitor large transactions and ensure transfers were made only after proper authorisation.
UOB branch manager Carlene Lam said she contacted the bank’s Risk and Anti-Fraud teams after Jane reported the incident to assess what had happened and put safeguards in place.
“I assured Jane that safeguards were in place and contacted my colleagues in the Risk and Anti-Fraud teams to assess the incident and take the necessary precautions to protect Jane’s organisation, including verifying all payment instructions,” she was quoted as saying.
UOB head of group compliance Daniel Ng said such scams had evolved beyond conventional e-mails, with criminals increasingly using messaging, voice and video platforms to impersonate trusted executives.
“Scammers increasingly exploit messaging, voice and video channels – including AI-enabled impersonation – to pose as trusted executives and trick employees into making fraudulent fund transfers,” he told The Straits Times.
“As these scams become more sophisticated, businesses should treat unexpected or urgent payment instructions with caution and independently verify them through established channels before acting,” he added.
Singapore police recorded 262 business e-mail compromise cases in the first six months of 2026, up from 156 in the same period last year, making it the third-largest scam category by amount lost.
The scams typically involve criminals impersonating suppliers, vendors, clients or senior executives to trick employees into transferring company funds to fraudulent bank accounts.
Adrian Hia, managing director for Asia Pacific at cybersecurity firm Kaspersky, said the scams were particularly effective because they exploited familiar communication channels and workplace hierarchies.
He said employees could be less likely to question requests from senior executives, particularly when they were framed as urgent.
“Essentially, the authority associated with a high-ranking executive can work to reduce a recipient’s level of scrutiny and encourage immediate action rather than verification. Business e-mail compromise attacks succeed not only because of technical deception, but because they leverage authority and social workplace expectations,” he was quoted as saying.
Hia said warning signs included unexpected payment requests, particularly those outside established procedures.
Requests to transfer money to new or unfamiliar bank accounts, or where payment details differ from previous transactions, should also be independently verified.
Other red flags include instructions to bypass standard approval procedures or keep the request confidential, as well as unusual sign-in links, unsolicited attachments and unexpected login prompts when opening files.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.