An iMessage can appear to come from DBS or Shopee and warn that a purchase is still pending. It gives you a phone number and suggests that a fraud investigator can fix it.
The message is designed to make a phone call feel safer than ignoring the alert. The person who answers then turns a routine transaction question into a request for card details, one-time passwords, or account access.
Singapore Police warned about this exact impersonation pattern in September 2026. The names in the message may change, but the call-back trap stays the same.

Overview
The alert uses a transaction you might recognize
The iMessage claims that a DBS card payment or Shopee order is pending. It may say that the transaction was blocked, that a purchase needs verification, or that an account is at risk. The wording is deliberately vague so that a recipient can connect it to a recent purchase.
DBS and Shopee are familiar names in Singapore. Seeing either one in a message gives the warning a reason to be opened before the recipient has time to check where it came from.
The message is not a confirmation from the bank or the marketplace. It is an opening move that tries to make the victim call a number controlled by the criminals.
The hotline is the real phishing page
The scam does not always need a website. The phone call supplies the conversation that a fake form would normally provide. The person on the line can sound calm, quote a transaction amount, and transfer the call to a supposed security team.
That performance matters because the victim is no longer looking at an unfamiliar URL. They are speaking with someone who appears to know the bank or the order and who can answer questions quickly.
Scammers can also use hold music, a ticket number, or a scripted transfer. These small touches are cheap to imitate and make the call feel like a larger support operation.
Card details and OTPs complete the theft
Police said the callers asked for card information and one-time passwords. A victim may be told that the code is needed to cancel a payment, secure the account, or confirm identity. In reality, the code can authorize the transaction the criminal is trying to make.
The final loss can include unauthorized card purchases, new logins, wallet enrollments, or further attempts against the victim’s bank account.
Because the conversation is live, the criminal can adjust the story when the victim hesitates. They may apologize for a delay, quote a new transaction reference, or offer to connect a supervisor.
The extra detail is not proof of account access. It is a way to keep the victim from ending the call long enough for the operator to test the information already provided.
- An unsolicited iMessage claims that a DBS or Shopee transaction is pending.
- The message supplies a fraudulent hotline instead of directing you to the official app.
- The caller asks for a full card number, expiry date, security code, or OTP.
- The caller creates urgency by saying the transaction will complete unless you act now.
- The same script can be reused with different brands, amounts, and phone numbers.
- The victim is kept on the line while the criminal tests the stolen details.
- A follow-up caller may claim to be from a bank, police unit, or card security team.

Why the DBS and Shopee Message Feels Official
The brands are placed next to a believable problem
A pending card purchase is a normal event. Online marketplaces also send order and payment updates, so the combination of a brand name and a transaction warning feels familiar. The criminal does not need to invent a complicated story.
Even a person who has not used Shopee recently may worry that somebody used their card. That concern encourages a call, which is exactly where the scammer wants the conversation to move.
iMessage makes the contact feel personal
People often treat a message delivered through Apple’s messaging system as a direct contact rather than a mass campaign. The sender name or thread can still be spoofed. A familiar interface does not prove that the message came from the named organization.
The message can also arrive beside legitimate conversations, which makes the warning look less like a random advertisement. The delivery channel is being used to borrow trust from the application.
A phone conversation defeats quick link checks
Many people know to look for a suspicious domain in an email. A phone number does not offer the same obvious visual clue. The caller can keep the victim moving through instructions before they think to find the bank’s real number.
The criminal may tell the victim not to hang up because the transaction is being reversed. That prevents an independent call and gives the operator time to use each new detail.
Company and Checkout Checks
The name in the message is not authentication
DBS, Shopee, and other brands can be typed into a sender field by anyone. Do not use the number or link supplied by an unexpected message. Open the official mobile app yourself and inspect recent activity there.
The number is part of the criminal infrastructure
A scam hotline may forward to a small call center, a disposable voice account, or an operator working from a script. A professional greeting and background music do not change who controls the line.
The caller has no reason to request an OTP
A bank employee should not ask you to read a one-time password aloud so a payment can be cancelled. The code exists to authorize an action. If it is read to a stranger, the stranger may be the party authorizing that action.
The real account is the independent source of truth
Check the transaction in the official bank or shopping application. Type the known web address yourself if a browser is necessary. If the app shows no alert, end the call and report the message through an official channel.
How the Fake DBS and Shopee iMessage Scam Works
Step 1: The scammer sends a pending-transaction warning
The first message says that a DBS card payment or Shopee transaction is awaiting confirmation. It may include a precise amount, a short deadline, or language about suspicious activity. Those details are chosen to make the event sound like a real fraud alert.
The sender does not need access to the victim’s account. A broad campaign can mention a common brand and wait for recipients who recognize the name or fear that their card has been used.
Step 2: The message supplies a fraudulent hotline
Instead of asking the recipient to open the official app, the message says to call a phone number. The number may be formatted like a local support line or may be described as a fraud department.
Making the phone call the next step moves the victim into a private conversation. It also prevents the victim from seeing the real account status before the criminal begins asking questions.
Step 3: An operator confirms the invented transaction
The caller repeats the brand, amount, or order information from the message. They may say that the payment is being attempted from another device and that immediate verification is required.
A second operator can join as a supposed bank investigator or Shopee specialist. The hand-off is meant to make the call sound like a real internal escalation, not a single person reading a script.

Step 4: The caller collects card information
The criminal asks for the card number, expiry date, and security code. They may request the cardholder’s name, identity number, or address to make the verification sound complete.
Some victims are told that the card will be temporarily blocked. That claim lowers resistance because the victim thinks the details are being collected to prevent a loss rather than to make one.
If the caller asks you to move money to a safe account, end the call. A bank will not protect an account by asking a customer to transfer funds to a stranger’s account or cryptocurrency wallet.
Do not read a full identity number or banking password over the phone either. The request may expand after the first card details are supplied, especially if the operator believes the victim is still cooperative.
Step 5: A real OTP or app prompt arrives
After the card details are entered into a real transaction, the bank can send a one-time password or an approval request. The caller says the code is needed to cancel the pending payment or unlock the account.
Reading the code aloud can authorize the criminal’s purchase. The caller may remain silent while the code is used, then tell the victim that the reversal is processing.
Step 6: The victim is kept on the line while the account is tested
The operator can ask for another code, suggest that the first attempt failed, or claim that a replacement card is required. The delay gives the criminal time to test the details, add a wallet token, or attempt another login.
When the call ends, the victim may receive a real bank notification. That notification is often the first clear sign that the supposed investigator was the person creating the transaction.
Warning Signs of the DBS and Shopee Call-Back Scam
- The message arrives without any matching alert in the official bank or marketplace app.
- The sender tells you to call a number included in the message.
- The caller asks for a full card number or security code.
- The caller asks you to read an OTP or approve a phone prompt.
- You are told not to hang up or to keep the call secret.
- The caller claims that a code will cancel a transaction.
- The script changes from DBS to Shopee, police, or another security team during the call.
- The caller asks for a second card when the first transaction is supposedly blocked.
What to Do if You Have Fallen Victim to This Scam
- End the call and stop sharing information. Do not read another OTP and do not install software at the caller’s request.
- Call the bank using an official number. Use the number on the back of the card or inside the bank’s genuine app, not the iMessage number.
- Ask for an immediate card freeze and replacement. Tell the bank that card details and a one-time password may have been exposed.
- Review every recent transaction and wallet token. Ask whether a new device, digital wallet, or unfamiliar login was added.
- Secure connected accounts. Change passwords for email, shopping, and banking services, then enable strong two-factor authentication.
- Preserve the message and call evidence. Save screenshots, the phone number, times, caller claims, bank alerts, and transaction references.
- Scan the device if anything was installed. Malwarebytes can check for malicious or unwanted software. AdGuard can help block known phishing domains and deceptive redirects if the message also contained a link.
- Report the impersonation. Notify the bank, Shopee, your mobile carrier, and Singapore Police or the relevant local fraud authority.
- Watch for recovery scams. A person who promises to recover the money for an upfront fee may be using details from the first call.
Frequently Asked Questions
Did DBS or Shopee send the iMessage?
No. Singapore Police described messages that impersonated DBS fraud investigators and Shopee support. The brands in the message are being used to make the hotline seem trustworthy.
Why would a caller need my OTP?
A legitimate support agent should not ask you to disclose an OTP. The code can authorize the transaction the criminal is attempting, even when the caller says it will cancel a payment.
What if the caller knew my name?
A name or order detail does not prove the call is genuine. Information can come from data brokers, previous leaks, public profiles, or details supplied during the call.
Can I trust the phone number because it looks local?
No. Local formatting is easy to copy, and a displayed caller ID can be manipulated. End the call and dial the official number yourself.
What if I only answered and gave no details?
End the call, block the sender and number, and monitor your accounts. Report the message so the bank and carrier can connect it to the wider campaign.
What is the safest way to check a pending transaction?
Open the official bank or shopping app from your normal device and review the transaction there. Never use a number or link supplied by an unexpected message.
That independent check is safer even when the message happens to mention a purchase you made. A real transaction will remain visible in the account you control, without requiring a stranger to guide you.
The Bottom Line
The fake DBS and Shopee iMessage scam turns a familiar transaction warning into a live phone conversation controlled by criminals. The brand name is only the bait.
A real bank or marketplace will not need you to read a one-time password to a stranger on a number from an unsolicited message. Check the account through the official app instead.
If you shared card details or an OTP, contact the bank immediately. Speed matters because the operator may still be testing the information while the call is in progress.