“Singpass Mules” trade their national digital identities for the promise of cash. They are often liable for aiding and abetting downstream crimes. Most recently, someone was convicted of funnelling ~S$1 million in verified scam proceedings via bank accounts set up with his Singpass details.[1]
In response to a rise in such events, Parliament introduced the Criminal Law (Miscellaneous Amendments) Act on 14th October 2025.[2] Under the changes to the Computer Misuse Act (“CMA”), mules who help launder scam proceedings or provide Singpass credentials face discretionary caning of up to 12 strokes. This is on top of imprisonment of up to 3 years and an SGD$10,000 fine.[3] This builds on the logic of deterrence in Goh Hai Shan v Public Prosecutor. There, District Judge Paul Quan (“DJ Quan”) emphasised the staggering sums and syndicate-like activity warranting a deterrent sentence.
The current law on Singpass retrieval is governed by the CMA.[4] Crucially, section 8A(1) (a) and (b) are read conjunctively. This means that where an individual discloses his Singpass password and knows/has reasonable grounds to believe that the purpose of his disclosure is for the commission of an offence, that individual would be liable for an offence under the CMA.
The addition of discretionary caning comes with a caveat. It is only a sentencing option if the offender was aware that the enabling tool (i.e., his credentials) would be used to facilitate the commission of a scam. Caning would also be used where the offender had not taken reasonable steps to ensure that his identity was not used to commit or facilitate the commission of a scam.
A. Reasonable steps the public can take to defend themselves
What then, are reasonable steps the defendant(s) could have taken? To illustrate this, we use the case of Goh Hai Shan v Public Prosecutor (“Hai Shan”). While Hai Shan was decided before the s 8A of the CMA was passed, we nevertheless analyse how discretionary caning could have been avoided in his instance.
Under the s 8A of the CMA, for Hai Shan to demonstrate “reasonable steps” taken, he ought to:
(i) Find out the identity of their purchaser of his data, and
(ii) Identify the purpose of their transaction.[5]
In addition, there is a conjunctive proviso (“(iii)”) in the same section to be read with (i) and (ii), which is that if Hai Shan fails to act on his suspicions, he would be liable for aiding and abetting downstream crimes.[6]
The law does not unduly punish those who have taken reasonable steps to avoid doing wrong. In a similar vein, if Hai Shan can prove that he took steps to achieve (i), (ii) and per (iii) act on his suspicions, he would be able to avoid caning, though not a conviction. More pertinently, he would have ensured that he was making a well-considered decision that would likely turn him away from trading his credentials for cash.
The threshold for “having reasonable grounds to believe” on Hai Shan’s part might seem low. Nonetheless, insofar as Singpass transactions are done over private messaging channels and not official government channels, they warrant a degree of suspicion. This is especially so if details are promised in exchange for monetary gain. It is submitted that the foremost solution to protecting oneself from Singpass scams is to simply not entertain the thought of selling one’s identity in exchange for cash, no matter how lucrative it might seem in the short run.
B. Being unaware of the risks regarding the transaction is an inadequate defence
In his defence pleadings, Hai Shan cited mitigating circumstances like being “unaware” of the risk, and “financial difficulties” which gave him the impetus to sell his Singpass details.[7]
Like Hai Shan, Singpass merchants might suggest they were not aware of the risks associated with their transaction. However, under s 8A (2) of the CMA, it is not necessary for the prosecution to prove that the user knew, or had reasonable grounds to believe, that the purpose was to commit or facilitate the commission of any specific offence.[8]
Furthermore, even if it was pleaded, wilful blindness is legally equivalent to actual knowledge.[9] Any attempts to negate the fault element (i.e., the intention or knowledge that one’s actions would aid in the commission of a crime) in Singpass scams would evidently be nipped in the bud.
That said, the law recognises the distinction between genuine belief and wilful blindness. It is for the accused to cast reasonable doubt on the Prosecution’s submission that their act was done on the basis of being wilfully blind.
This is detailed under s 8A (4) of the CMA,[10] which states that it is not an offence if the Singpass user had genuinely believed that the purpose of his disclosure was for a lawful purpose.
C. Mitigating circumstances like financial difficulty are inadequate to overwhelm the overarching motivation of human greed and self-interest
The law gives credence to everyone’s circumstances. Unfortunately, as in the case of Hai Shan, it is precisely those circumstances which might incentivise someone to commit an offence.
In Hai Shan’s case, DJ Quan held that his present commitments and debilitating financial circumstances made the courts less confident in holding that there is no residual need to specifically deter Hai Shan from re-offending. There is a latent possibility that he might resort to doing so to alleviate any financial challenges ahead.[11]
The courts further added that even if mitigating factors like good character, financial hardships, and familial commitments are pleaded, those who “act out of pure self-interest and greed will rarely be treated with much sympathy” by the courts.[12] Evidently, such mitigating factors are insufficient in justifying the commission of offences motivated by greed.
It was held that Hai Shan had turned a blind eye to the obvious risks associated with selling his Singpass credentials. According to DJ Quan, the promise of reward incentivised his ostrich mentality.[13] The ostrich mentality here refers to a cognitive bias, where one disregards evidence perceived as undesirable by “burying their heads in the sand” as ostriches apparently do.
D. Conclusion
In conclusion, selling one’s Singpass is illegal. Once your credentials are weaponised, you are exposed to offences under the Computer Misuse Act (“CMA”), and the abetment of downstream crimes. You might be liable even if you did not receive the funds promised in exchange for your Singpass.
Further, given the fact that scams have risen by almost 50% from 2023 to 2024,[14] and that peddling Singpass and bank accounts has deleterious effects that are hard to detect and difficult to prevent, it was held by DJ Quan that harsher, deterrent sentencing in these situations are warranted.[15]
The market might look lucrative, but the law makes it ruinous. Trade your Singpass, and you may be trading your liberty.
Written by: Shawn Yip Hong
Year 2 LL.B. Student
Singapore Management University, Yong Pung How School of Law
Edited by: Audrey Leong Wen Yi
Year 3 LL.B. Student
Singapore Management University, Yong Pung How School of Law
[1] Lydia Lam, “Man sold his Singpass details, which scammers used to funnel almost S$1 million through bank accounts” (29 July 2024) <https://www.channelnewsasia.com/singapore/man-sold-singpass-details-account-1-million-funnel-scam-proceeds-4511081> (Accessed 10 December 2025).
[2] Singapore Parliamentary Debates, Official Report (5 September 2025) vol 96 (K Shanmugam, Minister for Home Affairs).
[3] Fabian Koh, “Caning for scammers and mules on the cards, as Singapore looks to toughen criminal laws” (14 October 2025) <https://www.channelnewsasia.com/singapore/parliament-mha-scammers-caning-penal-code-law-bill-amendment-sim-ann-5400056?cid=internal_sharetool_androidphone_14102025_cna> (Accessed 10 December 2025).
[4] Ministry of Home Affairs, “Commencement of Amendments to the Computer Misuse Act and Corruption, Drug Trafficking, and Other Serious Offences (Confiscation of Benefits) Act” (7 February 2024) <https://www.mha.gov.sg/mediaroom/press-releases/commencement-of-amendments-to-the-computer-misuse-act-and-corruption-drug-trafficking-and-other-serious-offences-confiscation-of-benefits-act/> (Accessed 10 December 2025).
[5] Computer Misuse Act 1993 (2020 Rev Ed) s 8A(1).
[6] Computer Misuse Act 1993 (2020 Rev Ed) s 8A(3)(c).
[7] Public Prosecutor v Goh Hai Shan [2024] SGDC 178 at [25]-[29].
[8] Computer Misuse Act 1993 (2020 Rev Ed) s 8A(2).
[9] Nagaenthran a/l K Dharmalingam v Public Prosecutor [2019] 2 SLR 216 at [30].
[10] Computer Misuse Act 1993 (2020 Rev Ed) s 8A(4).
[11] Public Prosecutor v Goh Hai Shan [2024] SGDC 178 at [27].
[12] Lydia Lam, “Man sold his Singpass details, which scammers used to funnel almost S$1 million through bank accounts” (29 July 2024) <https://www.channelnewsasia.com/singapore/man-sold-singpass-details-account-1-million-funnel-scam-proceeds-4511081> (Accessed 10 December 2025).
[13] Public Prosecutor v Goh Hai Shan [2024] SGDC 178 at [18].
[14] Singapore Police Force “ANNUAL SCAMS AND CYBERCRIME BRIEF 2023” (2023)<https://www.scamshield.gov.sg/files/Scams%20and%20Cybercrime%20Briefs/2023_annual_scams_and_cybercrime_brief_infographic.pdf> (Accessed 10 December 2025).
[15] Lydia Lam, “Man sold his Singpass details, which scammers used to funnel almost S$1 million through bank accounts” (29 July 2024) <https://www.channelnewsasia.com/singapore/man-sold-singpass-details-account-1-million-funnel-scam-proceeds-4511081> (Accessed 10 December 2025).
-
Understanding the Rationale and Impact of the Sentencing Advisory Panel (SAP) Sentencing Guidelines for Scam-Related Offences
