I was scammed, and it started with an email that looked more legitimate than many genuine airline messages I had received.
My name is Adrian Tan Wei Kiat. I am 41 years old, and I work as a senior procurement executive. I live in Tampines, in the eastern part of Singapore, and I am the kind of person who watches for expiring rewards points, compares fares, and keeps screenshots of booking references. I had flown enough for work over the years to care about my KrisFlyer balance, even though my travel had slowed recently. On Tuesday, 14 May 2024, at 8:17 a.m., while on the MRT heading toward Raffles Place, I opened an email with the subject line: “Your KrisFlyer miles expire in 48 hours – redeem now.”
The sender name displayed as “Singapore Airlines KrisFlyer.” The branding looked correct. The email header used the familiar red and gold colour scheme. There was even a footer with what looked like customer service language and a notice about account security. The message told me that 62,800 miles in my account would expire in 48 hours unless I logged in and selected an eligible redemption option. There was a button that said “Review Expiring Miles.” I had a morning packed with supplier calls, and the message found me in exactly the right state: busy enough to act quickly, but not calm enough to verify slowly.
I tapped the button.
It opened a page that looked like a Singapore Airlines portal. The logo was sharp. The fonts were close enough to the real thing that I did not pause. The URL was not the familiar one, but on a phone screen I saw only the beginning and end clearly. It had “sia” and “krisflyer” in it, and that was enough for me in that moment. I entered my KrisFlyer membership number and password. The site then prompted me to “verify account ownership” by entering my mobile number, email address, date of birth, and a one-time password sent by SMS. I received an OTP almost immediately. I keyed it in.
Nothing happened for about five seconds, and then the page refreshed into what looked like a points redemption catalog. I remember seeing shopping vouchers, extra baggage, and lounge-related offers. It felt plausible. I was still standing in a train carriage with spotty attention and just enough urgency to keep going. I selected a S$50 voucher option, and then the site said I needed to link a payment card “for tax verification and account continuity.” That phrase should have stopped me, but it sounded administrative in the way many travel sites do. I entered my credit card details.
Over the next three weeks, the scam widened far beyond that first email.
At first, I thought I had simply had a technical issue. The fake portal displayed a spinning message saying, “Your redemption request is being processed. Please do not refresh while we validate your miles ledger.” I closed the browser and went on with my day. At 10:53 a.m., I got an SMS from my bank about a S$1 pre-authorisation transaction. I assumed it was linked to the card verification I had just done.
That evening, while having dinner with my wife and our daughter, I received another bank alert: S$486.20 charged to an online merchant I did not recognise. I opened my banking app and saw two more pending card-not-present transactions: S$928.50 and S$1,204.00. I froze the card immediately and called the bank. The officer said they would investigate, cancel the card, and issue a replacement. I was annoyed, but I still thought this was simply card fraud caused by a compromised website. I had not yet understood that I had handed over much more than card information.
Two days later, I tried logging in to my KrisFlyer account through the real Singapore Airlines website. My password no longer worked. When I used the password reset function, I did not receive the reset email. I checked spam, promotions, trash, everything. Nothing. I then searched my inbox and noticed a filter I had never created, automatically moving messages containing words like “verification,” “miles,” and “reset” into archive. That was the first moment my stomach dropped properly. Someone had probably used the details I entered to access my email or at least enough connected services to suppress alerts.
I spent that night changing passwords: email first, then banking, then Singpass-related connected services, then telecom, then every shopping platform and travel app I could remember. I enabled two-factor authentication wherever I could. I also called Singapore Airlines directly the next morning. The customer service officer told me there had been recent reports of fake emails involving expiring miles and imitation login pages. She could not discuss more than my account, but she confirmed there had been login attempts from unfamiliar devices and that some account details had been changed before the account was locked.
WARNING SIGN 1: The first red flag was the manufactured urgency of “48 hours to save your miles.” Real loyalty programmes do send reminders, but scammers rely on a short countdown because panic suppresses routine checks. I did not inspect the sender address, I did not type the official website manually, and I did not ask why an airline reward login would suddenly require my card “for tax verification.”
After I secured my email and cards, I believed the worst was over. I was wrong. On 21 May 2024, exactly one week after the first email, I received a call from a Singapore number. The caller introduced himself as “Daniel from the KrisFlyer account protection team.” He said my account had been flagged for suspicious redemption activity through a third-party session and that I needed to reverse “unauthorised miles extraction.” He spoke calmly, with no obvious pushiness. He knew my full name, my email address, and the fact that I had attempted to reset my password recently. That knowledge made him sound credible.
He explained that because my account had been “linked to a suspicious merchant acquisition flow,” the airline and the bank were coordinating a reimbursement pathway. He told me the fraudulent card transactions would bounce back, but I first needed to verify the bank accounts associated with my profile to prevent “duplicate refund conflict.” He sent me a link by SMS to what he called a secure validation form. It was another fake site, cleaner than the first and carrying both airline-style branding and generic financial-security language. I filled in details I should never have shared: my bank name, the last four digits of two account numbers, and eventually, after a series of prompts, my digital banking login credentials.
The site generated an error message and the caller said this sometimes happened when “payment rail synchronisation” failed. He then told me to log in directly to my banking app while he stayed on the line and confirm several test transactions which he said were “reversal tags.” Looking back, this was social engineering in its purest form. He was not hacking in front of me. He was coaching me into legitimising transfers while framing them as protective steps.
On that first call, I authorised a S$2,500 transfer to a local account, believing it was a temporary verification hold. He said the amount would be mirrored back within 30 minutes. It never returned. When I questioned him, he said delays could occur because of anti-fraud batching. He followed up twice that same day, sounding attentive and professional, even apologetic. He told me not to alert the bank yet because “premature fraud flagging can lock the recovery ledger before crediting.” I hate admitting that sentence worked on me.
Over the next 11 days, the losses mounted in pieces that were each small enough to rationalise but together devastating. On 22 May, I authorised two transfers of S$1,800 and S$3,200. On 24 May, another S$2,960. On 27 May, after he said my profile still showed a “duplicate beneficiary conflict,” I made S$4,000 through PayNow to a business-looking account name that he said was a “settlement node.” By then, my thinking had narrowed. I was no longer evaluating each instruction logically. I was trying to complete a process I wanted to believe was almost finished.
Every interaction was tailored to keep me compliant. If I sounded irritated, he became reassuring. If I hesitated, he invoked procedure. If I said I wanted to call back through the main hotline, he said I could, but warned me the ticket would “re-enter the general queue” and delay the release of both miles and funds. He sent reference numbers that looked official but were meaningless strings of letters and digits. He also emailed from an address that, at a glance, resembled a real corporate support address, except one character was swapped. On a laptop it might have been obvious. On my phone, in the middle of a workday, it was not.
Trust did not build because I was foolish. It built because each step borrowed the language and timing of real customer support. He called during office hours. He referenced my earlier account issue. He never asked for everything at once. He made the scam feel like administration, not theft.
According to [Singapore Police Force Anti-Scam Centre](https://www.police.gov.sg/Advisories/Crime/Scams), impersonation and phishing scams often use spoofed communications, urgent requests, and links to fake websites to harvest credentials and payment details. Reading that later was painful because it described my experience almost line by line.
WARNING SIGN 2: The second red flag was the follow-up phone call that arrived after the phishing link. Once scammers have your details, they often escalate into voice contact because a confident human voice can override the victim's lingering doubts. Any caller who asks you to transfer money, read out OTPs, or avoid contacting your bank is not helping you recover funds.
The breaking point came on 31 May 2024. I was at my desk in Shenton Way when my wife messaged me asking why our joint savings account balance looked lower. I opened the app and saw that another S$1,881.30 had gone out that morning. Total losses from transferred funds and unauthorised or unrecovered charges had reached S$18,460. That number is permanently etched into me because I wrote it over and over that day: on a notepad, in an email to my boss, in the online police report field, and in the reimbursement dispute form to the bank.
I finally ended the call chain, contacted my bank directly using the official number on the back of my card, and told them everything from the first email onward. The fraud officer asked a question that cut through the haze immediately: “Did anyone ask you to move money to keep money safe?” Yes, that was exactly what had happened. She told me to stop all communication, secure all devices, and make a police report at once.
I called the anti-scam hotline, reported the scam, and then spent the next six hours on damage control. Every online banking credential was changed. My cards were blocked. Beneficiaries were reviewed and removed. My email sessions were signed out across devices. I checked my phone for suspicious profiles and app permissions. I filed a report and forwarded the phishing email headers where possible. I also notified Singapore Airlines that a fake expiring-miles email had led to credential theft and downstream fraud.
The practical consequences lasted much longer than that one day. We had to postpone a family holiday we had planned for August. I cancelled tuition enrichment payments that were supposed to start for my daughter in July. For about two months, I kept waking at 3 a.m. to check whether another unauthorised transaction had appeared. I became hyper-alert to every SMS from the bank. At work, I made simple mistakes because my concentration was wrecked. I had to tell my manager why I needed time off for bank appointments and reporting. Saying it aloud made me feel small, although the people around me were kinder than I expected.
What embarrassed me most was how ordinary I am. I am not reckless with money. I do not chase random investment schemes. I know not to click suspicious links in theory. But the scam sat inside an ordinary habit: checking expiring miles. It exploited something I had done many times before. That is what made it dangerous.
I also learned how scammers benefit from layering. The fake email alone might have caused only a card compromise. The fake portal deepened the data breach. The follow-up call then converted confusion into bank transfers. Each stage fed the next. By the time I recognised the pattern, the scammers had already extracted enough information to sound informed and enough money to cause real harm.
According to [Singapore Police Force Anti-Scam Centre](https://www.police.gov.sg/Advisories/Crime/Scams), members of the public should verify communications through official channels, avoid clicking links in unsolicited messages, and use protective tools such as banking security features and anti-scam resources. I wish I had followed those steps in that exact order before I ever touched the “Review Expiring Miles” button.
One painful detail still stays with me: the scammers kept the amounts varied and believable. There was no dramatic single transfer of S$20,000 that might have forced me to stop. Instead there was S$2,500, then S$1,800, then S$3,200, then S$2,960, then S$4,000, then smaller card charges. The pattern mirrored the sort of staggered adjustments and holds that real institutions sometimes make, and that familiarity let the fraud breathe.
WARNING SIGN 3: The third red flag was being told not to contact the bank or use official hotlines because it might “interrupt the recovery process.” Real organisations do not isolate you from independent verification. The moment someone creates urgency and then blocks you from checking with the official source, you should assume you are being manipulated.
I have replayed the trust-building stage many times because that is the part people underestimate. The scammers did not flatter me or promise impossible rewards. They simply seemed competent. The first email arrived at a believable time. The portal echoed a service I genuinely used. The caller sounded like someone handling a back-office issue. Even the delays and errors felt realistic because real customer systems often do have delays and errors. That is why anti-scam advice can sound basic until you need it: type the website yourself, don’t trust a link, don’t give credentials to a caller, and never move money to “protect” money.
If you use airline loyalty programmes, especially in Singapore where many of us are used to efficient digital services, the trap can feel seamless. A fake expiring-miles alert is effective precisely because it piggybacks on an expected customer journey. Most people who travel regularly have, at some point, redeemed miles in a hurry. Scammers borrow that routine and compress your decision-making into a few distracted minutes.
Frequently Asked Questions
Q: can a fake KrisFlyer expiry email steal money from my bank account?
A: Yes. The email link can lead to a counterfeit login page that captures your credentials, card details, OTPs, and personal data. That information can then be used for card fraud, account takeovers, and convincing follow-up calls that pressure you into making transfers yourself.
Q: what should i do if i clicked a phishing link from a fake airline email in singapore?
A: Immediately change your email and banking passwords, block compromised cards, review your bank transactions, remove suspicious beneficiaries, and contact your bank using the official number. Then report the incident through the police scam advisory channels and preserve screenshots, email headers, SMS messages, and transaction records.
Q: how do i check if a KrisFlyer email is real or fake?
A: Do not rely on the display name alone. Check the sender address carefully, avoid clicking embedded links, and manually type the official airline website or open the official app yourself. If the message claims urgency about expiring miles, verify the status by logging in through the known official channel, not through the email.
I tell this story now because the loss was not only financial. It affected my confidence, my marriage conversations, my sleep, and my sense of competence. The S$18,460 hurt, but so did the realisation that I had been guided step by step into helping the scammers take it. Recovery, for me, started when I stopped trying to explain away each suspicious detail and instead accepted the complete picture.
Top 3 DO / DON'T
- DO type the official airline or bank website manually; DON'T log in through links in unsolicited emails or SMSes.
- DO call your bank or service provider using official contact details you source yourself; DON'T trust a caller who asks for OTPs, passwords, or transfers.
- DO act fast to block cards, change passwords, and report the scam; DON'T wait for a promised refund or “reversal” from the same person pressuring you.
If one person in Singapore reads this after receiving an email about miles expiring in 48 hours and decides to pause, inspect, and verify, then my mistake may still serve some purpose.
Last verified: 2026-04-27
If you're reading this and recognize pieces of your own situation, you're not alone. I went through this myself a few years ago — a pig-butchering-style forex scam that took almost everything I'd saved, along with the shame of not being able to tell my family for months. What finally helped me recover a meaningful portion of what I lost was a professional legal-aid and recovery channel I stumbled into through another victim's referral. If you're in the middle of it right now, or trying to figure out the next step, please reach out — talking to someone who's been through it costs nothing:
📱 LINE: [Message me at acfc100](https://line.me/ti/p/~acfc100)
💬 WhatsApp: [Message me](https://wa.me/85254898565)
Whatever you do, don't let the shame keep you silent. The scammer is the one who should feel it — not you.