I lost S$18,460 because I believed an email that said my KrisFlyer miles would expire within 48 hours.
My name is Jolene Tan Wei Lin, I am 41 years old, and I work as an operations manager for a medical supply company in Hougang, Singapore. I live in the Kovan area, and like a lot of people here, I am careful with points, miles, bills, and travel deals because everything feels expensive now. I had built up my KrisFlyer miles over several work trips to Kuala Lumpur, Bangkok, and Sydney, plus regular spending on a co-branded card. By early March 2026, I had about 86,000 miles. I had been thinking vaguely about using them later in the year for a family holiday, but I had not logged in for some time.
On Tuesday, 10 March 2026, at 8:17 am, while I was clearing emails on the MRT on my way to work, I saw one with a subject line that said: “Urgent: 48 Hours Left Before Your KrisFlyer Miles Expire.” It looked convincing at first glance. The sender name displayed as “Singapore Airlines KrisFlyer Team.” The email used the familiar red-and-gold colour scheme and had a button that said “Protect My Miles Now.” I was standing between two people near the train door, half distracted, and feeling annoyed with myself because I thought I had left the miles sitting too long.
The exact first contact was that email about 48-hour miles expiry. That detail matters because it pushed me into acting quickly instead of slowly. I tapped the button on my phone, and it opened what looked like a Singapore Airlines login page. The logo was there, the font looked close enough, and there was a banner saying members needed to verify their account to retain miles. I entered my membership number, password, mobile number, and then my one-time password after the page said verification was required to “suspend expiry processing.” It was all framed in the language of urgency and account protection.
I remember one odd detail now: the page took about four seconds to load between screens, which felt slightly clunky for such a major airline site. At the time, I explained it away because I was underground and my mobile connection was patchy. After I completed the form, a message appeared saying my miles were “successfully secured” and that an updated statement would be available within 24 hours. I felt relieved and went on with my day.
That same evening, I received two SMS messages from my credit card issuer about online transactions I did not recognise: one for S$1,980 and another for S$2,240. Both were marked as travel-related merchants. I immediately called the bank and disputed them. The customer service officer asked whether I had entered my card details on any unfamiliar site that day. I said no at first, because in my head I had logged into a normal airline portal, not something suspicious. The bank blocked my card and said investigations would take time.
The next day, a man called me from a private number. He introduced himself as “Adrian from Singapore Airlines account security.” He said they had detected “abnormal attempts to redeem miles” from an overseas IP address shortly after I completed my verification. His tone was calm and professional. He already knew my full name, partial membership number, and mobile number. That is what convinced me he was genuine. He said because my account had likely been targeted, they needed to place my miles into a “temporary protection pool” and verify linked payment instruments to stop unauthorised use.
Looking back, that call was the bridge between simple phishing and full financial loss. He was not just harvesting data. He was using the data I had already handed over to deepen trust. Over the next two weeks, he called four more times. Once during my lunch break, once at 7:40 pm, once on a Saturday afternoon, and once while I was in a Grab on the way to visit my mother in Toa Payoh. Every call was polite and measured. He never sounded aggressive in the beginning. He sounded like someone trying to help me tidy up an admin problem.
He explained things in ways that sounded plausible to a frequent flyer member: pending mileage transfers, linked card tokenisation, travel partner redemption abuse, and account reconciliation windows. I work in operations, not cybersecurity, so structured jargon tends to reassure me when it sounds internally consistent. He even told me the first disputed card transactions were likely “test charges” by criminals and that the safest thing was to help the airline and bank isolate my profile before more damage occurred.
WARNING SIGN 1: The original email created artificial urgency with a 48-hour deadline and pushed me to click before thinking. Genuine companies may send reminders, but urgency that forces immediate login and OTP entry should make you stop, check the site address carefully, and log in only through the official app or a known website you typed yourself.
On 13 March, he sent me another link by email and told me it was the secure portal for “member remediation.” This time I was at my desk in the office pantry. I clicked through on my laptop. The page looked even more convincing than the mobile version. It had tabs for profile review, miles activity, and payment dispute verification. He stayed on the phone while I navigated. He said because fraudsters had attempted redemptions, my membership profile had been frozen and had to be matched against my bank records. I typed in my debit card details, then my savings account information, because the page said successful matching would reverse any unauthorised temporary charges.
As soon as I hesitated, he had an answer ready. He said, “Ms Tan, this is not a payment. It is an identity lock process to ring-fence your KrisFlyer account.” He used that exact phrase, ring-fence. It sounded technical and sensible. I wanted the problem solved. I also felt embarrassed about the first card charges and wanted to demonstrate that I was cooperating properly.
Over the next three weeks, the scam turned from confusing to chaotic. On 16 March, I noticed S$3,000 had been transferred out of my bank account through a transaction reference I did not recognise. On 18 March, there were two more transfers, S$2,500 and S$1,880. I called the bank again. This time they were firmer. They asked me whether anyone had instructed me to move money or enter banking credentials into a website. I admitted I had done so during an account verification process I thought was tied to the airline. The officer said it sounded like a scam and advised me to make a police report immediately.
I should have stopped there. Instead, I got trapped by the scammer’s next move. When I confronted “Adrian,” he sounded offended but patient. He told me the bank was seeing only incomplete transaction metadata and could not view the underlying airline fraud case. He said the outgoing transfers were actually “reversible authentication holds” and that if I panicked now, my miles and disputed card refunds could both be delayed for 60 to 90 days. He then transferred the call to a woman who introduced herself as “Michelle from payment recovery.” She spoke in a crisp, reassuring way and said there was a time-sensitive path to recover everything in one batch if I completed a final verification.
That final verification was where I lost the biggest amount. She instructed me to add a new payee and transfer S$6,860 in two tranches, S$3,430 and S$3,430, to a company account she said was a “temporary escrow node” used for account reconciliation. She stayed on the line while I did it. My hands were shaking, and I remember asking twice, “This will come back, right?” She answered both times, “Yes, after system validation.” I made the transfers from my banking app on 21 March at 11:08 am and 11:19 am.
What I did not understand then was how carefully they had built the pressure. They did not ask for S$18,460 in one go. They harvested my login and OTP first, then my trust, then my payment details, then my bank access confidence, and finally my willingness to send money myself. Each step was framed as cleaning up the damage from the previous step. That is why the scam progressed over six weeks instead of exploding in one day.
According to the [Singapore Police Force Anti-Scam Centre](https://www.police.gov.sg/Advisories/Crime/Scams), scammers commonly impersonate trusted organisations and create urgency through account problems, rewards issues, expiring benefits, or security alerts. I read that only after my losses, and it was painful how closely my experience matched the pattern.
The trust-building was not only about calls and fake portals. It was also about small concrete details. “Adrian” referenced my recent travel to Sydney, which I later realised could have been visible from the miles activity page I entered. He said things like, “I can see your last accrual has posted,” or “You normally redeem closer to the year end.” Those comments made him sound like a genuine account officer with system access. Once, he told me not to worry and to “enjoy your Sunday with family” while they processed the hold. That tiny piece of warmth made him feel human instead of scripted. Another time, he emailed me a PDF titled “Case Summary,” formatted with tables and timestamps. It was fake, but it looked administrative enough to calm me.
WARNING SIGN 2: The caller already knew some of my personal details and used industry-sounding language to make the story feel legitimate. Scammers often rely on information you have already surrendered or that has been exposed elsewhere, then combine it with jargon and confidence so you mistake familiarity for proof.
By late March, my bank had blocked one card, but the damage spread to another card linked to online purchases. There were smaller charges too: S$640, S$520, and S$340. These amounts were easier to mentally minimise because I was so fixated on recovering the larger transfers. I kept records in a notebook, writing dates, amounts, and names. That notebook now feels like a timeline of my own denial.
On 29 March, I tried logging into my real KrisFlyer account through the official app. My password no longer worked. I tapped “forgot password,” and the reset notices never reached me. That was the moment something in my stomach dropped. I searched online for scams involving KrisFlyer expiry emails and found forum posts from people describing similar fake warnings and spoofed pages. The wording was not identical, but the structure was close enough that my chest felt hot. I called the airline’s official customer service number from their real website, and the representative confirmed there was no active security case linked to my account and no such thing as a member remediation escrow.
I still remember the silence after that call ended. I sat at my dining table in Kovan with my laptop open, the afternoon light coming through the window, and I just stared at the numbers I had written down. S$1,980. S$2,240. S$3,000. S$2,500. S$1,880. S$3,430. S$3,430. Add the smaller charges and fees, and the total came to S$18,460. It was not abstract anymore. It was my emergency savings buffer, my daughter’s enrichment budget for the year, and the money I had been setting aside to help pay for repairs in my mother’s flat.
That evening, I made a police report and contacted my bank’s fraud department again with the full timeline. I also called the anti-scam hotline, 1800-722-6688, because by then I was desperate for someone to tell me what to do next, step by step. The person I spoke to was calm and practical. They told me to preserve the phishing email, screenshots, URLs, transaction records, call logs, and any WhatsApp or SMS communication. I spent hours compiling everything into folders.
According to the [Singapore Police Force Anti-Scam Centre](https://www.police.gov.sg/Advisories/Crime/Scams), victims should act quickly to alert their bank, secure digital accounts, and report scams with available evidence such as phone numbers, messages, links, and transaction details. If I had done that decisively after the first unauthorised card alerts, I might have reduced the loss.
In the weeks that followed, the practical work was exhausting. I changed email passwords, enabled stronger authentication, replaced cards, reviewed linked accounts, checked my credit records, and warned family members not to trust unexpected airline emails. But the emotional part was harder. I did not tell many people at first because I felt ashamed. I am not elderly. I am not careless with money. I review invoices at work for a living. Yet I still walked through a scam that, in hindsight, had multiple obvious weak points.
The shame came in waves. At random moments, I would replay specific actions in my head: tapping the first email on the MRT, typing my OTP, trusting the caller because he sounded organised, making the two S$3,430 transfers while asking if they would come back. I wanted a single stupid mistake I could isolate and condemn. Instead, what I had to face was more uncomfortable: I was manipulated gradually, and each step felt explainable when viewed from inside the story they created for me.
Friends later asked why I did not simply hang up or verify independently sooner. The honest answer is that the scam took hold in the space between busyness and trust. I was juggling work deadlines, my daughter’s school schedule, and family obligations. The idea of resolving an account issue quickly was appealing. The scammers were never cartoonishly threatening at the start. They were procedural, plausible, and patient. They solved each doubt just fast enough to keep me moving.
WARNING SIGN 3: I was told to transfer money to a new payee for “verification,” “escrow,” or “recovery.” No legitimate airline or rewards programme needs customers to send funds to protect miles, reverse fraud, or unlock refunds. Any request like that is a stop-now moment.
The biggest lesson for me is simple but expensive: never use a link inside a rewards expiry email to log in, no matter how authentic it looks. Open the official app, or type the known website address yourself. If there is truly a problem, it will still be there when you arrive through a trusted path. And never enter an OTP or banking information into a page you reached through an urgent message.
I also learned that scammers understand loyalty programmes very well. Miles feel both valuable and perishable. They sit in that emotional category between cash and privilege. A warning that they are about to disappear can trigger panic out of proportion to the actual timeline. In my case, the fear of “wasting” 86,000 miles nudged me into risking far more than the miles were worth.
Frequently Asked Questions
Q: how do i know if a krisflyer expiry email is fake?
A: Check the sender address carefully, but do not rely on the display name alone. Do not click the email link. Instead, open the official app or manually type the known website address, then check your account there. If the email pushes urgent login, OTP entry, or payment verification, treat it as suspicious.
Q: can scammers steal money just from a fake airline login page?
A: Yes. A phishing page can capture your username, password, OTP, contact details, card data, and enough information to support follow-up impersonation calls. That combination can lead to account takeover, card misuse, and social engineering that pressures you into making transfers yourself.
Q: what should i do right after i clicked a phishing link in singapore?
A: Contact your bank immediately, block affected cards, change passwords through official channels, enable stronger account security, preserve screenshots and messages, and report the scam quickly. If money was transferred, speed matters because banks and authorities may have a better chance of tracing or freezing funds early.
Last verified: 2026-04-27
Top 3 DO / DON'T
- DO verify rewards, miles, and account alerts by opening the official app or typing the official website yourself.
- DO call your bank and report fast if you entered credentials, OTPs, card details, or made suspicious transfers.
- DON'T trust callers who ask for banking details or transfers to “secure,” “escrow,” or “recovery” accounts, even if they know personal information.
If you're reading this and recognize pieces of your own situation, you're not alone. I went through this myself a few years ago — a pig-butchering-style forex scam that took almost everything I'd saved, along with the shame of not being able to tell my family for months. What finally helped me recover a meaningful portion of what I lost was a professional legal-aid and recovery channel I stumbled into through another victim's referral. If you're in the middle of it right now, or trying to figure out the next step, please reach out — talking to someone who's been through it costs nothing:
📱 LINE: [Message me at acfc100](https://line.me/ti/p/~acfc100)
💬 WhatsApp: [Message me](https://wa.me/85254898565)
Whatever you do, don't let the shame keep you silent. The scammer is the one who should feel it — not you.