Back Malaymail Singapore police warn crypto users after hackers exploit compromised email accounts
Singapore police warned of increased unauthorised access to cryptocurrency accounts due to reused passwords from hacked email accounts found in data breaches.
Scammers exploit compromised email credentials to access and manipulate crypto accounts, often undetected, by creating email rules and requesting password resets.
Authorities advise using strong, unique passwords, enabling multi-factor authentication, and monitoring account activity to prevent unauthorised access.
SINGAPORE, Sept 12 — The police have warned cryptocurrency users whose email accounts were recently hacked to check their account security after a rise in cases involving unauthorised access to linked crypto accounts since mid-August.
The Straits Times reported that police investigations found several affected email accounts had previously appeared in data breaches on other platforms, potentially exposing users’ login credentials.
The authorities said scammers could exploit reused passwords from those breaches to gain access to victims’ cryptocurrency accounts.
“Perpetrators may have exploited this by using the compromised e-mail credentials to access victims’ cryptocurrency accounts, taking advantage of victims who reused the same passwords across multiple online services,” the authorities said.
Police said scammers may first compromised email accounts for information on the cryptocurrency platforms or exchanges used by victims.
They could then create inbox rules to automatically archive, forward or delete messages from crypto exchanges, making it harder for victims to detect the intrusion.
Scammers may also request password resets for cryptocurrency accounts and intercept reset links, one-time passwords or verification emails sent to victims.
Police said credentials exposed in data breaches could similarly be used against cryptocurrency accounts where users had reused the same passwords.
The authorities advised the public to use strong, unique passwords and activate multi-factor or two-factor authentication, while regularly checking their email security settings for suspicious activity or unauthorised inbox rules.
Users whose credentials may have been exposed should change their passwords immediately and regularly review their cryptocurrency transaction histories and account activity notifications.
Anyone whose email or cryptocurrency account has been compromised should their email provider and cryptocurrency exchange immediately to secure or freeze the accounts, as well as check for suspicious activity and remove unauthorised trusted devices, recovery methods and authentication methods.
Police also urged anyone with information on such cases to the police hotline at 1800-255-0000 or submit information online through the police website.
Anwar-Modi Brics meeting: Semiconductor ties, bilateral trade take centre stage
‘My brother’: PM Anwar, Modi meet on Brics sidelines
A spring in Umno’s step: Three things we learnt from its 2026 general assembly
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
