Connect with us

CRYPTO

Singapore Police Trace Crypto Thefts to Hidden Inbox Rules

Singapore police say reused passwords from old data breaches, plus hidden inbox rules, are letting attackers reset and drain cryptocurrency exchange accounts.

Published

on

On Sept 12 the Singapore Police Force warned crypto users to review email security after hacked inboxes were used to open linked exchange accounts.

The force said it had seen an increase in those cases since mid-August. Several of the affected mailboxes had already appeared in data breaches on other platforms, and police said attackers likely reused those login details where victims had kept the same password.

A Mid-August Spike Tied to Reused Passwords

The warning is not a claim that Coinhako, OKX or any other named platform was broken. It is a claim about the mailbox that still sits under most exchange logins. Once someone else can open that mailbox, a password reset on the exchange is just another email.

Police investigations found that several of the hit email accounts had shown up in earlier leaks on unrelated sites. From there the path is ordinary: try the same password on the mailbox, then on the exchange, and hope the owner never used a second factor that lives off email.

WHAT WE KNOW

  • The timing: Police said cases of unauthorised access to crypto accounts through hacked email rose from mid-August.
  • The overlap: Several of those mailboxes had already appeared in data breaches on other platforms.
  • The method: Attackers search the inbox for exchange names, plant rules that hide mail from those platforms, then request password resets and intercept the links, one-time passwords or verification messages.
  • The advice: Unique passwords, multi-factor or two-factor login, an authenticator app rather than SMS, and a check of inbox rules, forwarding and login history.

WHAT IS UNCONFIRMED

  • The tally: Police have not published how many accounts were hit in this wave or how much crypto moved.
  • The brands: No email provider and no exchange was named as the source of the original leaks.
  • The dumps: The Sept 12 note does not identify which older breaches supplied the passwords.

That missing tally is why the note reads like a consumer alert rather than a crime roundup. The force is telling anyone who trades crypto and has had email trouble since mid-August to treat the mailbox as part of the vault.

Inbox Rules Hide the Exchange Mail

Getting into the mailbox is only the first half. The part that keeps the owner in the dark is a filter the owner did not write.

Police said attackers may first search the compromised account for mail that names the crypto platforms or exchanges the victim uses. They then create inbox rules that automatically archive, forward or delete messages from those platforms, so the later reset traffic never appears in the main inbox.

THE SILENT TAKEOVER

  1. Find the venue: Search the mailbox for exchange names, deposit receipts and old login alerts to see where the coins sit.
  2. Plant a rule: Archive, forward or delete mail from those senders so password-reset and withdrawal notices never reach the inbox the owner still checks.
  3. Ask for a reset: Start a password reset on the exchange, then intercept the link, one-time password or verification email that the platform sends.
  4. Lock the owner out: Change the exchange password, add a trusted device, and strip recovery options the owner still controls.
  5. Move the coins: Withdraw to a wallet the victim does not own, which on most chains cannot be reversed once it confirms.

Gmail’s own help pages show how little friction that second step needs. A filter can send matching mail to a label, archive it, delete it, or apply filters that archive or forward mail once a forwarding address has been verified. Outlook can do the same job with a rule that forwards or redirects messages as they arrive. None of that requires a second break of the exchange. It only requires the mailbox that the exchange already trusts.

The louder problem is not a fresh exploit against a Singapore-licensed platform. It is a reused password from a forgotten retailer or forum, plus a filter that makes the reset email vanish before the owner looks.

Where Those Login Details Came From

Several of the affected email accounts had previously appeared in data breaches on other platforms, which means the victims’ credentials may already have been sitting in dumps that anyone can buy or scrape. Police said perpetrators may have used those email credentials to reach crypto accounts because the same passwords were reused across services.

Perpetrators may have exploited this by using the compromised email credentials to access victims’ cryptocurrency accounts, taking advantage of victims who reused the same passwords across multiple online services.

Singapore Police Force, Sept 12 news release

That is credential stuffing with a crypto payout. Attackers do not need to guess which other site reused the password. They test the leaked pair against mailboxes and exchanges until one opens. Police also warned that credentials from older breaches can be tried directly on crypto accounts when the password was reused there, skipping the mailbox step entirely if the exchange login still matches.

In a May 21, 2025 advisory on safeguarding online accounts, the force and the Cyber Security Agency of Singapore already told the public to check Have I Been Pwned, a site that flags addresses exposed in platform breaches. The checker now lists 1,035 pwned websites and 17,811,564,180 pwned addresses. Anyone can check known data breaches against an address in a few seconds, then reset every account that still shares that password.

The Sept 12 cases make the cost of skipping that step concrete. A leak from a site that never held a satoshi can still open the inbox that holds the exchange reset. The coins move later, on a different company’s servers, which is why victims often describe it as an exchange hack when the first break was email.

S$8.94 Million Stopped on Eight Exchanges

Headline crypto-scam losses in Singapore are falling. The mailbox pattern is rising inside that drop, which is why the two sets of figures cannot be mashed into one story.

CRYPTO LOSSES POLICE CAN SEE

Window Figure What it covers
2025, full year About S$182.2 million All cryptocurrency scam losses, about 20% of S$913.1 million in total scam losses
First half of 2026 S$65.5 million All cryptocurrency scam losses, 16% of S$410.6 million (US$320 million) in total scam losses, down 43% from a year earlier
First half of 2026 More than S$8 million Cryptocurrency recovered by the Anti-Scam Centre, part of more than S$97.7 million recovered in all
1 July to 31 August 2026 More than S$8.94 million Potential losses stopped with eight platforms after officers reached over 355 victims of impersonation, investment and job scams

On Sept 3, Cyber Command said a fourth joint run with digital payment token providers prevented more than S$8.94 million in potential losses. Officers used blockchain analysis from Chainalysis and TRM Labs, then called or visited people flagged by Coinbase, Coinhako, DTCPay, Gemini, Independent Reserve, OKX, StraitsX and Upbit. They also passed leads to the FBI and to New South Wales police, which identified 50 foreign victims.

Those 355 people were visible because coins were about to move, or already had, on chains the force can watch with exchange help. An inbox rule that archives a Binance or Coinhako reset does not show up in that feed until the withdrawal hits the chain. By then the owner has often missed the only emails that would have stopped it.

First-half scam cases overall fell 14.4% to 16,821, and total losses fell 17.9% to S$410.6 million. Crypto’s share of those losses also shrank. The Sept 12 note still went out because this quieter path, reused passwords plus a hidden rule, does not need a fake job ad or a government-official impersonation call to work.

Gmail Filters and Outlook Rules to Audit Tonight

Police asked users to check email security settings for unauthorised inbox rules, forwarding and odd login activity, then to enable account-activity alerts on the exchange and to read recent transaction history. That audit is a half-hour job if the owner still has access to the mailbox.

CHECKS FOR EMAIL AND EXCHANGE ACCOUNTS

  • Gmail filters: Open Settings, See all settings, then Filters and Blocked Addresses, and delete any rule that archives, deletes or forwards mail from exchanges, wallets or the words “password”, “reset” or “verification”.
  • Gmail forwarding: On the Forwarding and POP/IMAP tab, disable any destination you did not add, and remove verified forwarding addresses you do not recognise.
  • Outlook rules: In Outlook on the web, open Settings, Mail, then Rules, and remove Outlook rules that forward mail or file exchange messages into RSS, Archive or a folder you never open.
  • Outlook forwarding: Under Mail, then Forwarding, turn off automatic forwarding to any address you did not set.
  • Login history: Sign-in pages on Google and Microsoft list recent sessions. Kick out unknown devices and revoke recovery phones or backup mailboxes you do not control.
  • The exchange: Turn on activity notifications, read the withdrawal log, and drop extra trusted devices, recovery methods and authentication methods you did not add.

If the mailbox password was ever reused on a shop, a forum, a game or a second mail account, change it on every one of those services, not only on Gmail. Police said users whose credentials may have been exposed should change passwords immediately and should not recycle the new string.

A filter you do not remember is the tell. Legitimate travel auto-forwards are rare, and they are almost never aimed at a single exchange domain. When in doubt, delete the rule, then read the Trash, Archive and RSS folders for the reset mail you were never meant to see.

SMS Codes Still Reach the Stolen Inbox

Police urged strong, unique passwords and multi-factor or two-factor authentication on both email and crypto accounts. Where possible, they said, use an authenticator application rather than SMS, which is easier to intercept.

That line is not new. A July 1 police advisory on malicious links and unauthorised crypto transactions already told users to prefer an authenticator app over SMS-based verification. Google’s own account help says texts or calls can be vulnerable to phone-number hacks. The Sept 12 note adds the reason the SMS path fails in this wave: if the second factor is itself an email, or if the SMS reset still copies a code into a mailbox the attacker reads, the extra step collapses onto the same channel.

An authenticator app that generates codes on a phone the attacker does not hold still blocks a stuffed password. Email-only two-factor does not. Hardware keys and passkeys sit further up that ladder, but the police text stops at the app, which is the step most exchange users can take the same evening.

Pay attention to breach notices from any service that ever stored that address. If a retailer or a ticketing site says your login was leaked, assume the mailbox and the exchange are next if the password was shared, and rotate them before a rule is planted.

Freeze the Account Before Coins Leave

Anyone who thinks the email or the crypto account is already in someone else’s hands should contact the email provider and the exchange at once and ask them to secure or freeze the accounts. Change the passwords on the affected mailbox, the exchange, and every other login that shared that string. Then strip unauthorised trusted devices, recovery methods and authentication methods so the attacker cannot walk back in after the freeze lifts.

Police asked anyone with information on these cases to call 1800-255-0000 or to submit it through the i-witness form. People who are unsure whether a message is a scam can call the 24/7 ScamShield helpline on 1799 or use the ScamShield app. Urgent help is still 999.

The coins will not wait on that call. Exchange withdrawals confirm on their own clocks, and a hidden rule is designed so the only alert you would have trusted never reaches the inbox you still open.

Disclaimer: This article is news reporting on a Singapore Police Force warning about cryptocurrency account takeovers, and it is for information only. It is not personal cybersecurity advice, investment advice, or legal advice, and it is not a substitute for guidance from your email provider or exchange. If you think an account has been taken over, contact the exchange’s support team and the police, and speak with a qualified cybersecurity professional before you move remaining funds or change recovery settings you do not understand. Figures and case patterns reflect police statements issued on Sept 12, 2026, and may change as investigations continue.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending