Singapore’s Cyber Security Agency is running a national exercise where volunteers receive simulated robocalls that mimic government impersonation scams, including AI-enabled calls. The article also points to real-world cases where criminals impersonated company executives on WhatsApp and even used digitally altered appearances on video calls to pressure victims into secrecy and compliance.
How the exercise and real attacks connect
Singapore's Cyber Security Agency (CSA) is running a six-month National Simulated Scams Exercise that sends volunteers robocalls mimicking government impersonation scams. CSA has said the pilot includes AI-enabled government impersonation scam calls, which reflects a shift toward more conversational and interactive scam tactics rather than static, scripted robocalls. This exercise is being paired with public warnings from Singapore Police about real cases where criminals impersonated company executives on WhatsApp, and in some instances used digitally altered appearances during video calls.
Why the executive impersonation tactic works
The scenario described by Singapore Police centers on a manipulation tactic built around secrecy. Victims were told they were working on confidential projects and instructed not to discuss the matter with colleagues. This single instruction is powerful because it removes the easiest way a target could catch the deception: asking a coworker or manager if the request is legitimate. Combined with impersonation of a senior executive and communication over WhatsApp instead of normal corporate channels, the setup creates pressure and isolation at the same time.
Red flags to watch for
- A request to keep a project or instruction secret from colleagues
- Executive-style requests arriving over WhatsApp rather than established corporate channels
- Urgency or authority cues designed to short-circuit normal verification steps
- Voice or video communications that feel unusually convincing or interactive, which may indicate AI-enabled or manipulated media
Building resistance across channels
The awareness takeaways from this case point to training that goes beyond email-based phishing awareness. Employees may now encounter a WhatsApp message supposedly from an executive, a convincing phone call from someone claiming to be IT, or a video call featuring a digitally manipulated face. Because voice-based social engineering can put victims under real-time pressure by exploiting authority, urgency, and fear, organizations are encouraged to build practical habits rather than rely on awareness alone.
The stated objective of exercises like this one is not to catch employees making mistakes, but to build a reflex: stop, verify, and use a second channel before acting. Practicing this response in a safe, simulated setting, sometimes called a fire drill approach, can help employees internalize the habit so they are more likely to apply it when a real attempt arrives through a phone call, video call, or messaging app.
Key findings
- Singapore’s CSA is running a six-month National Simulated Scams Exercise using robocalls that mimic government impersonation scams.
- CSA said the pilot includes “AI-enabled government impersonation scam calls,” reflecting more conversational, interactive scam tactics.
- Singapore Police warned criminals have impersonated company executives on WhatsApp and “used digitally altered appearances during video calls.”
- A key manipulation tactic described is secrecy: victims were told they were on “confidential projects” and instructed not to discuss with colleagues.
Who’s being targeted
- Commonly targeted roles: All employees, Finance/AP, Executive leadership, Executive assistants, IT helpdesk/service desk, HR and recruiting.
- Affected industries: Government / Public Sector, Private sector businesses (cross-industry), Consumers / general public.
- Attack channels: whatsapp.
- Impersonated: Company executive (senior management).
Red flags to watch for
- Pressure to keep the request secret from colleagues
- Request coming from WhatsApp instead of normal corporate channels
- Authority/urgency cues intended to bypass verification
Frequently asked questions
What is Singapore's National Simulated Scams Exercise?
It is a six-month exercise run by Singapore's Cyber Security Agency that sends volunteers simulated robocalls mimicking government impersonation scams, including AI-enabled calls.
How have criminals impersonated executives in real cases?
Singapore Police warned that criminals impersonated company executives on WhatsApp and in some cases used digitally altered appearances during video calls.
Why is a secrecy request a red flag in these scams?
Victims were told they were working on confidential projects and instructed not to discuss the request with colleagues, which cuts off one of the easiest ways to discover the deception.
What should employees do if a call or message feels off?
The goal is to build a reflex to stop, verify through a second channel, and avoid acting immediately under pressure or secrecy demands.
Read the video transcript
Singapore is literally running scam-call fire drills because AI scam calls are now that convincing. Now picture this: a WhatsApp from your ‘CFO’, then a video call where their face looks right, and they say, “This is a confidential project, don’t tell anyone, just follow my instructions.” That secrecy line is the trick. Singapore Police say victims were told they were on confidential projects and cut off from colleagues, that’s how the scam works, not a sign you’re trusted. Your move: the moment someone says, “Keep this secret, reply only here,” stop and verify through normal channels, Teams, corporate email, or a known number, not WhatsApp.