Scam losses and insurance: what the new personal cyber plans pay
A phishing scam and a personal cyber insurance claim are not automatically the same thing. Here is where bank protections end and where a cyber policy actually starts paying.
Scam losses in Singapore are large enough that MAS and IMDA introduced a Shared Responsibility Framework requiring banks and telcos to take specific steps to prevent phishing scams, and to compensate affected consumers when those steps are not met. That framework sits at the level of the bank account and the phone line. A personal cyber insurance plan is a different, and in some ways narrower, layer, and knowing which one actually applies to a given loss matters before you assume either one automatically covers you.
What the Shared Responsibility Framework is, and is not
The Shared Responsibility Framework (SRF) assigns duties to financial institutions and telecommunications companies to reduce phishing scams, for example through anti-malware controls, fraud surveillance and labelling unregistered message senders, and sets out how a victim can claim compensation if a participating bank or telco failed to meet its duties. If you suspect you are a scam victim, the first steps are to contact your bank immediately and make a police report; your bank coordinates the investigation and tells you whether your case falls within the SRF's defined scope.
This is not an insurance product, and it does not cover every type of scam. It is specifically aimed at phishing scams within participating banks and telcos, following a defined claim, investigation and outcome process. A scam that falls outside its scope, or a bank or telco that is not a participant, is not automatically compensated this way.
Where a personal cyber insurance plan comes in
Separately from the SRF, some insurers have started bundling personal cyber protection into everyday policies, most visibly into home insurance plans aimed at HDB and condominium owners. One example structure covers online theft or fraud up to a set benefit as part of a broader home plan, alongside worldwide personal liability and cover for loss or damage to valuables. This is a genuinely different mechanism from the SRF: it is an insurance payout against a defined trigger in your policy, assessed like any other claim, rather than a bank-and-telco compensation scheme.
Because "personal cyber cover" is not yet a single standardised product across the market, what is actually included varies a great deal between insurers and between the plan tiers of a single insurer. Some structure it as cover for unauthorised online transactions specifically; others frame it more broadly to include costs like identity restoration, data breach expenses, or legal costs connected to cyberbullying or online harassment. Read the policy wording for the specific triggers and exclusions rather than assuming "cyber protection" on a brochure means the same thing everywhere.
Questions worth asking before you assume you are covered
- Is this benefit part of a home, motor or other bundled policy, or is it a standalone cyber policy, and does that change the claims process?
- What counts as a covered "scam" or "unauthorised transaction" under this specific policy β does it require the loss to have occurred through a hacked account, or does it also cover you being tricked into authorising a payment yourself?
- Is there a cap per incident and a separate annual aggregate cap?
- Does the policy require you to have taken reasonable security precautions, such as not sharing one-time passwords, for the claim to be valid?
- If a loss might qualify under both the SRF and a personal cyber policy, does making a claim under one affect your position under the other?
What this means practically
If you are scammed, report it to your bank and the police first, since that starts the clock on both the SRF process and any related insurance claim, and preserves the evidence an insurer will also want to see. Then check separately whether any policy you hold, home, cyber or otherwise, has a relevant benefit, and follow its own claims process rather than assuming the bank's process covers it. If a claim under either channel is declined and you believe it should not have been, FIDReC is the independent avenue for unresolved disputes with a financial institution. You can compare current cyber and bundled home plans at /compare/singapore/cyber.
Talk to an advisor
Whether a specific home or standalone policy would actually respond to a given scam scenario is a question worth asking before you need the answer, not after. A licensed advisor can check a policy's cyber benefit against realistic scam scenarios relevant to your household. Use the portal's advisor matching to find one, or ask our assistant to explain what a specific policy's cyber protection actually covers.
Sources
This content is educational information from a licensed advisor, not financial advice. Product details vary by insurer β verify specifics with an advisor.