Josephine Teo
Singapore
“The Government's risk-calibrated approach to data security in artificial intelligence (AI) systems was explained in a written reply, given on 9 January 2024, to related questions asked by Dr Tan Wu Meng and Mr Gerald Giam.”
“Access to frontier models is helpful for specific use cases, such as advanced research and cybersecurity. However, these form a small proportion of artificial intelligence (AI) demand. For most industry, Government and research uses, capable models are already available.”
“The Government tracks the development of technical standards for identifying artificial intelligence (AI)-generated content, including watermarking and digital provenance approaches, as part of broader efforts to manage AI-related risks.”
“Upon receiving a valid report of intimate image abuse, the Commissioner of Online Safety is empowered by law to direct Online Service Providers (OSPs) to disable access by Singapore users to the specified harmful online material. This direction may be extended to cover identical copies found on the platform.”
“The Government is committed to keeping children safe online. We have announced plans to extend age assurance requirements to designated social media services, including requiring platforms to keep users under 13 off their services.”
“Under the Online Safety (Relief and Accountability) Act 2025, the Commissioner of Online Safety is empowered to issue directions to platforms to remove specified harmful content, including intimate image abuse.”
The complete record
Every one of 2,900 lines we hold for Josephine Teo, in date order, each linked to its source. Free to read, in full, without an account. Page 13 of 58.
“I do not think any executive in his or her right mind would find it easy to explain to their colleagues why because of non-compliance, access has been blocked; and since there is no personal liability, the need for extradition for non-compliance with Directions or Orders is moot. However, extradition can be undertaken in respect of the individuals carrying out the underlying specified offences, in accordance with the Extradition Act. I would add, however, in the era of user-generated content, a lot of these content creators are very hard to pin down. So, we have to ask ourselves what is the priority. If the priority is to prevent harm from continuing to reach our people, you can try and chase down the original perpetrator of the offence or you can try to prevent the harm from happening first. We want to be able to do both, but we need to be able to nip it in the bud quickly first. Mr Raj Joshua Thomas asked about the factors that will be taken into account, in deciding whether a person should be granted bail when the offence is failure to comply with the Directions. A key consideration is the risk profile of the offender. The nature of the underlying offence, which triggered the issuance of the direction in the first place, will not usually be taken into account, because the essence of the offence is the failure to comply with the Direction issued. Also, a person liable for non-compliance to a Direction could be an Internet service provider or online service, and thus may not be the perpetrator of the underlying offence to begin with. This shows that the offence of non-compliance and the underlying offence should be assessed separately. Mr Yip asked how the Bill would relate to existing legislation such as FICA and POFMA.”
“Mr Yip, Ms Ang and Mr Louis Ng cited the challenges relating to jurisdictional issues and asked how the Bill will be applicable to websites and online services that are based overseas. The Bill has provisions that allow us to issue Directions, Notices, Directives and Orders to entities and individuals, even if they have no presence in Singapore. We know, however, that some of them may choose not to comply, which is a challenge many countries similarly face. There are further steps that we can then take. First, we can prosecute for non-compliance, where possible. Second, the Bill allows the competent authority to issue Orders to restrict access to the non-compliant online service, to prevent the criminal activity and content from being accessed by persons in Singapore. For example, an Access Blocking Order can be issued to Internet access service providers to prevent non-compliant online services from continuing to reach users in Singapore and do them harm. These levers will be used judiciously and only when necessary. Mr Murali Pillai asked about the offence penalties and whether they were decided with extradition in mind. Relatedly, Mr Yong also asked whether we intend to hold key executives of e-commerce platforms criminally liable. The penalties in the Online Criminal Harms Act are aligned with similar legislation, such as FICA and POFMA. We want the executives of online platforms to take online harms seriously and to comply with Directions, but this does not mean they must be personally liable for non-compliance. There are more effective measures such as access blocking.”
“For example, in developing the codes of practice, we will engage the online platforms which we intend to designate, and take an outcome-oriented approach. We will also provide reasonable timeframes for platforms to comply with codes and Directives. Ms Ang and Mr Zhulkarnain asked how the Bill may affect privacy. Let me assure Members that the Government will strike an appropriate balance between preventing online criminal harms and privacy. For example, this Bill will not require online companies to “break” end-to-end encryption in private messaging. However, to combat a crime, we can issue Directions to the messaging platform to restrict the accounts which are being used to commit the crime. We may also require information on the suspected offenders and other platform users involved, in order to fully investigate the case. Mr Zhulkarnain asked that free speech and legitimate content continue to be protected. Article 14 of the Constitution provides such protections. At the same time, reasonable boundaries are needed because unfettered and absolute free speech can cause harm to individuals and society. It is therefore not uncommon to find laws in some jurisdictions that limit free speech; examples include prohibitions against hate speech. The Bill, as it stands, applies only to online content and activity that already constitute a criminal offence in Singapore, such as incitement to hatred against a religious group. I hope Mr Zhulkarnain will agree this does not create any new criminal offences in respect of speech, nor does it curtail legitimate content. I will move on to other queries about the Bill.”
“So, I hope this clarifies the terms that were being used. Mr Yip asked how quickly the Government can take action upon detection of online criminal content or activities. Where the magnitude of the criminal harm is high, and the impact is spreading fast, the authorities will seek to swiftly nip it in the bud. This would be the case for scams. The Police set up the Anti-Scam Command in 2022, and staff from the banks are co-located with Police officers at the Anti-Scam Centre. This has enabled us to sense-make and act quickly to prevent scams from harming more victims. And as I had mentioned in my opening speech, the threshold we have provided in the Bill for taking action against scams, is lower than for other offences, so that we can take action early and swiftly. As far as possible, we do not want to wait until a victim has fallen prey before acting. Ms Ang and Mr Melvin Yong asked about the responsibilities and expectations that will be placed on online service providers. Where we have identified a need for measures to be taken by such companies in order to tackle criminal activities, we would be requiring them in the law. The interventions would be designed with implementation in mind and with emphasis on the outcome more than the how. This approach recognises that every online platform has its unique features and operating considerations. The Government will be reasonable in applying the requirements under the Bill. To Ms Ang’s comment that there is appreciation of the consultative approach that the Government has been taking in developing this Bill, and her suggestion that such collaboration needs to continue. Let me assure her we will do so.”
“Mr Deputy Speaker, I thank Members for their support for the Bill. They raised many relevant points which I will do my best to address. Let me first address the questions on the circumstances under which the Government will use the levers provided in the Bill, such as Directions. Ms Janet Ang, Mr Yip Hon Weng and Mr Zhulkarnain Rahim had questions in this regard. Where there is reasonable suspicion that a specified offence has been committed and that an online activity is, in fact, helping the offence to be carried out, designated officers can issue Directions. In many cases, it would be apparent whether the threshold of “reasonable suspicion” is crossed and action can be taken immediately, for example, child sexual abuse materials that are uploaded onto the Internet. They are quite clear for everyone to see. In less clear-cut cases, the officers would first carry out investigations. In my opening speech, I had given examples of when the “reasonable suspicion” threshold may not have been crossed. To recap, they include, for example, initial contacting and grooming of victims of scams and blank websites that are not yet activated. These are the examples where the "reasonable suspicion" threshold may not have been crossed. So, Police action is not unfettered – you have to cross the threshold and the Bill sets the bounds within which the Police can act and beyond which it cannot. To Mr Pritam Singh's question, he may have missed my explanation in the opening speech. I may not have specifically used clause 6(1)(a), which describes the general threshold, and clause 6(1)(b) which describes the threshold for scams and malicious cyber activities. But it is this – clause 6(1)(b) also covers the preparation for the offence, even when the offence has not yet occurred.”
“The Member may refer to my Parliamentary reply on 7 November 2022 on the measures taken to safeguard Singapore's access to and the resilience of submarine cable networks. [Please refer to "Safeguarding Submarine Data Cables against Sabotage and Major Disruptions", Official Report, 7 November 2022, Vol 95, Issue 73, Written Answers to Questions for Oral Answer not Answered by End of Question Time section.] To further support our growing bandwidth needs, we will allocate more space and landing resources for submarine cable operators.”
“As with many types of services, liability for losses incurred due to disruptions of a digital service would be governed under (a) the terms of use for the service and/or (b) the contractual agreement between buyer and seller. Where services have significant impact to our economy and society, regulatory agencies have also imposed minimum service standards. For example, the Infocomm Media Development Authority requires telecommunication operators and Internet service providers to comply with Quality of Service standards and audit requirements for network resilience. The Monetary Authority of Singapore has strict requirements for banks with regard to the resilience of their critical services, which include digital banking. These were detailed during the 21 April 2023 Parliament Sitting. [Please refer to "Banking Disruptions That Have Lasted More Than An Hour in Last Five Years", Official Report, 21 April 2023, Vol 95, Issue 101, Written Answers to Questions for Oral Answer not Answered by End of Question Time section.]”
“The Government has integrated artificial intelligence (AI) in digital services, such as chatbots on Government websites, the OneService Chatbot for reporting municipal issues through social messaging platforms, and the SG Translate Together web portal. Recent developments in AI technologies, such as those powering Chat Generative Pre-trained Transformer, can help the Government improve the quality of e-services, for example, through better customised responses by chatbots to public queries. We must, however, ensure the accuracy and reliability of responses before such service enhancements can be deployed for public use. This will require a period of experimentation and testing. There are other ways in which the public can benefit from the use of such technologies within the Government, for example, through more efficient research and analysis of complex issues. The Public Service has, therefore, introduced guidelines for public officers when using such technologies, to clarify accountability and safeguard data security.”
“Public officers and political officeholders are allowed to communicate on work matters using their personal mobile devices to facilitate efficient coordination. However, classified information should not be communicated using personal mobile devices. We also do not allow Government services, such as emails, to be accessed via their personal devices.”
“If and when we are able to get to that situation, please be assured that we would be very willing to consider his suggestions being taken forward. [(proc text) Question put, and agreed to. (proc text)] [(proc text) Bill accordingly read a Second time and committed to a Committee of the whole House. (proc text)] [(proc text) The House immediately resolved itself into a Committee on the Bill. – [Mrs Josephine Teo]. (proc text)] [(proc text) Bill considered in Committee; reported without amendment; read a Third time and passed. (proc text)]”
“Mdm Deputy Speaker, firstly, I would like to thank the Member for his clarification that he is not advocating a carte blanche. And indeed, the Police will look at the situation, understand where the person who made the report was coming from, examine the circumstances carefully and if indeed, it was a matter of negligence and perhaps not much harm had been done, the Police will certainly take these into consideration in deciding whether or not to proceed with further action. On the Member's second question which has to do with due diligence, he had referred to the actions that landlords can take under the Immigration Act to, in some sense, demonstrate that they have done their part in trying to prevent illicit activities. In principle, we would like to get to a point where these due diligence steps can be very clearly articulated and all of us can take part in preventing scams from happening. But as many Members have noticed and commented on during their speeches, the scam types and tactics are evolving so quickly. At present, it would be very hard to say that "here are the three things you can do", and you would have been considered to have fulfilled your due diligence. In fact, the measures that we have to take to protect ourselves are still a matter that is evolving each day. As the scam types present themselves, we notice increasingly new actions that we will have to take to protect ourselves and to protect our accounts from being misused. So, appreciating the Member's very well-intended suggestions, we would certainly like to get to a point where we can articulate "here are the three things or five things that you can do".”
“For a second or subsequent offence, the penalty will be a fine of up to $20,000 or imprisonment of up to five years, or both. In addition, clause 5 amends section 13 of the CMA so that the two new offences will apply and our Courts will have jurisdiction over the offences, even if they are committed outside of Singapore. The nature of scam syndicates is that they operate mostly from overseas. Regardless of where these offences are committed, it is critical for us to prevent conduct that amounts to an abuse of Singpass to facilitate scams and other criminal activities and to protect Singpass as Singapore's national digital identity service. Mr Deputy Speaker, these two Bills are necessary to strengthen our collective defence against scams. They seek to disrupt the operations of criminals preying on Singaporeans by acting as guardrails for the use of payment accounts and Singpass credentials and allowing Police to better act against money mules and those who abuse Singpass to perpetrate scams and other crimes. Sir, I beg to move. [(proc text) Question proposed. (proc text)]”
“These proposed provisions are based on actual situations Police have observed, where individuals have deliberately sold or disclosed their Singpass credentials to criminal syndicates. The offence of disclosing an individual's own Singpass credentials will carry a fine of up to $10,000 or imprisonment of up to three years, or both. Again, to be abundantly clear, it is not our intent to criminalise situations where there is a genuine need to share credentials for legitimate transactions. For instance, seniors may, in some situations, need the help of their family members to make Singpass transactions. The new provisions are also not intended to capture persons who were genuinely tricked into giving up their Singpass credentials. Clause 4 of the CMA Bill also introduces a new offence in the form of a section 8B in the CMA, which criminalises acts of obtaining, retaining or dealing in another person's Singpass credentials. This is to deal with those who purchase Singpass credentials and syndicates which trade the Singpass credentials. The Bill introduces provisions in section 8B to clarify the scope of this new offence. It is not an offence if an individual obtained or retained another person's Singpass credentials for a legitimate purpose. It is also not an offence if an individual supplied, offered to supply, transmitted or made available the Singpass credentials of another person for a legitimate purpose and the individual did not know or have reason to believe that those credentials will be or are likely to be used to commit an offence. The offence of obtaining or dealing in Singpass credentials will carry a fine of up to $10,000 or imprisonment of up to three years, or both, for a first offence.”
“But in many others, the Singpass users are uncooperative in investigations and fabricate stories about how their Singpass came to be abused. This situation favours the scammers and it is highly unsatisfactory. Therefore, clause 4 of the CMA Bill introduces a new offence in the form of a new section 8A in the CMA, to address the conduct of Singpass users who deliberately give their credentials to other persons, which are then used to facilitate criminal activities. We are concerned with the behaviour of Singpass users who disclose their Singpass passwords or access codes, or who provide any means of accessing their Singpass accounts in situations where the credentials can then be used to facilitate criminal conduct. In my speech, for ease of reference, I will refer to all of these types of acts collectively as "disclosing Singpass credentials". To combat such behaviour, it will now be an offence for a Singpass user to disclose his Singpass credentials, if he did so knowing, or having reasonable grounds to believe, that the purpose of the disclosure is for any person to commit, or facilitate the commission by any person, of any offence under any written law. The intent of this change is not to make legitimate users of Singpass fearful of disclosing their credentials. They should, however, be aware that in certain situations, the disclosure could be an offence if, one, the disclosure was carried out for any form of gain; two, the disclosure was carried out with the knowledge it would likely cause wrongful loss to any person; or three, the disclosure was carried out but without reasonable steps being taken to find out the identity and physical location of the person to whom the credentials were disclosed.”
“While clause 7 provides that a person could be liable for an offence under any of the four circumstances I described earlier, clause 7 also provides in the new subsection 55A that it is a defence if the person is able to prove that he did not know and had no reason to believe that the property he had dealt with directly through his account, or indirectly, was criminal proceeds. The offence of assisting another person to retain benefits from criminal conduct will carry a fine of up to $50,000 or imprisonment of up to three years, or both. Let me move now to explain the second set of proposed amendments, the amendments to the Computer Misuse Act (CMA). I mentioned the worrying trend of Singpass users who give away their Singpass credentials, often for money. The actions of such errant Singpass users facilitate scams and other criminal conduct. They undermine Singpass as our national digital identity service which many people have come to depend on for digital transactions. However, it is challenging to take such errant Singpass users to task. For example, under the CMA today, it must be proven that the Singpass user knowingly disclosed his credentials for wrongful gain or an unlawful purpose, or that it would cause wrongful loss, which is difficult to do. In one recent case, one Singpass user who had sold his login credentials subsequently pretended to be a victim and came to the Police, claiming that he had been deceived into giving up his Singpass credentials. It was only through extensive investigations, taking up enormous Police resources, that the Singpass user eventually admitted to have sold his credentials, knowing that his Singpass would be used for criminal activities. The authorities managed to crack this case.”
“One, the value of the property he dealt with is disproportionate to his known sources of income; or two, he allowed another person, or persons, to access, operate or control his payment account and failed to take reasonable steps to find out the purpose of this arrangement; or three, he received or transferred money using his payment account and failed to take reasonable steps to find out the source or destination of the money; or four, he received money from or transferred money to another person or persons and failed to take reasonable steps to find out that person's identity and physical location. I will cite an example to illustrate the above offence. Person C responded to a job advertisement by a company. C is told he will earn $100 a day for using his own bank account to receive money from the company's customers and transfer the money to the company's bank account. All these from a purported employer whom he does not ever meet. As unusual as the job may have sounded, C did not question why he needed to use his personal account to receive and transfer money from the company's customers. He did not take steps to find out where the money was coming from or going to. After all, the effort required of him is quite minimal. Why do all these details matter then? Sir, to stop the build-up of such a network of money mules, this new section 55A could render a person like C liable for an offence of assisting another person to retain benefits from criminal conduct.”
“Person B responded to an online advertisement on a social media platform calling for people to "rent out" their bank accounts; it literally used those terms – "rent out". B provided the Internet banking login details for his personal bank account to an unknown subject and was paid $800 to let his personal bank account be used by that subject. B did not know what his bank account was used for. B claimed that he did not suspect anything wrong with the arrangement despite receiving this quite easy $800. Investigations found that his bank account was used to receive about $20,000 from a Singaporean victim of a love scam. To an ordinary reasonable person, this offer would have sounded suspicious and really "too good to be true". Sir, the offence of rash money laundering will carry a fine of up to $250,000 or imprisonment of up to five years, or both. The offence of negligent money laundering will carry a fine of up to $150,000 or imprisonment of up to three years, or both. Based on investigations into scams, the Police have observed conduct common among money mules in facilitating a scam. Hence, clause 7 of the Bill adds a new section 55A which introduces a new offence of assisting another person to retain benefits from criminal conduct. A money mule can be held liable for this offence if his conduct falls within any of the following four circumstances.”
“A person can be liable for rash money laundering if he proceeded to carry out a transaction while he had some suspicions about the transaction, but did not make further enquiries to address those suspicions. A person can be liable for negligent money laundering if he continued with a transaction despite the presence of red flags or suspicious indicators, which would be noticeable by an ordinary, reasonable person. These changes will allow a money laundering offence to be made out against an individual at a lower level of culpability, compared with the current laws. Which of these offences are made out, if any, will depend on the facts and circumstances of the case. Let me share an example where a money mule can be held liable for a rash money laundering offence. Person A responds to an online job advertisement seeking to hire an accounts manager. A was told that he would be paid $2,000 a month to receive money using his personal bank account and all he had to do was to transfer sums of more than $100,000 to other bank accounts weekly. That is all the job requires, allowing the bank account to be used for transfer of monies. It is nothing like the kind of work that would justify a monthly salary of $2,000 that we would normally expect. Despite the exceptional attractiveness of this job, which should have raised suspicions, A did not verify the source of the funds he was receiving, the purpose of the transfers nor the authenticity of his purported employer. Due to the frequency and amount of money transacted, A suspected that the monies could be criminal proceeds, but he chose to carry on without further checks and the money was eventually found to be criminal proceeds from scam victims. I will also share an example of negligent money laundering.”
“Out of 19,000, fewer than 250 ended up being prosecuted. In the OCBC phishing scam which I mentioned earlier, out of the 120 suspected money mules, only nine could be charged for money mule offences. Think about that, it is fewer than one in 10. Similarly, it has been challenging to prove the wrongful intention of those who give up their Singpass credentials under existing laws like the Computer Misuse Act. Clearly, there is a gap that has allowed money mules to continue abetting scammers at little cost to themselves. Why should they be deterred if they can evade prosecution by simply claiming ignorance? The two sets of amendments we are proposing are, therefore, intended to strengthen our collective defence against scams. First, it sets guardrails on the use of bank and Singpass accounts. Bank account holders and Singpass users must be careful and exercise diligence regarding their bank accounts and Singpass credentials. Our bank accounts and Singpass accounts are for our own use. We should not allow them to be used by another person, especially if we do not know who the other party is or what the transactions are for. Second, the amendments will empower the Police to act more effectively against those who blatantly ignore these guardrails, and abuse or allow to be abused, their bank accounts and Singpass credentials to perpetrate scams and other crimes. I will first explain the proposed amendments to the CDSA. Clauses 3 to 6 of the CDSA Bill amend sections 50, 51, 53 and 54 to introduce the offences of rash and negligent money laundering. "Rash" and "negligent" are not new concepts. They are defined in sections 26(E) and 26(F) of the existing Penal Code and are also applied in the Road Traffic Act.”
“Many agreed to facilitate these money transfers because they were paid to do so. They claimed that they did not think that they were doing anything illegal and did not know they were dealing with criminal proceeds. The fact is, however, that their actions caused great harm to scam victims, whose monies have been moved beyond reach, beyond our ability to recover. Besides money mules, the Police have also observed a trend of scam syndicates abusing Singpass to facilitate their criminal activities. For example, syndicates recruit Singpass users with the promise of monetary gain and then use the Singpass accounts to further their schemes. Scam syndicates who get hold of another person's Singpass credentials can use them to open bank accounts, which are then used to receive and transfer funds obtained through scams. Irresponsible Singpass users have facilitated this by selling or sharing their Singpass credentials, such as their Singpass password and SMS one-time password. Scam syndicates effectively assume the identity of a Singpass user for their criminal activities and exploit the Singpass account to commit criminal activities while hiding their own tracks. As a result, these scam syndicates are extremely difficult to pursue. Sir, we must do everything we can to prevent scams from harming Singaporeans. This includes recognising the limitations of current laws, which make it difficult to take the money mules to task. It requires the Prosecution to prove that the money mule had knowledge or reasonable grounds to believe that the monies transacted through his bank account are linked to criminal activity. As a result of these difficulties, of the 19,000 money mules investigated by Police from 2020 to 2022, fewer than 250 money mules were eventually prosecuted.”
“They also include those who use their accounts to receive or transfer monies under the criminals' instructions. Some Members may recall the OCBC phishing scam that occurred between December 2021 and January 2022 – 790 victims fell prey. The total losses amounted to $13.7 million. In this scam, the Police identified more than 120 suspected money mules. More than 120 local bank accounts were used to receive the scam victims' monies. Why do the scammers need money mules? Scam syndicates typically cultivate a network of money mules to facilitate their crimes or to launder criminal proceeds. The money mules' bank accounts form a web of multiple accounts; scammed monies can be split into different denominations and transferred through these accounts. This process is repeated many times over, so that the monies go through multiple layers of bank accounts, before being transferred out of Singapore into the hands of the syndicate. This tactic of "layering" is designed to make it difficult for the authorities to follow the money trail and to get to the perpetrators. Between 2020 and 2022, scammers exploited more than 38,000 bank accounts to launder their proceeds from local victims. Over the same period, more than 19,000 money mules were investigated by the Police. One big problem for the Police is that with electronic transactions, all these actions that I described earlier happen very quickly, often in a matter of hours. Another problem is that when interviewed by the Police, most of the money mules claimed they did not know that they were handling illegal funds. They claimed not to have known the identity of the person who instructed them, nor the identity of the bank account holders whom they were receiving funds from or transferring funds to.”
“Members would have seen the public campaign, "I can ACT against Scams", or hosted outreach sessions by Police officers in their constituency events involving residents. We have taken proactive measures to prevent scammers from being able to reach victims in the first place. For example, the Infocomm Media Development Authority (IMDA) has been working with the telcos to block spoofed calls from reaching Singaporeans. Every month, close to 60 million calls are blocked. We launched the ScamShield app in November 2020, which has been downloaded more than 550,000 times and filtered out more than 7.4 million SMSes that are suspected to be part of a scam. Earlier this Sitting, we tabled the Online Criminal Harms Bill. Among other things, the Online Criminal Harms Bill will help to stop potential scams from taking place, or as soon as they are detected. We have also made it easier to detect and report scams and follow-up with partners. The Police set up the Anti-Scam Command in 2022 to consolidate expertise and resources in combatting scams. Staff from the major banks are co-located with the Police, so that all the parties can quickly act together to freeze scam-tainted accounts. With the help of our foreign partners, Police brought down 13 scam syndicates in 2022. More than 70 persons based overseas were arrested. The Bills we are proposing today will add to our suite of anti-scam measures outlined above. We propose to empower the authorities to deal more effectively with money mules and to prevent the abuse of Singpass for scam operations. First, let me explain the role of money mules. They are individuals who allow criminals to control their bank or other payment accounts.”
“Thank you, Sir. We will still have the Second Reading of the Computer Misuse (Amendment) Bill to comply with the procedural requirements. Sir, scams have become a global problem. Scammers lurk in every corner and victims are often caught unawares. Many scams go unreported, because victims feel embarrassed or do not believe any good will come of their reporting. But even just counting those that were reported, the amount lost to scams worldwide grew by about 16% from 2020 to over $77 billion in 2021. In Singapore, the number of scams has also increased sharply. Police reported that scam cases exceeded 31,000 in 2022. This is more than a fivefold increase since 2018. Scam cases are now more than one-and-a-half times that of physical crime. Back in 2018, they were only a quarter. The amount of money lost to scams is staggering. In 2022 alone, victims lost $660 million. Since 2018, close to $2 billion. Many of us know or have personally heard stories of people who have fallen prey. They include elderly Singaporeans who lost their life savings. Younger Singaporeans are not immune. In fact, more than half of scam victims in 2022 were aged 20 to 39. Victims often lose more than money – they lose peace of mind, sense of well-being, relations with family sometimes become very strained and all of these things bring about great distress. Many scams in Singapore have an overseas nexus. We cannot stop the global tide but must do everything we can to try and keep the scammers far from shore. The Bills we are debating today are part of the Government's multi-pronged strategy to fight scams. We have been educating the public so that they are aware of the signs of scam and know what actions they can take to protect themselves.”
“Mr Deputy Speaker, Sir, I beg to move, "That the Bill be now read a Second time." Sir, this Bill is linked to the next Bill on the Order Paper, the Computer Misuse (Amendment) Bill. May I propose that the debates on both Bills take place together?”
“Even as SNDGG aims to enable Singaporeans to reap economic benefits and productivity gains in the digital age, our fundamental aspiration is to build an inclusive, united and caring society that is “Digital First but not Digital-Only". Together with ServiceSG, SNDGG will ensure that citizen services offered by public agencies remain accessible for less digitally adept Singaporeans, such as seniors and people with disabilities. Non-digital touchpoints and assistance will be made available to these groups of Singaporeans, wherever possible and necessary. SNDGG will also empower our people to use digital tools to participate fully in society. We will support efforts by MCI to promote digital skills and literacy in our people, such as the Digital for Life movement led by the Infocomm Media Development Authority, which galvanises the community to help citizens of all ages and from all walks of life embrace lifelong digital learning. Digital technologies will empower Singapore to discover new opportunities and make our mark on the world. With our people, private and public sector partners, SNDGG is committed to building a Smart Nation where everyone has a place.”
“We will also drive advancements in Singapore’s cyber-physical infrastructure with URA, including scaling innovative solutions in estate management from Punggol Smart Town to other districts. Finally, SNDGG will refresh the Digital Government Blueprint in end-2023 and strive towards more discoverable, personalised and seamless Government services. We will work closely with ServiceSG to redesign whole-of-Government service delivery. This includes promoting the use of common digital platforms across Government and building up the Government’s data sharing and data usage architecture. As more of our lives and Government services move to the digital space, it is essential to maintain trust in public institutions and secure the digital platforms hosting these services, so people feel safe and protected against scams. This will set Singapore apart from other world-leading digital hubs. First, SNDGG will roll out the CheckWho product in end-2023 to help the public verify the legitimacy of calls from public officers. Second, SNDGG will ensure that transactions on Government platforms are secure and resilient with tools to better detect phishing sites that pose as Government agency websites, and fraud analytics solutions for Singpass. We will also continue to move more eligible Government systems to Cloud to improve resilience, security monitoring and threat detection. Finally, SNDGG will work with the community to bolster digital trust and safety. We will support the National Crime Prevention Council and the Singapore Police Force to foster a culture of vigilance and contribution to scam prevention through applications like ScamShield.”
“The Smart Nation and Digital Government Group (SNDGG) aims to harness technology to secure opportunities for all, build trust and safety, and foster an inclusive Singapore community. We work closely with other Government agencies to ensure technology bolsters Singapore’s resilience and improves the lives of Singaporeans. Digital technology offers significant opportunities for businesses, people and Government agencies. SNDGG will enable all to seize these benefits through close partnerships with Government agencies, industries and research players, and with robust digital and cyber-physical infrastructure anchored by a strong Digital Government. First, SNDGG will leverage technology to facilitate the business activity, growth and innovation of Singapore-based enterprises. Together with the Ministry of Trade and Industry, we will enhance the one-stop GoBusiness digital platform to support firms’ day-to-day transactions and longer-term investments, such as in equipping workers with future skills. We will work with the Ministry of Communications and Information to support the digital economy through initiatives like the SG Financial Data Exchange. We will make it easier for businesses to tap on the expertise of public research players for innovation, such as through the JTC-Singapore Institute of Technology Living Lab testbed, and the Urban Redevelopment Authority (URA)-Smart Nation and Digital Government Office Jurong Lake District Innovation Challenge. Second, SNDGG will use technology to transform the lived experiences of citizens. We will improve the convenience of digital services and transactions through applications, such as Singpass and LifeSG.”
“MCI is committed to doing our part, alongside the public and our partners, to meet the challenges ahead and build a thriving digital future for all.”
“MCI will also support efforts to protect public interest and trust by providing the public with a reliable source for facts, addressing misperceptions, and alerting the public to scams and other threats. MCI is committed to building and strengthening our Singapore communities in both offline and online spaces. We will continue to provide timely, accessible, and inclusive Government communications, through in-person engagements as well as traditional and digital media platforms, to reach Singaporeans from all walks of life. We will also engage the community through REACH, to better understand stakeholders’ views, needs, and aspirations. All Singaporeans should be able to participate meaningfully in society and reap the benefits of digital technologies, regardless of ability or personal circumstances. MCI will expand its digital inclusion efforts by: (a) providing subsidised devices and internet access under the DigitalAccess@Home and Mobile Access for Seniors schemes; (b) offering tailored training and assistance for the elderly and other groups through the Info-communications Media Development Authority’s SG Digital Office; (c) organising outreach efforts under the National Library Board’s Libraries and Archives Blueprint 2025; and (d) mounting people, private and public partnerships under the Digital for Life movement. Access to credible sources of information and content that reflect our Singapore voice and values is vital to our social cohesion, cultural heritage, and national identity. MCI will support the creation and delivery of high-quality news and content across various media platforms and languages to the public. We will also continue efforts to implement subtitling or sign language interpretations for more free-to-air television programmes.”
“We will also help workers, both within the information and communications sector and across the economy, upskill and deepen their proficiencies in high-demand areas such as 5G, artificial intelligence, and cybersecurity. As part of the Forward Singapore exercise, we will work with the Ministry of Manpower and Ministry of Education, as well as industry partners, to ensure that good opportunities remain accessible to all, through initiatives such as the TechSkills Accelerator for ITE and Polytechnics Alliance. Trust among our people, and in our institutions and systems, is essential to the continued vitality and resilience of our society and economy. MCI takes a comprehensive approach to building and strengthening trust. MCI will continue to protect users from harmful online content, with codes of practice for social media services and app stores, and advisory guidelines for the protection of personal data. Through the Singapore Cybersecurity Strategy 2021, MCI and the Cyber Security Agency of Singapore will also enhance efforts to protect our critical information infrastructure and other important systems and entities from cyber threats, and raise the cybersecurity posture of companies and individuals through the Cybersecurity Labelling Scheme and Cybersecurity Trust and Essentials Mark certification programmes. MCI, together with partners from industry, academia, and the community, will grow the digital, information, and media literacy of Singaporeans, and promote better social cohesion, wellness, and health outcomes. MCI will continue to coordinate Whole-of-Government public communications on major national issues to ensure that the public receives timely and accurate information.”
“The Ministry of Communications and Information (MCI) seeks to enhance opportunities, sustain trust and strengthen our communities to reap the full benefits of digital and technological advances, while mitigating the potential harms. MCI will work with partners to develop a new Digital Connectivity Blueprint for strategic, sustainable, and future-ready digital infrastructure. We will also continue investing in research and innovation, including in quantum technologies and artificial intelligence, as part of Singapore’s Research, Innovation, and Enterprise 2025 Plan. These efforts to enhance digital infrastructure and encourage innovation are the foundation for our businesses and people to thrive in a digital age. MCI will continue to support digital transformation of our businesses, particularly to help Small-Medium Enterprises improve their productivity and access new markets. MCI will scale adoption of digital utilities that support core business functions, such as e-payment and e-invoicing. MCI will also refresh the schemes to help firms improve their cybersecurity posture and raise their overall digital maturity. These will be brought together under the new Digital Enterprise Blueprint, a comprehensive guide to the Government’s support for enterprise digitalisation. We will also work with partners to shape international rules, benchmarks, and norms, through Digital Economy Agreements and other initiatives. MCI will continue to help Singaporeans raise their digital proficiencies, both to access digital services and navigate confidently online, as well as to access good opportunities in tech. Initiatives under the Information and Communications Jobs Transformation Map will equip tech workers with the tools to stay competitive.”
“The Government must strike a balance between introducing frictions to protect against abuse by some and usability for the vast majority.”
“The Government is aware that automated bots may be used to secure limited goods, slots or services on various websites, including Government-linked online reservation systems. Some errant users have gone further to use these bots or encourage others to lend their accounts to them, so that they can resell the slots for profit. Such actions undermine the fairness of the booking process and crowd out legitimate users. The Government, therefore, pays close attention to instances of abuse and takes prompt actions to stop them. For example, since early 2021, SportSG has stepped up its on-site enforcement measures. A person who books a slot must be present and be part of the playing party or risk the booking being cancelled. In addition, SportSG conducts periodic checks on suspicious booking patterns in the ActiveSG system and on-selling activities across various social media platforms. If suspicious booking patterns are found, the accounts will be suspended for a period of three months for the first time and 12 months for repeat violations. Since 2021, more than 600 bookings have been cancelled for on-selling activities and about 200 ActiveSG accounts have been suspended for suspected bot usage. Government agencies have also put in place technical measures, such as the use of Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA), introduction of delays between login attempts and web application firewalls with bot control features, to detect and prevent automated bots from launching actions on websites. As technology evolves, bots will become more sophisticated and require newer countermeasures. These may come at a cost to the user experience, including to persons with disabilities or who have intermittent access to the Internet.”
“The Public Service keeps an active lookout for tech talent keen on contributing to public good. Besides the Smart Nation Scholarship programme, we offer internships to tertiary students. Experienced tech specialists may be offered Smart Nation Fellowships to do short stints and work on innovative projects with us. In addition, agencies conduct their own recruitment exercises and participate in joint recruitment efforts involving other organisations. We welcome persons of all backgrounds, including those who may have been laid off, as long as they meet the job requirements and are keen to serve the public. A few months ago, the Government also launched the “Tech for Public Good” initiative to accelerate tech hiring for the Public Service. As part of the initiative, we set up a new microsite, techhiring.open.gov.sg, to publicise available tech-related openings across all agencies. Since then, we have conducted 15 career talks that attracted over 800 attendees. More than 100 positions have been filled.”
“AISG has various AI literacy outreach efforts. More than 100,000 attendees participated in its "AI for Everyone" programmes as well as courses catered to a younger audience. As in other fast-growing fields worldwide, demand for talent will likely exceed supply for some time. The Government will continue working with partners to scale up our efforts and empower more of our citizens to access these valuable opportunities.”
“The Government recognises the potential of artificial intelligence (AI) and has, since 2019, implemented the National AI Strategy to broaden and deepen the use of AI in Singapore. Talent is a key enabler to drive AI innovation and adoption and the Government has taken proactive steps to grow our AI talent pool in different but complementary ways. First, we are growing a pipeline of talent to support the translation of AI advancements into new products and services. The TechSkills Accelerator (TeSA) initiative has placed and trained more than 2,600 individuals in AI and data analytics job roles since 2016. With support from TeSA, AI Singapore (AISG) has also partnered companies to train mid-career Singaporeans to take up good AI-related jobs. Through AISG’s Programme, trainees receive hands-on training on projects contributed by participating companies and Government agencies. Results have shown that, given the right training, our local workforce is capable of seizing opportunities in AI, with 80% of participants receiving multiple job offers before graduation and also benefiting from an average pay increase of 25%. Second, we continue to expand the pool of top-quality local AI research talent. Researchers in Singapore are already internationally recognised leaders in fields of AI research, such as natural language processing and computer vision. Later this year, the Government will partner AISG to introduce an AI Investigatorship to target top-tier AI researchers who can mentor promising local talent. This complements AISG’s PhD Fellowship Programme in 2020, which supports top research talents in advancing fundamental AI research here in Singapore. Third, we are growing awareness of AI’s value and potential in the wider economy and society.”
“Regulations and interventions by the Government, are only part of the solution. Support from the community, including families, remains vital. The Government will continue to work with the community to find ways to educate the public on radicalisation.”
“Singapore adopts a zero-tolerance approach towards radicalisation and any form of extremist ideology. The Online Safety (Miscellaneous Amendments) Act, which took effect from 1 February 2023, provides the Infocomm Media Development Authority with levers to disable access to online content that advocates or instructs on terrorism or violence. While the levers are currently limited to social media services, the Ministry for Communications and Information will be looking into measures to strengthen online safety in other services. This includes online games that can be accessed via various platforms, including App Stores. More details will be announced when ready. The Ministry of Home Affairs (MHA) will be introducing legislation to combat online criminal harms, which will cover content that incites terror-related activities. Levers under the legislation will cover all mediums of online communication through which criminal activities could be conducted. A whole-of-society approach is necessary to mitigate the dangers of extremist ideologies and radicalisation in Singapore. For example, MHA has also been reaching out to neighbourhoods, schools and workplaces to raise public awareness of the threat of terrorism and online radicalisation and the importance of early reporting. This is done through the SGSecure movement, as well as through community organisations, such as the Religious Rehabilitation Group (RRG) and the Inter-Agency Aftercare Group (ACG). For example, RRG and ACG conduct regular community outreach through visits to RRG Resource and Counselling Centre, assembly talks and youth forums to sensitise members of the public to the terrorism threat and strengthen the community's resilience against extremist ideas.”
“As the custodian of Government records of national or historical significance, the National Archives of Singapore (NAS) works with Government agencies to facilitate access to Government records that have been transferred to NAS. Since 2016, Government agencies have reviewed more than 5,000 Government records that were not declassified in response to 2,130 requests by members of the public. Eighty-three percent of these records have been approved for access. In total, some 68,000 file records have been declassified and are available for access.”
“Was there one more question that was not answered?”
“As was also mentioned in the media today, we are looking at whether an option can be made available to subscribers to decide that they do not want to be on the receiving end of overseas calls at all because the vast majority of scam calls originated from abroad. In some instances, people know very well that they do not have an overseas network. They have no reason to be receiving an overseas call. In order to prevent themselves from falling victim, they would rather not receive these calls. That is an option that we are studying together with the telcos. We hope to be able to update you soon.”
“Mr Chairman, firstly, I would like to thank Ms Hany Soh for her acknowledgement of my colleagues' efforts during the COVID-19 pandemic. I think not only are they gratified, more importantly, they appreciate the fact that they were able to make a contribution to help Singapore through a very difficult period. To your question on scams, you are right. Minister of State Sun Xueling had covered it in fairly great detail during the COS debate for MHA yesterday. One of the things that she described was the multilayered approach that we take in fighting scams. There are interventions at the level of the individual. There are also interventions at the level of financial services – the banks, primarily. Another very important layer that you described is intervention within the telco infrastructure. Some of the things that we have done include blocking scam calls as well as SMSes. We have progressively implemented default blocking of overseas calls that are spoofing local numbers – this has been in place since last July – as well as the in-network scanning of SMS content for malicious URLs – links that could be carried within these SMS messages. This has been in place since last October. Just to give you a sense of the scale of the impact of these measures, just during the time that I took to deliver my COS speech – I believe it was something like 28 minutes – during that time, we would have blocked about 40,000 malicious calls. Just in that time, 40,000. What that means is that each month, we are getting 57 million fewer spoof calls. They have been blocked. Since this January, we have, of course, mandated the SMS Sender ID Registry for those that use alphanumeric headers for their SMSes. So, that is something that has been worked on.”
“Mr Chairman, I thank Mr Pritam Singh and also appreciate his comments that the scheme is to be welcomed. The income criteria that is applicable, I think it is not directly comparable because it is a merger of two schemes. In any case, the eligibility criteria is gross household income of less than or equal $1,900 per month. But if a household has school-going children or a person with disability, we actually bump it up to $3,400. This is to recognise the greater needs of such families.”
“Thank you, Mr Chairman. I thought that I will respond briefly to Ms Tin's question of what we are doing to help school-going children to acquire the digital skills. Firstly, I think it is a very pertinent question because we have said on multiple occasions that digital access is one thing. If people are not able to acquire the skills that allow them to maximise the benefits of digital engagement, then it still does not go far enough. We have spent quite a lot of time talking about seniors. With school-going children, there are two separate tracks of efforts that are proceeding in parallel. One group is in collaboration, of course, with the Ministry of Education, through the school system. I mentioned earlier in my speech that there is a very specific enrichment programme that has been implemented for some years now. We are constantly looking at how its contents can be refreshed and made even more relevant, as well as broadening its coverage. The other track of effort has to do with providing additional support for children from disadvantaged backgrounds. For this purpose, we are very fortunate to have the support of our partners – through the DfL movement. Not only do these companies bring together their knowledge and understanding of how technology is changing our lives, they are usually also able to mobilise volunteers. Quite frequently, these volunteers are drawn from within their staff strength. So, these are two broad strands of efforts that are ongoing, and we will certainly continue to look at ways to strengthen them further.”
“In addition, by positioning ourselves as a thought leader, we are better able to partner like-minded countries and shape new international norms in digital. Promising developments include our chairmanship of the United Nations Open-Ended Working Group on ICT Security, the Digital Economy Agreements with Australia, the UK and South Korea, or the US-Singapore Partnership for Growth and Innovation, the Smart City Initiative with Shenzhen, the ASEAN Data Management Framework which we initiated and the Digital Forum of Small States (Digital FOSS) which we championed. These initiatives are opportunities for our voice to be heard and our economic space to expand. There are no guarantees that we will succeed in every project, nor can we be sure that global developments will always be favourable. But our foundations are strong, and our investments will bear fruit. Working with our partners at home and abroad, I am confident we can empower Singaporeans to thrive in our digital future.”
“Berita Harian has produced podcasts discussing social and geopolitical issues, and Tamil Murasu is on track to launch its mobile app this year. These efforts have paid off especially with younger viewers. An MCI survey showed that 82% of 15- to 24-year-olds regularly consumed local mainstream news via online platforms in 2021, a jump of around 30-percentage points since 2018. That said, our media has lots more to do. As Singaporeans’ news consumption habits continue to evolve, both SPH Media Trust (SMT) and Mediacorp will have to continue demonstrating progress. True transformation will not come just through new technologies but from mindset changes. Journalists will need to develop new skills and have the support of management in this process. The road ahead is long and difficult, and we should not underestimate the effort required. When it comes to promoting information literacy, the National Library Board (NLB) also plays a critical role. To questions by Ms Tin Pei Ling, since 2013, NLB’s flagship information literacy programme, SURE, has been helping citizens navigate our dense information landscape. Complementing these efforts, NLB launched the “Read to be SURE” campaign in November 2021 to further promote critical thinking. The campaign helps Singaporeans hear from different voices on topical issues such as cryptocurrency or gender equality. Since inception, it has garnered over 220,000 engagements. Mr Chairman, let me conclude by touching on the international significance of our efforts in digital. Today, Singapore is considered one of the leading countries in digital developments, at the frontier of digital infrastructure and regulation. This has brought real economic pay-offs.”
“Members will recall that Open Government Products (OGP) has integrated ChatGPT into Microsoft Word and plans to trial its use among some civil servants. As more use cases are developed, we will monitor developments to support AI innovation whilst protecting our people. Emergent technologies that are immersive, decentralised and anonymous, including the metaverse and Web 3.0, could also introduce new types of online risks. We will continue to review our measures to keep in step with technological trends. I will now turn to the third theme of my speech – promoting trust to build social resilience. To withstand online misinformation, Singaporeans must have trusted and easily accessible sources of information. In their absence, we cannot assume that our society will hold together. A citizenry that is informed and information-literate helps to strengthen social resilience. This is a key reason for supporting our Public Service media. To Ms Jessica Tan's question, our local media's digital capabilities have strengthened considerably in the last few years. To grow online outreach, especially to the young, they have used digital technologies to tell stories in innovative ways. For example, Mediacorp has used augmented reality in its coverage of the Russian-Ukraine war. The Straits Times has used interactive graphics to report on how our HDB flats have changed over the decades and the impact of rising sea levels on our shoreline. Some of these efforts have won international acclaim. 4.15 pm Our vernacular media are also making efforts to go where audiences are. For example, Mediacorp has launched a digital-first Chinese-language debate programme, “Frontline Connects” or《前线开讲》 that caters primarily to younger audiences online.”
“CSA is hence examining how we can develop our entire cybersecurity ecosystem, ranging from nurturing talent to promoting innovation and capability development. We will provide updates on this as well as the Cybersecurity Act review later this year. Let me briefly discuss our approach to emerging technologies, which Ms Tin had asked about. By now, Members are all aware of seminal developments in AI, including tools like ChatGPT. While AI brings many benefits, it also brings risks we must mitigate. This is important because AI is increasingly commonplace. Members will recall that in 2019, Singapore launched a Model AI Governance Framework. Last year, we also launched AI Verify, the world's first AI Governance Testing Framework and Toolkit. We will build on these initiatives to strengthen the guardrails that ensure responsible AI development and deployment. Let me mention two Advisory Guidelines that will be published by the Personal Data Protection Commission (PDPC) later this year. The first is on the use of personal data in AI systems. This will encourage AI users to abide by standards of transparency and explainability so that customers will know when and how AI is being used to process their personal data. It will also contain best practices on how industry can use personal data to train, test and monitor AI systems. The second is on children's personal data. This will set out clear actionable standards for social media services and companies whose products interface with children. For instance, they must obtain parental consent before collecting data from children under the age of 13 and implement protective defaults such as making sure that children's profiles are not made public. There are many more questions about AI that deserve our attention.”
“A survey covering both parents and children will allow us to better understand the issues and shape our response. This may include working with the people sector to support the vulnerable groups which Mr Baey Yam Keng had identified. The survey will examine exposure of children to unwanted interactions and inappropriate content on gaming platforms. It will also examine the social and psychological impacts of gaming, extending beyond problematic content. This requires extensive work and we will do our best to be timely. Next, I will briefly discuss cybersecurity. Cybersecurity has become a crucial aspect of national security, especially for a country as digitally connected as Singapore. During last year's debate, I announced that the Cyber Security Agency of Singapore (CSA) was reviewing the Cybersecurity Act, which only came into effect in 2018. Since then, CSA has held discussions with its stakeholders, including owners of Critical Information Infrastructure (CII). We have also engaged trade associations and key industry players. We have made good progress and will start formal industry consultations next month. One area under review is how we will adapt our regulatory framework to allow the safe and secure use of virtualised systems beyond CII. Specifically, CSA has identified cloud services and data centres as foundational digital infrastructure we need to better protect. As this is a new area, our discussions with the industry will be important in ensuring that our regulations remain effective. With increasing industry digitalisation, demand for cybersecurity services has been growing domestically and overseas.”
“To Ms Tin Pei Ling's and Ms Janet Ang's questions, we will take another step to strengthen online safety through a new Code of Practice for App Stores. App stores may carry apps with harmful content, especially for children. This could include content depicting explicit sexual activities or inciting violence. As with social media services, app stores should be expected to have systems and processes in place to deal with harmful content. The new code will take time to be developed and involve industry engagement. We will work out the details and update Members in due course. In the debate on the Bill, there was also strong interest from members for MCI to look into online games. When the new Code for App Stores is introduced, the risks of exposure to harmful content through games on these stores will be curtailed. Apps with egregious content may also become unavailable for download. But games may also be accessed through platforms other than app stores. We will have to study how to deal with this. A possible measure is to introduce a classification scheme for online games, much as we already do for video games. This will clarify the age-appropriateness of games and help parents exercise better supervision over their children's online gaming. We will work towards these moves over the next 12 to 18 months. We have also started a detailed landscape survey on online gaming to assess if more can be done, for example, to reduce the risk of cyber addiction, which Ms Hany Soh was very concerned about. This survey is necessary because there is no international consensus on the nature of the problem or the effectiveness of measures. The concerns in Singapore are also not fully understood.”