ScamCheck
impersonation

iMessage Scams: Impersonation Phishing via Police, Courts, Courier

Published by ScamCheck · 10 August 2026

As reported by Straits Times - Scam News (Singapore), iMessage scams involving impersonation of police, courts, and courier firms are costing victims millions. We explain the insidious tactics behind these phishing attacks, from spoofed sender IDs to sophisticated social engineering, so you can prot

What Is iMessage Impersonation Phishing and Why Is It Dangerous?

This scam leverages Apple's iMessage platform, which many users trust, to deliver deceptive messages that appear to come from legitimate organisations. Scammers impersonate trusted entities like the police, courts, or even popular courier firms. Their ultimate goal is often identity theft, credential harvesting, or direct financial fraud. According to Straits Times - Scam News (Singapore), these scams are incredibly effective, with more than $1.2 million lost to scams involving courier firms and Apple’s iMessage alone. The danger lies in the high level of social engineering involved and the apparent legitimacy of the messages, making it difficult for unsuspecting individuals to discern the fraud until it’s too late.

How Does This Scam Work? (Step by Step)

We've analysed hundreds of such messages and observed a consistent pattern in how these iMessage impersonation scams unfold:

  1. Initial Contact (Spoofing): The scam begins with an unsolicited iMessage. Scammers often use sophisticated spoofing techniques to make the sender ID appear official, mimicking legitimate numbers or names associated with police departments, court systems, or well-known courier services. This initial trust is crucial for their social engineering efforts.
  2. Urgency and Fear Tactics: The message typically contains alarming or urgent language. For instance, it might claim you have an outstanding court summons, an unpaid fine, a parcel stuck in customs, or an issue with your digital identity account (like Singpass in Singapore, which some scams have targeted, leading to compromised work permit holders’ accounts as reported by Straits Times).
  3. Call to Action (Malicious Link): The message then directs you to take immediate action, usually by clicking a link embedded within the iMessage. This link is almost always malicious, designed to lead you to a phishing website.
  4. Phishing Website (Credential Harvesting): Once you click the link, you are redirected to a fake website that looks identical to the legitimate organisation's official portal. Here, you'll be prompted to enter sensitive information: your full name, identification numbers, Singpass credentials, bank details, or credit card information. This process is known as credential harvesting.
  5. Data Theft and Fraud: Once scammers obtain your personal data, they can use it for various malicious activities, including making unauthorised purchases, applying for loans in your name (identity theft), or directly accessing your bank accounts. In some cases, the "issue" is resolved by asking for a small "processing fee," which is a direct financial theft.

What Are the Warning Signs?

Be vigilant for these specific red flags in iMessages:

Scam vs Legitimate: How to Tell the Difference

Scam Behaviour Legitimate Organisation Behaviour
Uses generic greetings and urgent, threatening tone. Addresses you by name, uses professional and clear language.
Demands immediate action via a provided link. Provides official channels for verification (e.g., official website, hotline) before any action.
Requests sensitive personal or financial details directly via a link in the message. Asks for personal details only through secure, authenticated portals you initiated.
Malicious links lead to poorly secured or fake websites with slightly altered URLs. Links direct to official, secure websites (HTTPS) with correct, verifiable domain names.
Threatens legal action or financial penalties for non-compliance via iMessage. Sends formal notices via official mail or secure authenticated communication channels, not unsolicited iMessages for urgent action.

Who Is Being Targeted and Why?

These iMessage scams often cast a wide net, targeting anyone with an iPhone or iPad, as iMessage is pervasive. However, victims who reported this scam described a particular vulnerability among individuals who are less tech-savvy, those who are easily intimidated by authority figures (like police or court impersonators), or those expecting a delivery.

Scammers target these individuals because:

What Should You Do If You Receive This?

If you receive a suspicious iMessage impersonating a government agency, police, courts, or a courier service:

  1. Do NOT Click Any Links: This is the most critical step. Clicking the link can expose you to malware or lead you directly to a phishing site.
  2. Do NOT Reply: Engaging with the scammer confirms your number is active and might lead to more targeted attacks.
  3. Verify Independently: If you're concerned the message might be legitimate, do not use any contact information provided in the suspicious message. Instead, directly contact the organisation using their official phone number or website (obtained from a trusted source like their official government website or a general search, NOT the message itself).
  4. Block the Sender: Block the number to prevent further messages from that sender.
  5. Report the Message: Report the message as junk or spam within iMessage. You can also report it to your local cybercrime authority. In Singapore, you would report it to the police. If you have been affected, report to your local cybercrime authority immediately.

How Can You Stay Safe?

Prevention is always better than cure when it comes to online scams.

Verified by ScamCheck Research Team. Source: Straits Times - Scam News.

Frequently Asked Questions

Can scammers really send iMessages that look like they're from the police or courts?

Yes, scammers use sophisticated spoofing techniques to make their iMessages appear to originate from legitimate entities like the police, courts, or courier firms. This is a common social engineering tactic to gain your trust and trick you into clicking malicious links or divulging sensitive information. Always verify such messages independently using official contact details.

What kind of information are scammers trying to steal with these iMessage scams?

Scammers are primarily after sensitive personal and financial information. This can include your full name, national identification number (like Singpass credentials), date of birth, home address, bank account details, credit card numbers, and login credentials for various online services. This stolen data is then used for identity theft or direct financial fraud.

I clicked a suspicious link in an iMessage but didn't enter any information. Am I still at risk?

While not entering information reduces the immediate risk of credential harvesting, clicking a malicious link can still be dangerous. It could potentially download malware onto your device, although iOS is generally more resilient to this than other platforms. It's best practice to run a security scan if possible, monitor your device for unusual activity, and reset passwords for any accounts you might have been logged into at the time, as a precautionary measure.

Received a suspicious message?

Paste it into ScamCheck and get an instant AI verdict — free, no signup needed.

Check it now — it's free