Scammer Working on Laptop in Singapore

What the proposed law says about buying, renting, borrowing, or controlling someone else’s account

Buying an established social media or chat account can look like a shortcut. It may already have followers, a local identity, a posting history, or access to features that a brand-new account does not. But under Singapore’s proposed anti-scam changes, receiving an account for criminal use could become a specific offence.

The Scams (Countermeasures) and Other Matters Bill was introduced in Parliament on 4 August 2026. Among other changes, it proposes an offence covering the receipt or control of designated online accounts when the person intends to use or supply the account for crime, or for wrongful gain or loss.

The Bill was still at the First Reading stage on 13 August 2026. So this article describes a proposal, not an offence that is already in force. The final wording, the start date, and how it is enforced will depend on the rest of the process.

Why receiving an account is treated as a separate problem

Scam networks need a steady supply of accounts. Some people create accounts and sell them. Others collect, organise, and pass the accounts on to operators. A recruiter may buy accounts from many individuals, while a scammer may rent a verified profile for just a few days.

If the law only targeted the original account holder, the buyer or operator could avoid a direct account-dealing offence even though they deliberately obtained the account for a scam. The proposed receiving offence targets this other side of the deal.

It also covers people who keep control of an account opened using someone else’s personal information. This reaches situations where an operator gets another person to complete the identity checks, but keeps the password, recovery details, and day-to-day control.

What “receiving” includes

The proposed section uses several words. A person may commit the offence by buying, renting, borrowing, or otherwise receiving a designated online account. Offering to buy, rent, borrow, or receive an account is also included.

The transfer does not need a formal sale agreement. It could be a temporary loan, a revenue-sharing arrangement, or a swap. Payment is not always needed, though acting for gain has an important effect on how intention can be proved.

Receiving an account also includes receiving the information that lets you control it. The Bill gives examples such as a username, password, or user authentication code. This makes sense, because online control usually passes through login details rather than a physical object.

Keeping control of an account opened with someone else’s details

The offence also covers keeping control of a designated online account that was opened using someone else’s personal information. This can happen when a recruiter asks a person to complete the account verification, then takes over the profile.

For example, Person A might use Person B’s identity details to create a verified account. Person A keeps the password, the connected device, and the recovery email. Person B may look like the registered user, but Person A actually runs the account. If Person A keeps control with the required criminal intention, the proposed offence may apply.

This wording matters for account farms. Scam syndicates often prefer profiles that look like they belong to real local users. They can use those profiles to advertise fake goods, impersonate businesses, or contact victims with less chance of an instant platform block.

The required intention

Simply receiving access is not enough on its own. Under the proposed wording, the person must intend to use the account, or supply it to someone else, for one of two broad purposes.

The first is to commit or help an offence under written law. The second is to cause or help wrongful gain or wrongful loss to any person.

So the prosecution must address the recipient’s purpose. Evidence might come from messages, payment arrangements, account activity, instructions, connected devices, or the way several accounts were obtained and managed.

The wording can reach a person who plans to pass the account further down the chain. The recipient does not have to be the one who eventually sends the scam message.

How gain may affect the case

The Bill proposes a presumption in certain proceedings. If a person receives an account for gain, they may be presumed, until they prove otherwise, to have intended to use or supply the account to commit or help an offence.

Gain can make an arrangement look less innocent. A person paid to collect verified accounts cannot safely ignore obvious warning signs. But a presumption does not make every paid account transfer automatically criminal. The specific offence, the evidence, the lawful purpose, and the chance to prove otherwise still matter.

Legitimate businesses should record why control was transferred and what the payment covered. A marketing agency may be paid to manage a client’s profile, but that payment is for a lawful professional service. Written authority, platform role access, and a clear scope of work help show the difference.

A lawful-purpose protection

The proposal says a person does not commit the receiving offence if, at the time, there were reasonable grounds to believe the aim was to allow lawful use of, or access to, the account.

This protection is essential, because people receive account access every day for proper reasons. An employee may take over a brand account. An IT admin may recover a user’s login. A buyer of a genuine business may receive its marketplace and social media accounts as part of the deal.

Still, the belief must have reasonable grounds. Make checks that fit the risk. If the account is verified in someone else’s name, confirm ownership, authority, and the reason for the transfer. Secrecy, unusual payment methods, and instructions to hide the new controller are all warning signs.

A completed scam may not be necessary

The Bill states that, to prove whether the account was used to commit or help an offence, the prosecution does not need to prove that a specific offence happened.

This allows action before a victim loses money. Suppose a person buys 100 verified chat accounts and receives scripts for pretending to be bank staff. The operation might be stopped before the accounts are fully used. The lack of a completed scam would not necessarily block a charge if the elements of the account-receiving offence can be proved.

This reflects the preventive aim of the Bill. Online scam infrastructure can be harmful even before it produces a completed offence.

Proposed penalties

For an individual convicted for the first time under the proposed receiving provision, the maximum is a S$10,000 fine, up to three years in jail, or both.

For a second or later conviction, the maximum rises to a S$20,000 fine, up to five years in jail, or both. An organisation could face a maximum fine of S$20,000 for a first conviction and S$40,000 for a second or later one.

An individual could also face caning of up to 12 strokes in a specified case. This extra punishment is linked to an intention to use or supply the account to commit or help a scam offence. The Bill says the scam itself does not need to have been carried out for that provision.

Actual penalties in a real case would depend on the charge, the proof, sentencing law, and the facts. The figures above are the maximums in the Bill, not automatic sentences.

Common account offers that should worry you

Some requests are especially risky:

  • Buying an older Facebook or Instagram profile because it “looks trusted”
  • Renting a Telegram or WhatsApp account for a short campaign without knowing the advertiser
  • Collecting verified marketplace accounts for a buyer who refuses to identify themselves
  • Taking control of accounts opened by people recruited through quick-cash adverts
  • Receiving Apple or Google accounts together with recovery codes and identity details
  • Being paid per account and told to change the login location immediately
  • Keeping accounts ready for an operator who will tell you later what to post

The risk goes up when the other party wants local-looking accounts, asks for secrecy, or promises unusually easy money.

How legitimate transfers should be handled

A lawful handover should be transparent. Check the registered owner and the person giving authority. Record the purpose and expected length of access. Use the platform’s business manager, delegated role, or admin function where you can.

Do not change recovery details in a way that hides the true owner, unless a genuine ownership transfer needs it. Keep the sale agreement or client contract if the account is part of a business deal. Record which staff have access, and remove it when the work ends.

For agencies, a central access register can help. It should note the client, the account, the approved users, the date access started, the lawful purpose, and the date access ended. This makes unusual activity easier to investigate.

What to do if you unknowingly received a suspicious account

Stop using the account and do not pass it to anyone else. Keep the messages, payment records, usernames, recovery details, and instructions connected to the transfer.

Contact the platform through its official reporting process. If there are signs of scam activity, report it to the Police. Explain when and how you received access, what you were told, and what you did before you realised the risk.

Do not try to “clean” the account by deleting messages or changing its history. Those actions can destroy evidence and make things harder to explain. If the situation is serious, get legal advice before giving a detailed statement.

What parents and educators should explain to young users

Young people may have long-standing accounts that scammers find valuable. They may also be tempted by small payments for an account they no longer use.

The key message should go beyond “do not share your password”. Students should understand that selling, renting, or borrowing online identities can support real fraud. A profile with local contacts and a normal history can make a fake offer look believable.

Encourage young people to speak up early, without immediate panic. If a young person admits transferring an account, secure it, keep the evidence, and report any suspicious use. Delay only gives the buyer more time to reach victims.

The main takeaway

Under the proposed law, a person who deliberately obtains or controls someone else’s designated online account for criminal use could face a specific offence. Receiving login details can count as receiving the account, and receiving an account for gain may trigger a presumption in certain cases.

The safest rule is simple. Do not buy, rent, or borrow online accounts from strangers. For genuine business access, verify identity, record authority, and use official role-based tools. An established digital identity is valuable, and that is exactly why scam syndicates want it.


Frequently Asked Questions

1. Does logging in once count as keeping control of an account?

One login does not decide the issue by itself. The surrounding facts, your ability to control the account, and the required criminal intention would all matter.

2. What if the account details were posted publicly and anyone could use them?

Being public does not make criminal use lawful. A person who takes control with the intention required by the proposed offence could still be at risk.

3. Is storing someone else’s password in a password manager the same as receiving the account?

Storage for an authorised lawful purpose is different from taking control for criminal use. Even so, businesses should limit who can reveal or use stored login details, and keep audit records.

4. Can the registered owner recover an account from a recipient without paying them?

The owner should use the platform’s official recovery and impersonation processes. Paying an unknown controller may just invite more demands and does not guarantee you get the account back.

5. Can someone take over an abandoned community account?

An account that looks abandoned still belongs to someone under the platform’s rules. Use official recovery or admin procedures and get the organisation’s consent, rather than taking the login details informally.

Thank you for sharing this article...
About the Author: Randy Alta
Randy Alta holds a Juris Doctor degree and currently works as a legal researcher supporting Singapore-based and international clients. His areas of experience include family law, corporate and commercial law, criminal law, and the mediation of cross-border business disputes.