THE BROAD VIEW

Businesses need to detect online impersonations before customers do

When an organisation’s identity is used to deceive, the damage can affect public confidence in its services

Summarise
    • The Singapore Police Force disrupted 52,200 malicious websites in the first half of 2026, which shows the scale of online impersonation.
    • The Singapore Police Force disrupted 52,200 malicious websites in the first half of 2026, which shows the scale of online impersonation. PHOTO: ST
    Published Fri, Oct 2, 2026 · 03:51 PM

    IN AUGUST, Singapore’s Ministry of Home Affairs said it detected and took down more than 500 websites impersonating the ministry and seven Home Team agencies. The sites copied official branding and publicly available content closely enough to potentially mislead users.

    While investigators did not find evidence that the sites had been used for scams or phishing, and no government systems were compromised, the takedown still matters.

    This episode exposes a gap in the familiar advice to verify suspicious messages through an official website. What if the website itself is the imitation?

    For years, consumers have been told to inspect Web addresses, avoid unsolicited links and look for suspicious clues, such as spelling mistakes. This remains sound advice, but it assumes that people have enough information to distinguish a convincing copy from the real thing.

    The organisation being impersonated knows which domains and channels it owns; the public usually does not.

    For the company being impersonated, declining confidence in its genuine communications could translate to serious consequences, even if its own systems were never breached.

    Most lookalikes are more than registered names

    OneSecure’s State of Digital Trust in Singapore 2026 study examined 120,702 distinct lookalike domains associated with 448 reference organisation domains in a Singapore-focused sample.

    At the median, each reference domain was associated with 151 lookalikes. But this does not mean that the typical organisation faced 151 scam sites.

    A lookalike may actually belong to an unrelated legitimate business or lead to a harmless holding page. Instead, the figure indicates the scale of the problem facing companies today; a customer may report one lookalike but security teams have multiple similar identities to assess.

    The finding that deserves closer attention is that 82 per cent of the lookalikes studied had observable Internet or e-mail-routing infrastructure, or both. These technical foundations support online interactions.

    Put simply, an Internet address can connect a domain to online infrastructure that may present content or redirect visitors. An e-mail-routing record configures a domain to receive e-mails.

    While security teams might not automatically assume or declare such lookalikes dangerous, these features make them relevant for an assessment.

    The practical risk here is change. A domain may initially show little beyond a familiar name, but later acquire a website, e-mail capability, copied content or even a redirect from the original site. That is where the potential danger lies as these changes could make a lookalike seem more trustworthy to an unsuspecting site visitor.

    The study showed that 12.3 per cent of these lookalike sites were created just in the past year, suggesting that new domains are continually registered. A single takedown operation only clears out a fraction of the threat before new ones pop up or existing ones acquire additional features.

    The burden has to be shared

    While not specific to lookalike domains, the Singapore Police Force disrupted 52,200 malicious websites in the first half of 2026, which shows the scale of online impersonation.

    As the problem grows, Singapore is moving towards shared responsibility through the phishing-loss framework and new requirements for platforms to detect and disrupt scams proactively.

    The same principle should inform how organisations protect their own customers. Consumer vigilance is necessary, but it should not be the only line of defence.

    Yet, defence also does not mean trying to remove every similar-looking domain. The study found lookalike populations ranging from 23 to 1,769 per reference domain, so indiscriminate investigation would consume time without necessarily reducing risk.

    Businesses need a structured way to prioritise these cases: establish what lookalike domains exists; watch for material changes; and investigate signals such as copied sign-in pages, payment requests, redirects or e-mail capability appearing where none existed before.

    These should attract greater scrutiny than a dormant domain with no apparent connection to the business.

    Businesses need to act before harm is reported

    When an organisation’s identity is used to deceive, the damage can also impact the public’s confidence in its legitimate e-mails, websites and services.

    Trust is part of the infrastructure of a digital economy, and maintaining it requires attention beyond the systems that a business directly controls.

    Firms should also decide who acts when a credible threat appears. Cybersecurity teams may detect it, legal teams may pursue its removal, communications teams may warn customers, and customer-service staff may receive the first report.

    Clear escalation routes and an easy way for customers to verify or report suspicious websites should be in place before an incident.

    If an impersonation can be confirmed, an early warning should explain what customers need to do to avoid these pages and reach the genuine page safely while the organisation works on removing the lookalike.

    A company may not own the website impersonating it, but its customers can still suffer the consequences. Protecting trust therefore requires businesses to look beyond the systems they control and act proactively – before the first customer reports a loss.

    The writer is senior director, innovation and core engineering, at OneSecure Asia