KrisFlyer Phishing Scam 2026: SIA Warns of Fake Anniversary Draw Emails — Delete Immediately
KrisFlyer phishing scam 2026 — Singapore Airlines issued its official warning on July 21, 2026 advising all customers to delete fraudulent "KrisFlyer Anniversary Draw" emails immediately and not to click any links or provide personal information.
KrisFlyer phishing scam 2026 is actively circulating — Singapore Airlines issued an official warning on July 21, 2026 alerting all customers to delete fraudulent emails claiming to offer a “KrisFlyer Anniversary Draw,” confirming these are phishing attempts designed to steal personal information, banking credentials, and KrisFlyer account access.
The KrisFlyer phishing scam 2026 warning is particularly urgent for the large Indian KrisFlyer member community — Indians flying Singapore Airlines from Delhi, Mumbai, Bengaluru, Chennai, Hyderabad, and Kochi represent one of SIA’s largest national loyalty programme bases, and the fake anniversary draw is specifically crafted to exploit trust in the airline’s genuine loyalty programme.
Singapore Airlines in a Facebook post on July 21 warned that there are fraudulent emails going around about an anniversary draw involving its frequent flyer programme KrisFlyer. Recipients of the emails are advised not to click on any links or open any attachments, and to delete it immediately.
What the Fake Email Claims and What the Scam Does
The KrisFlyer phishing scam 2026 email is a classic advance-prize phishing construct — framed as an anniversary celebration draw, designed to make recipients feel they have been specially selected, and engineered to extract personal and financial information through fake claim processes.
Recipients of the scam are informed that they have been selected for a draw or have won air tickets. It will then prompt the recipient to enter his or her personal details.
The scam works in stages. The initial email informs you that you have been selected as a winner or participant in a KrisFlyer anniversary draw. The next step asks you to verify your identity — typically requesting your name, email address, KrisFlyer membership number, and sometimes passport details. A third stage introduces the financial element — requesting a processing fee, credit card details, or OTP to “release” your prize.
This is the standard advance-fee phishing playbook. No prize exists. Every piece of information you provide is captured by the scammers for use in identity theft, financial fraud, or sale to other criminal networks.
SIA will never ask for passwords, one-time passwords, credit card PINs, remote access to devices, or payment to claim a prize.
This is the most important sentence in Singapore Airlines’ advisory. Any communication — email, phone, or message — that asks for your OTP, credit card PIN, remote device access, or a payment to claim a prize is definitively fraudulent, regardless of how authentic the SIA branding appears.
How to Identify the Real Singapore Airlines Email Domain
While SIA does organise giveaways, lucky draws and contests periodically and require winners to furnish their information for verification purposes, the airline said that all contact will be carried out by SIA staff whose emails will come from singaporeair.com.sg.
The domain check is the simplest and most reliable verification tool:
Legitimate SIA emails: Come from @singaporeair.com.sg — note the .sg suffix which is Singapore’s official country domain. Legitimate SIA communications may also come from @krisflyer.com.
Phishing emails: Will come from domains designed to look similar but are not the official domain. Examples include addresses ending in .com (not .sg), domains containing extra words (like singaporeair-draw.com), or completely unrelated domains.
Before clicking any link in an email claiming to be from Singapore Airlines, check the sender’s email address by hovering over or clicking on the sender name. If the domain is not singaporeair.com.sg or krisflyer.com, delete the email immediately.
The Five Red Flags of a KrisFlyer Phishing Email
The KrisFlyer phishing scam 2026 and similar SIA phishing attempts across the years share consistent characteristics. Any one of these should cause immediate deletion:
1. Prize without entering. You cannot win a draw you did not enter. If you receive a notification that you have won an anniversary draw you have no memory of participating in, it is fraudulent.
2. Urgency language. Phishing emails typically include language like “claim within 24 hours,” “limited winners,” or “your prize will expire” to create panic that overrides critical thinking. Singapore Airlines’ genuine communications are not time-pressured in this way.
3. Request for OTP, PIN, or payment. SIA will never ask for passwords, one-time passwords, credit card PINs, remote access to devices, or payment to claim a prize. No exceptions. No matter how official the email looks.
4. Non-singaporeair.com.sg sender domain. Every legitimate Singapore Airlines communication comes from @singaporeair.com.sg. Any other domain is fraudulent.
5. Link to a non-SIA website. Hover over any link before clicking. If the URL does not show singaporeair.com or singaporeair.com.sg, do not click.
If You Have Already Responded: Immediate Actions
Those who have already responded or provided any personal information are advised to report the incident to the police, secure their bank accounts and to change their passwords if they have been disclosed.
If you have already clicked a link, entered your details, or provided any information in response to a KrisFlyer phishing scam 2026 email, take these actions immediately in this order:
Step 1 — Secure your bank accounts. Call your bank immediately and inform them that you may have been the victim of a phishing scam. They can temporarily freeze the account, block international transactions, and monitor for fraudulent activity.
Step 2 — Change your KrisFlyer password. Log directly into singaporeair.com (not through any link in the email) and change your KrisFlyer PIN and password immediately. Enable two-factor authentication if you have not already done so.
Step 3 — Change email and other account passwords. If you used the same email password that you provided to the phishing site, change your email password immediately. Check whether the same password is used across multiple accounts and change them all.
Step 4 — Enable SIA two-factor authentication. Customers are also strongly encouraged to add an additional layer of security to flight bookings made via the Singapore Airlines website or SingaporeAir mobile app by enabling the two-factor authentication (2FA) feature. When enabled, customers will be provided with a time-sensitive, randomly-generated one-time password (OTP) to verify their identity before they can securely access passenger details, and change or cancel their flight bookings.
Step 5 — File a police report. In Singapore, report to the Singapore Police Force via police.gov.sg. In India, file a cybercrime report at cybercrime.gov.in or contact the National Cybercrime Reporting Portal at 1930.
Step 6 — Contact SIA directly. Customers who are unsure of the authenticity of any messages purporting to be from SIA can contact the airline directly for assistance. Use only contact details from singaporeair.com — not any contact details provided in the suspicious email.
The Broader SIA Phishing Pattern
The KrisFlyer phishing scam 2026 is not an isolated incident. SIA has issued phishing warnings multiple times over the years — in 2017 for fake survey forms via WhatsApp, in 2022, 2023, 2024, and now again in July 2026. The pattern is consistent: scammers monitor SIA’s anniversary dates, seasonal promotions, and loyalty programme milestones and time their phishing campaigns to coincide with when SIA customers might plausibly expect an anniversary communication.
SIA has taken down the email domain associated with the phishing email — but taking down one domain does not prevent scammers from registering new ones. The advisory remains active and relevant for any KrisFlyer member who receives an anniversary draw email going forward.
What Indian KrisFlyer Members Must Know
For Indian KrisFlyer members — the largest single nationality in SIA’s loyalty programme outside Singapore — the KrisFlyer phishing scam 2026 warning carries specific practical weight.
Indian digital literacy has grown significantly, but phishing sophistication has grown alongside it. Modern KrisFlyer phishing emails are visually indistinguishable from legitimate SIA communications — they use identical logos, fonts, colour schemes, and email templates. The only reliable verification method is the sender domain check: @singaporeair.com.sg or delete.
Indian KrisFlyer members earning miles on Air India (through the SIA-Air India partnership under the Tata Group relationship), IndiGo codeshare flights, and other Star Alliance partners have built significant mile balances that would be attractive targets for scammers seeking to transfer or redeem stolen accounts.
Enable two-factor authentication on your KrisFlyer account immediately. This takes two minutes at singaporeair.com and protects your miles against unauthorised redemption even if your password is compromised.
For travel insurance covering Singapore Airlines trips including any disruption or loss related to flight booking changes, SafetyWing Nomad Insurance provides comprehensive coverage at affordable daily rates for Indian travelers.
FAQs — KrisFlyer Phishing Scam 2026
Q: What should I do if I receive a KrisFlyer Anniversary Draw email?
Recipients of the emails are advised not to click on any links or open any attachments, and to delete it immediately. Singapore Airlines in a Facebook post on July 21 warned that there are fraudulent emails going around about an anniversary draw involving its frequent flyer programme KrisFlyer. Do not enter any personal information, do not click any links, do not open any attachments. Delete the email immediately. If you are unsure whether an email is genuine, contact SIA directly through singaporeair.com — not through any contact details in the email.
Q: How can I tell if a Singapore Airlines email is genuine?
All contact will be carried out by SIA staff whose emails will come from singaporeair.com.sg. Check the sender’s email domain — legitimate SIA communications come from @singaporeair.com.sg only. Any email from a different domain claiming to be from Singapore Airlines or KrisFlyer should be treated as fraudulent and deleted. SIA will never ask for passwords, one-time passwords, credit card PINs, remote access to devices, or payment to claim a prize.
Q: What if I already clicked the link and provided information?
Those who have already responded or provided any personal information are advised to report the incident to the police, secure their bank accounts and to change their passwords if they have been disclosed. Act immediately — call your bank to alert them, log into your KrisFlyer account directly at singaporeair.com and change your PIN and password, enable two-factor authentication, change any other accounts using the same password, and file a cybercrime report. In India, report at cybercrime.gov.in or call 1930.
Final Word
The KrisFlyer phishing scam 2026 advisory from Singapore Airlines — issued July 21, active as of August 2026 — is a reminder that aviation loyalty programmes are among the most frequently impersonated brands in phishing campaigns worldwide. KrisFlyer’s large member base, the high value of accumulated miles, and Singapore Airlines’ genuine anniversary and draw communications create the exact conditions that phishing scammers target. The defence is simple and takes seconds: check the sender domain — @singaporeair.com.sg is real, everything else is fraud. Enable two-factor authentication on your KrisFlyer account today. And if you have already responded to a suspicious email, act immediately through the steps above rather than waiting to see if anything happens.
Also Read:
- Singapore Airlines A380 Routes — 25% More Flights Nov 2026
- Singapore SG Arrival Card 2026 — Free Guide and Scam Warning
- Singapore Travel Guide Indians 2026 — Visa, Money and Transport
Official Sources:
- Singapore Airlines Official Advisory — Phishing Scams and Cybersecurity Practices
- Straits Times — KrisFlyer Anniversary Draw Phishing Scam Warning
Aaseem Bhardwaj is a journalist, seasoned traveler and IT professional based in India. With firsthand travel experience across Southeast Asia, East Asia, Middle East and Europe, Aaseem founded Travel Man Today to provide reliable visa updates and travel news for Indian passport holders. He has personally traveled to Thailand, Vietnam, Malaysia, Japan, Singapore, Hong Kong, South Korea, UAE and Europe. Follow his travel vlogs on YouTube at @travelmantoday
Templates for Indians