Singapore
Singapore extends Singpass passkey to Android users to curb phishing scams
Singpass’ passkey authentication, first rolled out to Apple iPhone users, is now available to Android users as part of Singapore’s push to reduce phishing scams. — Picture via Facebook/GovTech (Government Technology Agency of Singapore)

SINGAPORE, Sept 9 — National authentication system Singpass has expanded its passkey feature to Android users, extending a security upgrade first rolled out to Apple iPhone users as part of Singapore’s push to reduce phishing scams.

The Straits Times reported that the Government Technology Agency of Singapore (GovTech), the government agency that operates Singpass, began notifying Android users today to create their passkeys through the Singpass app.

GovTech said the passkey system uses a unique pair of encryption keys — one stored on the user’s device and the other on Singpass’ backend — to ensure access is granted only to legitimate websites.

The agency added that passkeys cannot be shared or exploited, unlike passwords or QR codes, and will not work on fake websites because the private key on the device must match the public key registered with Singpass.

GovTech said about 800,000 iPhone users have created their passkeys since the feature launched in July.

Singpass supports 5.5 million users and is integrated with more than 1,400 government and private‑sector services, including HealthHub, the Inland Revenue Authority of Singapore’s tax portal, the Central Provident Fund Board, DBS Bank and Singtel.

Users must complete a one‑time registration to enable passkey authentication.

Android users need to update their Singpass app, tap the “create passkey” banner and follow the instructions to activate the feature.

Once registered, users log in to Singpass‑enabled websites by scanning their face or fingerprint, or by entering their six‑digit passcode if biometric authentication is not enabled.

Singpass’ backend system verifies the private key stored on the device against the public key registered in the system for every login attempt.

Users do not need separate passkeys for each website.

GovTech said laptops and desktops do not yet support Singpass passkeys, but the feature will be extended to desktop users by the end of 2026.

Singpass passkeys comply with open standards developed by the Fast IDentity Online (Fido) Alliance, whose members include Microsoft, Google, Apple and government bodies in Australia, the United Kingdom and the United States.

Many online services from Apple, Google, Microsoft and Adobe already support Fido passkey authentication alongside passwords and two‑factor verification.

Phishing cases in Singapore fell to 3,104 in the first half of 2026, down from 3,772 in the same period in 2025, while monetary losses dropped from S$30 million (RM105 million) to S$9.6 million (RM33.6 million). 

 

Related Articles

 

You May Also Like