Singapore residents fall for phishing despite high MFA adoption rates
The report also found 64% of employees had received cybersecurity training.
Singapore residents show strong cybersecurity awareness and high multi-factor authentication (MFA) uptake, but many still fall for phishing and social engineering attacks, according to Yubico’s Global State of Authentication Survey 2025.
The report highlights a mixed cybersecurity landscape. Whilst 78% of Singaporeans use MFA for personal accounts and 43% use mobile authentication apps like TOTP or push notifications at work — nearly double the global average — a majority still rely on traditional logins.
Usernames and passwords remain the default for 58% at work and 63% in personal use, exposing users to ongoing security risks.
Despite high levels of awareness — 89% are concerned about AI’s impact on account security (the second-highest globally), and 85% say phishing is becoming more sophisticated — nearly half (44%) admitted to engaging with a phishing message in the past year.
Additionally, 26% reported social media account hacks, and 22% said they had accidentally shared work emails in phishing incidents.
At the workplace level, 60% of companies in Singapore require MFA across all apps, well above the 48% global average, though down from 68% in 2024.
The report also found 64% of employees had received cybersecurity training, and 86% felt their company's security policies were appropriate for their roles.
Still, data leaks remain a concern. Beyond email exposure, 17% of respondents shared names, and 16% shared phone numbers as a result of phishing incidents.