TechNewsReel
Live

Singapore Police Warn of Crypto Theft via Compromised Email Accounts

Hackers are using leaked credentials from third-party data breaches to infiltrate email accounts and steal cryptocurrency, the Singapore Police Force warns.

TechNewsReel Newsroom · September 12, 2026

The Singapore Police Force (SPF) has issued a warning to the public regarding a growing trend of unauthorized access to cryptocurrency accounts. Authorities report that hackers are utilizing compromised email accounts as a primary gateway to steal digital assets.

According to the SPF, attackers are gaining entry to cryptocurrency accounts by first infiltrating the users' associated email addresses. The police noted that several of these compromised email accounts had previously appeared in data breaches on other, unrelated platforms. This allows attackers to use leaked credentials—often obtained from non-financial services—to gain a foothold in a user's digital identity and subsequently pivot to high-value crypto wallets.

The Credential Stuffing Threat

This attack vector relies heavily on the common practice of password reuse. When a third-party platform suffers a data breach, usernames and passwords are often leaked or sold on the dark web. Cybercriminals then employ "credential stuffing," a technique where they automate login attempts across various other services using those same leaked pairs. In this instance, the email account serves as the critical point of failure; once an attacker controls the email, they can often trigger password resets or bypass security checks for cryptocurrency exchanges and wallets.

Systemic Security Vulnerabilities

This trend highlights a critical vulnerability in the current digital security landscape: the over-reliance on email as the primary method for account recovery and authentication. Because email accounts often act as the "master key" for a user's entire online presence, a single breach in a low-security service can lead directly to the loss of significant financial assets. The incident underscores that the security of a cryptocurrency portfolio is only as strong as the weakest password used across any linked account.

The Broader Cybercrime Landscape

These warnings come amid a challenging security environment in Singapore, where phishing and credential stuffing remain primary attack vectors. The Singapore Police Force has previously reported that losses from scams and cybercrime continue to reach hundreds of millions of dollars annually, reflecting the increasing sophistication of digital theft.

Next Steps for Users

While the SPF has flagged the trend, users are encouraged to move away from password reuse and implement robust security measures. Security experts generally recommend the use of unique, complex passwords for every account and the activation of multi-factor authentication (MFA)—specifically hardware keys or authenticator apps rather than SMS or email-based codes—to decouple account recovery from a single point of failure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.