The Singapore Police Force (SPF) and Meta have dismantled more than 3.6 million scam-linked accounts, pages and entities across Facebook and Instagram as part of a joint enforcement effort announced in September 2026.
According to information circulated by McGallen & Bolden, the removed “shell” pages were not overtly malicious but were described as being created to serve as infrastructure that scammers could use for future campaigns.
Abhishek Kumar Singh, Head of Security Engineering, Singapore at Check Point Software Technologies, said the operation reflects a broader shift in cybercrime, where attackers build and maintain large-scale digital infrastructure ahead of launching scams. “Rather than creating fraudulent assets only when needed, threat actors are establishing dormant social media accounts, cloned websites, impersonation assets and lookalike domains that can be activated rapidly at scale,” Singh said.
Singh also pointed to Check Point Research findings that identified Facebook and WhatsApp among the world’s most impersonated brands in phishing campaigns, arguing that takedowns targeting dormant assets can disrupt scam activity before it is “weaponized”.
He said the approach aligns with exposure management strategies focused on identifying and reducing external risks before they become active threats, including monitoring for phishing sites, fraudulent profiles and brand impersonation campaigns and then initiating investigation and takedown actions.
For Singapore, where scams remain a major concern, Singh said the SPF-Meta collaboration illustrated how intelligence sharing and proactive disruption can reduce the effectiveness of fraud campaigns by limiting attackers’ ability to leverage trusted online platforms against consumers.

