top of page

Scam Alert—or ACRA Reminder? The Government Email That Has Singapore Businesses Afraid to Click

Nixon Ng
Sep 2
4 min read

Imagine receiving an urgent email telling you that your company has an outstanding ACRA filing or reminder.


Screenshot of the actual Email received
Screenshot of the actual Email received

The message looks important. There may be a deadline, and ignoring it could potentially result in late-filing penalties or compliance issues. You are about to click the link—but then you notice something strange.


The email did not come from an address ending in @acra.gov.sg. Instead, it came from:



When you hover over the links embedded in the email, it does not appear to take you directly to the familiar ACRA, Bizfile or Corppass website either. Instead, the link seems to go through Menlo Security, a name that many Singapore business owners have never encountered.


At that point, most careful recipients would stop and ask:


“Is this really from ACRA—or is someone trying to steal my Corppass credentials?”


That reaction is entirely understandable.


In fact, a business executive raised the alarm and immediately sought clarification with their corporate service provider, which assured them that the email was legitimate.


Why does an ACRA reminder come from “Plumber”?


Screenshot of the login page of Plumber
Screenshot of the login page of Plumber

The word “Plumber” does not immediately make anyone think of company filings or government compliance. It sounds more like a home-repair service than a platform used to send official government reminders.


However, Plumber is a digital automation tool developed by Singapore’s Open Government Products. It allows public officers to create automated workflows, including sending emails and reminders.


Plumber’s official guidance states that emails generated through the system use the fixed sender address info@plumber.gov.sg. Officers using the platform cannot simply replace it with their own agency’s email address.


Therefore, an ACRA-related reminder sent from this address may be genuine.


What is Menlo Security?


Screenshot of the login page of Menlo Security
Screenshot of the login page of Menlo Security

Most people would naturally expect an email about ACRA matters to come from ACRA. When it arrives under the name “Plumber”, suspicion is not unreasonable—it is responsible.


Then the link goes somewhere unexpected. The concern grows when the recipient checks the link and sees a Menlo Security address rather than the usual Corppass or Bizfile domain.


Menlo Security provides cybersecurity technology that can inspect or isolate websites to protect users from malicious content. The link may therefore have been rewritten or routed through Menlo as a security measure.


Ironically, a system intended to improve security can make an authentic email look even more suspicious.


Bottom line: Plumber and Menlo Security are related to the Singapore Government as of this article.


For years, businesses have been told:


  • Check the sender’s address;

  • Do not trust unfamiliar links;

  • Be careful with urgent requests;

  • Confirm that the URL matches the organisation; and

  • Never enter Corppass or Singpass credentials through a suspicious link.


Yet this reminder seems to trigger almost every warning sign that users have been trained to recognise.


An unfamiliar sender? Yes.


An unexpected link? Yes.


An urgent compliance matter? Possibly.


A request to click and take action? Yes.


If this were part of a cybersecurity-awareness exercise, many employees would correctly identify it as a possible phishing attempt.


“I thought it was a scam”


For corporate secretaries, accountants and business owners, ACRA reminders are part of daily working life. Missing a filing deadline can affect the company and may expose its officers to penalties.


That creates a difficult choice.


Clicking an unfamiliar link could expose the user’s credentials or company information. Ignoring a genuine reminder could lead to a missed deadline.


The recipient is left wondering:


“Do I click it, delete it or report it?”


This uncertainty is unnecessary. An official communication should inspire confidence—not make a responsible recipient feel that they are taking a gamble by opening it.


What should you do if you receive one?


Even if the email may be genuine, you do not have to click its link.


The safest response is to verify the matter independently:


  • Do not click the link immediately.

  • Open a new browser window.

  • Manually enter the official ACRA or Bizfile website address.

  • Log in using the official Corppass or Singpass route.

  • Check whether the company genuinely has an outstanding filing or transaction.

  • Contact ACRA through its published official channels if you remain uncertain.


Never enter your Singpass, Corppass, banking or other credentials after following a link that you do not fully trust. Do not approve an unexpected authentication request, even if the email appears urgent.


Taking an extra few minutes to verify the reminder is far better than risking unauthorised access to your company’s records.


A genuine email should look genuine


The issue is not necessarily that these reminders are scams. The available information indicates that info@plumber.gov.sg is used by an official government automation platform, while Menlo Security may be involved for cybersecurity purposes.


The real issue is how the communication appears to the person receiving it.


Most business owners do not know the government’s internal technology arrangements. They should not have to research unfamiliar systems before deciding whether an official reminder is safe to open.


If ACRA uses Plumber to send reminders, the email should prominently explain:


  • That Plumber is an official Singapore Government platform;

  • That the message was generated on ACRA’s behalf;

  • Why the sender is info@plumber.gov.sg rather than an ACRA address;

  • Why its links may pass through Menlo Security; and

  • How recipients can verify the reminder without clicking anything.


The reminder should also direct users to manually access the transaction through the official ACRA or Bizfile website.


The uncomfortable irony


Singapore businesses are constantly reminded to stay alert against phishing. Yet an email can apparently be genuine while looking remarkably similar to the very scams we are warned about.


That is the uncomfortable irony.


The technology behind the email may be secure, but the recipient’s experience matters too. If a genuine government reminder causes careful users to hesitate, delete it or report it as phishing, then the communication has not fully achieved its purpose.


Businesses should continue to be cautious and verify ACRA reminders independently. At the same time, official communications should be designed so that ordinary users can recognise and trust them without becoming cybersecurity investigators.


Because when an official ACRA reminder looks like a scam, the problem is no longer just whether the technology is secure.


The problem is whether anyone feels safe enough to click. ----------

media contact: nixon.ng@smaths.com

1 Comment

Rated 0 out of 5 stars.
No ratings yet

Add a rating
Ian Gan
Ian Gan
Sep 02
Rated 5 out of 5 stars.

Plumber!

Like
bottom of page