maybe he sub, as he recovering from injury.
the last game before today, he sub in, first touch is magic already lol made lautaro 1 on 1 in which he was fouled, and messi took the pk.
A man lost S$3,800 in a card phishing scam after clicking on a TikTok ad.
But a tribunal found that the man had to bear the losses, and not the bank. Here's why:
https://cna.asia/3S273Mv
Full Case Details
Incident: A Singaporean man clicked a seemingly legitimate TikTok ad for goods/deals, landed on a fake checkout site, entered his credit‑card details + OTP, and lost S$3,800 in unauthorised charges. He claimed the bank should refund; the bank refused, so he brought the case to FIDReC — Singapore’s financial dispute tribunal .
Ruling Outcome: He must bear the full loss; bank not liable.
Why the Tribunal Decided This
Under Singapore’s Shared Responsibility Framework (SRF, since Dec 2024) and E‑Payments User Protection Guidelines, liability follows a “waterfall” test:
1. Bank’s duty first: Must spot suspicious activity, send alerts, block risky transfers — here, FIDReC found the bank met all its security obligations.
2. Telco/platform next: SRF covers SMS‑originated phishing, but TikTok‑ad‑driven web‑phishing falls outside SRF scope; telcos/platforms not legally on the hook here.
3. User responsibility: The man voluntarily clicked the ad, entered card data + OTP himself — this counts as an authorised‑looking transaction; he failed to take basic checks:
• Did not verify the merchant’s authenticity
• Shared sensitive info + OTP on an unknown site
• Ignored standard “stop‑check‑tell” scam‑safety steps
When both bank & telco/platform did their part, the consumer bears 100 % loss.
Key Context
- SRF protection gaps: Only applies to phishing via SMS, not social‑media ads or direct web‑entry scams.
- FIDReC limits: Adjudicates up to S$150 000; rulings bind banks but not users, who can still sue later .
- TikTok scams trend: Fast‑growing in SG — 23.8 % of social‑media scam cases in 2025; fake‑shopping ads the top vector.
Lessons / Prevention
✅ Never click ad links to enter payment data — go directly to verified brand sites
✅ OTPs are never to be shared for “verification” — only for confirmed, known merchants
✅ Install ScamShield, enable transaction alerts, and call 1799 if unsure
✅ Report scams to police + bank within 24 hours to boost recovery chance