A fake Instagram account using your logo is running a “clearance sale” and taking deposits. A cloned Facebook page is answering your customers’ enquiries. A one-star review appears from someone who has never been through your door. Somewhere in your inbox is a screenshot from a customer asking whether the account is really you.
Since 29 June 2026 there has been a new answer available in Singapore — the Online Safety Commission opened, and statutory torts under the Online Safety (Relief and Accountability) Act 2025 came into force on the same day. A lot of marketing commentary has since assumed this is the tool that finally deals with brand impersonation.
It is not, and the reason is worth understanding precisely, because it changes what you should actually do this week. The impersonation limb of that Act is written, passed and printed — and not in operation. What is in operation includes a duty that falls on you, as the administrator of your own brand’s page or group.
This article works through what commenced and what did not, straight from the commencement note, then covers the routes that genuinely work today in the order you should try them. It is a companion to our Singapore social media management guide, and it deliberately does not repeat the trend-level summary in our 2027 digital marketing trends piece — this is the operational version.
What actually commenced on 29 June 2026 — and what did not
The Online Safety (Relief and Accountability) Act 2025 defines thirteen categories of “online harmful activity”. Eight of them are eligible for a statutory tort. But the Act’s own definition of online harmful activity carries a qualifier that most summaries drop: it means the listed activities “other than an activity the definition of which in Part 3 has not been brought into operation“. Sections 89(1) and 93(1) repeat the same qualifier for the tort Parts.
So the question is simply which Part 3 definitions were switched on. The commencement note on the Act is explicit. Brought into operation on 29 June 2026: Part 1, Part 2, and “sections 9, 10, 12, 13, 14” among others. Those are online harassment (s9), doxxing (s10), online stalking (s12), intimate image abuse (s13) and image-based child abuse (s14).
Section 15 (online impersonation) and section 16 (inauthentic material abuse) are not in that list. Neither are the publication-of-false-material, statement-harmful-to-reputation, instigation or incitement definitions.
The consequence is precise. Section 85 creates a tort of online impersonation and section 86 creates a tort of inauthentic material abuse — both sit in the statute book today — but each defines its “victim” by reference to a Part 3 section that has not commenced. The remaining categories are, in the Government’s own framing, to be progressively implemented.
| Harm eligible for a statutory tort | Defining section | In force 29 Jun 2026? | Relevance to a brand |
|---|---|---|---|
| Online harassment | s9 | Yes | High — pile-ons directed at named staff |
| Doxxing | s10 | Yes | High — staff details published to provoke |
| Online stalking | s12 | Yes | Moderate |
| Intimate image abuse | s13 | Yes | Low |
| Image-based child abuse | s14 | Yes | Low |
| Online impersonation | s15 | No | Highest — the fake account problem |
| Inauthentic material abuse | s16 | No | High — deepfake endorsements |
| Incitement of violence | s21 | No | Low |
There is a second reason not to plan a brand-protection strategy around these torts even once they commence. Every one of the definitions is built around a harm test expressed in human terms — conduct “likely to cause a person … harassment, alarm, distress or humiliation”. Section 15 requires impersonation of a “victim” and section 16 requires material that is a false or misleading depiction of “the victim’s words, actions or conduct”. Whether a company can be that victim, as opposed to the named founder, clinician or agent being impersonated, is a question for a lawyer on your facts and not one to settle from a blog post. The practical read is that the natural claimant is usually the individual whose face and name are being used, not the entity.
The duty that is live — and it points at you
Here is the part most brands have missed entirely. Two of the torts that are operative do not target the person who caused the harm. They target whoever runs the online location where it happened — and the Act defines “administrator” broadly enough to include the person who runs your brand’s Facebook group, Telegram channel, forum or comments-enabled page.
Section 90 — facilitating or permitting. A person must not develop, maintain or administer an online location in a manner that facilitates or permits an applicable online harmful activity, while intending it or knowing it is likely. Whether that is made out turns on the purpose of the location, the profile of its users, the nature of the material, the moderation policies and practices applied, and how prevalent the activity is. The Act’s own illustrations are instructive: an administrator who leaves offending posts up and takes no moderation steps has permitted the activity; one who removes them within an hour, bans the accounts and issues warnings has not.
Section 91 — failing to respond reasonably to an online harm notice. A victim may send an administrator a written notice identifying the harmful activity. On receiving one, the administrator owes the victim a duty, within a reasonable time, to “take reasonable care to assess whether the applicable online harmful activity identified in the notice has occurred” and, if so, to “take reasonable steps to address” it. Fail, and the victim can sue.
Section 91(6) is the provision that should change your workflow. If the victim proves a valid notice was sent, that the activity occurred at your location, that it involved online material, and that after a reasonable period the material was still there, then it is presumed until the contrary is proved that you failed to take reasonable steps. The burden shifts to you. The only clean way to discharge it is a dated record of what you assessed and what you did — which means a notice-handling process, not an inbox.
Section 94 imposes the equivalent duty on online service providers, which is the route to use against a platform that ignores you.
There is also a shield. Section 92 gives an administrator a right of action against anyone who sends an online harm notice that is frivolous, or false in a material way and known by the sender to be false. Weaponised notices are contemplated by the Act, and answered by it.
None of this is optional housekeeping. If your brand runs a community — and our guide to community management in Singapore assumes many do — you are now a named legal category with a named duty and a shifting burden of proof.
What actually works today, in the order to try it
1. The platform route, and the registration that unlocks it
For a fake account or a cloned page, the fastest genuine remedy is still the platform’s own. Meta’s Brand Rights Protection tool lets a brand search across ads, commerce surfaces, accounts and posts and report trademark violations, counterfeits and copyright infringement — and, importantly, to report Facebook Pages and Instagram accounts on the basis of business impersonation. Access requires a registered trade mark, a Business Suite account and a clean compliance record.
That requirement is the buried lede. The single highest-leverage brand-protection action for most Singapore SMEs is not a monitoring tool — it is registering the mark, because registration is the key that opens the fast lane at every major platform.
The Intellectual Property Office of Singapore publishes the numbers. The application fee is S$280 per class where the specification is fully adopted from IPOS’s Classification Database, and S$410 per class where it is not. IPOS states it takes “about 9 months for a trade mark to be registered (if the application did not contain any deficiency or face any objection/opposition)”, including publication in the Trade Marks Journal for a 2-month opposition period.
Nine months is the reason to do this before you need it. A business that registers only after the fake account appears has chosen the slowest possible sequence.
2. The false-statement orders under the Protection from Harassment Act
Where the problem is a false statement of fact rather than an impersonating account, the Protection from Harassment Act 2014 provides a court-ordered route. Section 15A allows the subject of an alleged false statement to apply for a stop publication order against “any individual or entity”, requiring them to stop publishing the statement and not to publish any similar statement by a specified time. Section 15B allows a correction order requiring publication of a correction notice, in a specified form, place and proximity to the offending statement.
Two details matter for a business. First, section 15A(2) states that an order may be made “even if the respondent does not know or have reason to believe that the relevant statement is false” — intention is not the gate. Second, section 15(4) says an order may be made whether or not the respondent is in or outside Singapore, or incorporated outside it, and may require acts outside Singapore.
The Online Safety Act also amended this regime with effect from 29 June 2026, adding a correction (administrator) order and a stop publication (administrator) order to the list in section 15 — remedies aimed at whoever runs the location rather than only the author.
The standing question is genuinely open and should be raised with counsel rather than assumed: whether a company can be the “subject” of a false statement for these purposes was the issue the Court of Appeal wrestled with in Attorney-General v Ting Choon Meng in relation to the earlier version of section 15, and the provisions have since been restructured.
3. The routes that have not changed
- Defamation remains available for a false statement that damages reputation, and a company can sue in defamation for a statement that damages it in the way of its business.
- A police report is the right route where the fake account is taking money — that is a cheating offence, not a marketing problem, and it should not sit in your social inbox for a week first.
- The Online Safety Commission’s own directions are available to the individual who is the victim of one of the five live harms. If a named member of your team is being harassed or doxxed, that person has a fast administrative route that the company does not.
Fake reviews: a different problem with a different answer
Fabricated reviews sit outside all of the above, and the honest position is that Singapore gives a business less than most people expect.
The Consumer Protection (Fair Trading) Act protects consumers against unfair practices by suppliers. When a competitor posts a fake review about you, you are not the consumer and they are not supplying you — a point we made at length in our guide to marketing agency red flags in Singapore, where the same gap means pre-signing due diligence is the only real protection. The practical routes are the platform’s own review policies, and, where the review makes a false statement of fact, the POHA orders above or a defamation claim.
The stronger move is on the other side of the ledger. A business with forty genuine, recent, specific reviews absorbs a fake one-star with no visible dent. A business with six absorbs nothing. Volume and recency are the defence, which makes review generation a brand-protection activity and not only a local-SEO one — our guides to getting Google reviews in Singapore and Google Business Profile optimisation cover the mechanics.
One warning that belongs here rather than anywhere else: the temptation to answer fake negative reviews with fake positive ones is a supplier-side unfair practice, and it puts you on the wrong side of the Act you were hoping would protect you.
The evidence pack, and the monthly routine
Every route above fails on the same thing: a report filed three weeks after the account was deleted, with no record of what it said.
Capture, at the moment you find it: the full URL and account handle, a full-page screenshot with the visible date, the profile creation date if shown, the exact text of the offending post or review, any message the impersonator sent a customer, and the name and contact of the customer who reported it. Store it somewhere that is not a staff member’s phone.
Then a monthly routine that costs nothing but calendar time:
- Search your brand name and its two most common misspellings on each platform you use, plus the “people also searched” suggestions.
- Search your brand name alongside “sale”, “clearance”, “official” and “customer service” — the four words impersonation accounts add.
- Check the ad transparency library on Meta for ads running under your name.
- Read every review left in the period, not just the ones the tool flagged.
- Log what you found and what you did, in the same place, dated.
That last line is the one that discharges a section 91 presumption. It is also, not coincidentally, the discipline our social media audit guide builds around, and it belongs in whoever owns your organic Instagram growth or influencer and KOL programme — the same person usually spots the fake account first.
From 2027 the platforms carry a matching duty of their own. Our guide to Singapore’s new online advertising code covers the advertiser identity verification Facebook, Instagram and TikTok must complete by 31 January 2027, and the directions that can disable an ad, a landing page or an entire ad account without a prior hearing.
Frequently asked questions
Can my company sue someone for impersonating our brand online under the new Online Safety Act?
Not at present. Section 85 creates a tort of online impersonation, but it defines its victim by reference to section 15, and section 15 was not among the provisions brought into operation on 29 June 2026. The five harms whose definitions did commence are online harassment, doxxing, online stalking, intimate image abuse and image-based child abuse. The remaining categories are to be implemented progressively.
What did commence on 29 June 2026 that affects a brand?
The administrator duties. Section 90 makes it a tort to administer an online location in a way that facilitates or permits a live harm with the requisite knowledge, and section 91 requires an administrator who receives an online harm notice to assess it and take reasonable steps within a reasonable time. Section 91(6) presumes failure if the material was still up after a reasonable period, which puts the burden on the administrator.
Do I need a registered trade mark to get a fake account taken down?
Not for a basic impersonation report, but it changes what you can access. Meta’s Brand Rights Protection tool requires a registered trade mark, and it is the surface that lets a brand search and report across ads, accounts, commerce and posts at scale. Registration in Singapore costs S$280 per class using IPOS’s classification database and takes about nine months where nothing is contested.
Can I get a fake review removed through the courts in Singapore?
Possibly, where it contains a false statement of fact. Sections 15A and 15B of the Protection from Harassment Act allow a court to make stop publication and correction orders, including against parties outside Singapore, and an order can be made even where the respondent did not know the statement was false. Whether a company has standing as the “subject” is a question to take to a lawyer. The Consumer Protection (Fair Trading) Act will not help, because it protects consumers against suppliers, not businesses against competitors.
Someone sent us a harm notice about a post in our Facebook group. What do we have to do?
Assess it and act within a reasonable time, and record both. Section 91(3) requires reasonable care in assessing whether the activity occurred and reasonable steps to address it if it did. The Act’s illustrations treat prompt removal, account suspension and a warning as reasonable steps. If the notice is frivolous or knowingly false, section 92 gives you your own right of action — but that is a separate matter from responding to it properly first.
What should we do the moment we discover an impersonating account?
Capture the evidence before reporting, because reporting often makes the account disappear. Then report to the platform, warn your own audience on your real channels with a clear statement of which handles are genuine, and make a police report if money has changed hands. Do not contact the impersonator directly.
The summary, if you take one thing
The law that arrived in June 2026 is real, and it will eventually reach impersonation and manipulated media. Today it does something different: it gives five interpersonal harms a fast route, and it makes whoever runs a brand’s online location legally responsible for acting on notices about it. For the fake account and the fabricated review, the tools that work are the ones that were already there — the platform’s own reporting, backed by a registered mark you should file long before you need it, and a court order where a statement of fact is provably false.
The businesses that come out of an impersonation episode well are the ones that had a registered mark, a monitoring habit and an evidence process before it started. That is unglamorous, and it is the whole difference. Our Singapore client case studies show what a well-run brand presence looks like when it is not firefighting.
Not sure who is responsible for spotting this in your business? Talk to our social media marketing team about building the monitoring and notice-handling routine into how your channels are already run.
Sources, all read directly: Online Safety (Relief and Accountability) Act 2025, Singapore Statutes Online (commencement note and ss 3, 9, 10, 15, 16, 85, 86, 89, 90, 91, 92, 93, 94); Protection from Harassment Act 2014, Singapore Statutes Online (ss 15, 15A, 15B as amended by Act 23 of 2025 with effect from 29 June 2026); Ministry of Law, Online Safety portal — statutory torts; Allen & Gledhill, partial commencement note on OSRAA; Meta Business Help Centre, About Brand Rights Protection; IPOS, How to Register Trade Marks (fees and timeline). Last updated 3 September 2026. Written by Adrian Tan and the SDM team. General information about how these rules are written, not legal advice.


