
Summary
In 2025, the Home Ministry reported that online scams caused RM2.77 billion in losses, translating to roughly RM7.6 million lost daily. Cyber financial scams have emerged as a significant threat as Malaysians spend more time online and increase their use of digital financial services. This trend shows no signs of abating as scammers get increasingly sophisticated, using technology to scale up their operations and refine their deceptive tactics.
In this paper, we define cyber financial scam as “financial loss caused by a victim’s voluntary actions as a result of trickery performed by the perpetrators in an online space”.
This study dives into the problem of cyber financial scams in the Malaysian context to glean insights into key issues using a systemic perspective. The research objectives are as follows:
- To understand the anatomy of a cyber financial scam, focusing on the chain of events that occur and their underlying issues;
- To identify gaps within Malaysia's existing regulatory and non-regulatory initiatives on the problem; and
- To propose policy recommendations to improve the work around combatting scams.
Using desk research and drawing from stakeholder discussions, we developed a Scam Anatomy framework that outlines the key stages within a typical scam lifecycle from the perspective of the scammers. We find that scams usually move through seven stages, from the initial groundwork and operational setup, to the establishment of contact and interactions with the victim, to the final disappearing act and cashing out of extracted funds.
With the framework thus established, we used it to analyse Malaysia’s current regulatory and non-regulatory initiatives to combat scams. From our mapping, we observe that a plethora of regulations already exist across the scam lifecycle, with most gaps in the governance of technological advancements even though the government is moving rapidly on closing these gaps. While much effort has been poured into mitigation and safeguards, initiatives tend to be reactive, focusing on the financial extraction end of the scam lifecycle. There is also disproportionate focus on literacy campaigns and individual responsibility.
To tackle cyber financial scams and scam outcomes more effectively, we recommend the following priorities:
- To distribute risk and responsibility among key enabling actors, rather than placing the full burden on individuals when scams occur. This approach ensures that institutional actors, such as financial institutions, telecommunication companies, and application service providers are held accountable for effectively discharging their obligations in preventing and addressing scams.
- To develop technological solutions to connect and build upon existing legal and information systems to match the speed and scale of malicious actors. For example, a scam advertisement detection tool can be used together with legal provisions from the Online Safety Act for effective content takedowns. A dedicated scam prevention app integrating existing official databases and tools can also serve as a single source of truth of verification and response guidance for consumers.
- To provide accurate, timely and publicly available data for scam monitoring by having a public-facing dashboard. Such a dashboard can reduce cross-agency data discrepancies, provide a transparent baseline for comparison along with valuable indicators, and thereby increase public vigilance and improve incident reporting rates.
- To enhance literacy campaigns to build anti-scam resilience by moving beyond basic information on scam identification towards more engaging, innovative, and evidence-based approaches. Likewise, simulation training and scam-awareness sandboxes should be considered as part of broader efforts to build a scam-resilient population.
- To close legal gaps and enact forward-looking legislation, particularly on areas related to emerging technology. Legislations should adopt a preventive rather than reactive approach to better respond to emerging threats.
- To increase law enforcement capacity and safeguards, more resources should be invested to keep pace with the growing sophistication of scams, while appropriate safeguards are put in place to address unintended effects of tight enforcement.
- To strengthen cybersecurity defence by investing in, nurturing and developing more cybersecurity talent.








