
Summary
In 2025, the Home Ministry reported thatonline scams caused RM2.77 billion in losses, translating to roughly RM7.6million lost daily[1]. Cyberfinancial scams have emerged as a significant threat as Malaysians spend moretime online and increase their use of digital financial services. This trendshows no signs of abating as scammers get increasingly sophisticated, using technologyto scale up their operations and refine their deceptive tactics.
In this paper, we define cyber financialscam as “financial loss caused by a victim’s voluntary actions as a result oftrickery performed by the perpetrators in an online space”.
This study dives into the problem of cyberfinancial scams in the Malaysian context to glean insights into key issues usinga systemic perspective. The research objectives are as follows:
- To understand the anatomy of acyber financial scam, focusing on the chain of events that occur and their underlyingissues;
- To identify gaps withinMalaysia's existing regulatory and non-regulatory initiatives on the problem;and
- To propose policy recommendationsto improve the work around combatting scams.
Using desk research and drawing fromstakeholder discussions, we developed a Scam Anatomy framework that outlinesthe key stages within a typical scam lifecycle from the perspective of thescammers. We find that scams usually move through seven stages, from theinitial groundwork and operational setup, to the establishment of contact and interactionswith the victim, to the final disappearing act and cashing out of extractedfunds.
With the framework thus established, we usedit to analyse Malaysia’s current regulatory and non-regulatory initiatives to combatscams. From our mapping, we observe that a plethora of regulations alreadyexist across the scam lifecycle, with most gaps in the governance of technologicaladvancements even though the government is moving rapidly onclosing these gaps. While much effort has been pouredinto mitigation and safeguards, initiatives tend to be reactive, focusing onthe financial extraction end of the scam lifecycle. There is alsodisproportionate focus on literacy campaigns and individual responsibility.
To tackle cyber financial scams and scamoutcomes more effectively, we recommend the following priorities:
- To distribute risk and responsibility among key enabling actors, rather than placing the full burden on individuals when scamsoccur. This approach ensures that institutional actors, such as financialinstitutions, telecommunication companies, and application service providers areheld accountable for effectively discharging their obligations in preventingand addressing scams.
- To develop technologicalsolutions to connect and build upon existing legal and information systems to match the speed and scale of malicious actors. For example, ascam advertisement detection tool can be used together with legal provisionsfrom the Online Safety Act for effective content takedowns. A dedicated scamprevention app integrating existing official databases and tools can also serveas a single source of truth of verification and response guidance forconsumers.
- To provide accurate, timely and publicly available data for scammonitoring by having a public-facing dashboard.Such a dashboard can reduce cross-agency data discrepancies, provide atransparent baseline for comparison along with valuable indicators, and therebyincrease public vigilance and improve incident reporting rates.
- To enhance literacycampaigns to build anti-scam resilience by movingbeyond basic information on scam identification towards more engaging,innovative, and evidence-based approaches. Likewise, simulation training andscam-awareness sandboxes should be considered as part of broader efforts tobuild a scam-resilient population.
- To close legal gaps and enact forward-looking legislation, particularly on areas related to emerging technology. Legislationsshould adopt a preventive rather than reactive approach to better respond toemerging threats.
- To increase law enforcementcapacity and safeguards – more resources should beinvested to keep pace with the growing sophistication of scams, whileappropriate safeguards are put in place to address unintended effects of tightenforcement.
- To strengthen cybersecuritydefence by investing in, nurturing and developing more cybersecurity talent.











