The truthful, trustworthy merchant will be with the Prophets, the truthful, and the martyrs. — Tirmidhi 1209

Malaysia Lost RM3 Billion to Online Scams in 2025 — AI Just Changed the Attack Surface

AI-assisted fraud in Malaysia has shifted from attacking bank systems to attacking bank customers. With RM2.97B lost in 2025, the Islamic banking sector faces a fundamentally different threat.

Digital banking interface on a smartphone with security notification

The Thesis

Malaysia lost RM2.97 billion — roughly $670 million — to online scams in 2025. That is an 87% surge from the prior year, and 66,204 fraud cases, nearly double the 35,368 counted in 2024. The numbers have the shape of a system being overwhelmed, not one that is bending under pressure.

But the more important shift is not in scale. It is in architecture. According to security researchers and senior banking executives who gathered at the LexisNexis Risk Ready conference in Kuala Lumpur in May 2026, AI-assisted fraud has fundamentally changed its attack surface: the threat has moved from bank systems to bank customers. That is a harder problem than it looks — and it hits retail Islamic banking squarely.

What Changed

Traditional bank fraud targeted the institution: breach the perimeter, exploit the system, extract value. Banks have spent decades hardening their defenses against this. The fraud architecture that is winning in 2025–2026 exploits something harder to harden: the customer.

Eighty-six percent of Asia-Pacific bank leaders surveyed by BioCatch in June 2026 said AI has increased the sophistication of fraud targeting their institutions. Seventy-nine percent reported that their banks had already encountered attacks using agentic AI — software that can autonomously orchestrate a fraud sequence from start to finish. The most documented case this year was JadePuffer, a ransomware attack disclosed by Sysdig in July 2026, in which a large language model executed the entire intrusion cycle — reconnaissance, credential theft, lateral movement, privilege escalation, encryption — with no human operator. It went from a broken login to a working exploit in 31 seconds.

Malaysia is at the acute end of this trend. The country logged a 408% year-on-year jump in deepfake fraud activity, making it one of Asia Pacific’s fastest-growing deepfake hotspots. The liability question that matters: when a customer is tricked into authorizing their own loss — via a deepfake video call, a synthetic-identity impersonation, or an AI-generated voice — who is responsible?

Why Islamic Banking Is Specifically Exposed

Islamic banking serves a predominantly retail customer base in Malaysia. The sector — which accounts for roughly 45% of total banking assets in the country — has prioritized financial inclusion and digital accessibility: app-based onboarding, low-friction mobile banking, and broad reach into communities that traditional banking has historically underserved. That accessibility is also vulnerability.

Irfan Amer, Chief Information Security Officer at AEON Bank — Malaysia’s Islamic digital bank — was among the panelists at the LexisNexis event. The point his presence underlines: digital Islamic banking platforms are not peripheral targets. They serve millions of retail customers whose primary fraud exposure is not a bank breach but a scam call, a fabricated WhatsApp message, or a synthetic voice impersonating a family member.

The Response Framework

Malaysia is not standing still. Bank Negara Malaysia and Payments Network Malaysia (PayNet) are developing an AI-driven fraud detection system, using large language models and predictive analytics, with a 2026 rollout target. The system is designed to alert users to potential scams before transactions are authorized. Malaysia is also rolling out a National Fraud Portal for earlier intervention across institutions.

The BioCatch survey found that 86% of APAC bank leaders believe AI agents could become the industry’s single largest exploitable vulnerability within the next year. Eighty-six percent also believe that distinguishing legitimate AI-assisted actions from malicious ones will be very challenging — which means the defensive tools are not yet adequate to the threat.

The Honest Limit

Across Asia, scam losses reached $688 billion in 2024 according to the Global Anti-Scam Alliance — a number that needs the methodological footnote that it is based on consumer self-reporting extrapolated across populations, not government audit data. It is indicative, not precise.

What is more solidly grounded: Deloitte’s projection that generative AI will enable $40 billion in fraud losses globally by 2027, up from $12.3 billion in 2023 — a 32% compound annual growth rate. That growth is not slowing because banks are not solving the problem fast enough; it is accelerating because the tools to commit fraud are now commoditized, and the customers who are the target cannot be “patched.”

What to Watch

The National Fraud Portal is the right structural intervention — a shared intelligence layer across banks that enables earlier detection of fraud patterns before individual victims complete transactions. Its rollout timeline and how Islamic banks integrate with it will be a meaningful indicator of whether Malaysia’s financial inclusion gains can be defended at scale.

The harder question is liability. Regulators in Singapore (Scam Bill) and Malaysia are both moving toward frameworks that assign partial responsibility to banks when customers are defrauded even through authorized transactions. If that framework extends to Malaysia’s Islamic banking sector — where a customer authorizing a payment under deception is still, in the bank’s ledger, a voluntary transfer — it has significant operational implications for how digital Islamic banks price risk and design friction into their onboarding and payment flows.