Banks Must Rethink Fraud Prevention As Scams Shift From Cyber Threats To Behavioural Risk

Malaysia’s financial scam problem is entering a more difficult phase for banks. The challenge is no longer simply keeping criminals out of banking systems, but stopping legitimate customers from being manipulated into letting them in.

Bank Negara Malaysia has said 95% of online fraud losses involve authorised transactions, where customers themselves approve the transfer. For banks, this means traditional security controls can work exactly as designed and still fail to prevent the eventual loss.

Dr Simon Liu, Chief Data and AI Officer at TrustDecision and Adjunct Associate Professor at Nanyang Technological University, believes this should force financial institutions to rethink the very nature of fraud prevention.

“When 95% of fraud losses flow through transactions the customer approved, as Bank Negara Malaysia’s 2025 Annual Report confirms, the control failure is not in the authentication stack,” Liu told BusinessToday in an exclusive email interview.

In these cases, every identity control can pass. The genuine customer, using a registered device and valid credentials, completes a transfer that cyber security systems correctly recognise as legitimate.

The compromise instead happens before the transaction reaches the bank’s conventional security controls, when a scammer manipulates the customer’s decision.

For Liu, that represents a fundamental shift in how banks should classify and respond to fraud.

“Fraud has migrated categories, from a cyber security problem where the asset under attack is the system, to a behavioural risk problem where the asset under attack is the customer’s judgment,” he said.

That changes what banks need to examine. Rather than simply asking whether credentials are valid, financial institutions need to assess whether the decision context resembles the customer’s normal behaviour.

This could include the device being used, session patterns, the counterparty’s risk profile and how far a transaction deviates from the customer’s historical behaviour.

The urgency is becoming clearer in Malaysia’s fraud numbers. Online fraud losses rose from RM1.57 billion in 2024 to RM2.97 billion in 2025, according to the Home Ministry, while a further RM830 million was recorded in just the first five months of 2026.

This deterioration has occurred despite banks strengthening authentication through measures such as moving away from SMS OTPs, binding accounts to single devices and introducing cooling-off periods.

The problem, Liu argues, is that these controls are increasingly defending against the wrong point of attack.

He stressed that this does not mean banks should abandon cyber security. Identity assurance remains the foundation upon which behavioural analysis depends.

However, the next ringgit of defensive investment may deliver greater protection through behavioural and counterparty intelligence than another authentication layer.

Keeping security as fast as the payment

The challenge becomes particularly acute as Malaysia’s payment infrastructure becomes faster.

DuitNow has made it possible to move money almost instantly, but that convenience has also compressed the time banks have to identify suspicious transactions.

Liu does not believe speed and security necessarily have to be competing objectives.

“Speed and security compete only when the risk architecture is slower than the payment rail,” he said. “That is an engineering condition, not a law of payments.”

The financial industry has already dealt with this problem through card networks, where risk controls evolved to operate within the speed of transactions rather than attempting to intervene after the payment had already gone through.

The same principle now needs to apply to instant payments.

PayNet processed 8.44 billion digital payment transactions in 2025, meaning risk decisions on instant payment rails need to happen in tens of milliseconds before funds are released.

That is technically achievable through architecture where risk features are calculated in parallel, counterparty and network risk is pre-computed and cached, and models are served at millisecond latency.

For institutions still relying on overnight batch analysis, Liu argues the issue is not really about choosing between convenience and security. The payment rail has already decided how quickly the bank needs to operate.

The real trade-off is between blanket friction and targeted intervention.

Lower transaction limits, mandatory delays and additional confirmation steps for everyone may reduce risk, but they also make legitimate banking more cumbersome.

Risk-based decisioning offers a more precise alternative. Most transactions can proceed without noticeable intervention, while a smaller proportion could trigger a targeted warning, additional confirmation or short hold. Only transactions with sufficiently strong evidence of fraud would be declined outright.

“The moment an institution finds itself slowing all customers down in order to feel safe, the thing to reconsider is its architecture, not its rails,” Liu said.

AI is changing the economics of the scam

The race is becoming even more complicated as artificial intelligence becomes a tool for both criminals and defenders.

Scammers can now use AI to generate convincing phishing messages, clone voices, create synthetic identities and produce deepfake personas at a fraction of the previous cost.

Liu believes offensive and defensive AI are evolving at comparable speeds, but the advantages are not evenly distributed.

“Offensive AI has won the economics of production,” he said, pointing to the collapse in the cost of manufacturing convincing deception.

Deloitte’s Center for Financial Services projects AI-enabled fraud losses in the US could rise from US$12.3 billion in 2023 to as much as US$40 billion by 2027, representing a compound growth rate of about 32%. Deepfake incidents in fintech have also risen sharply, while the UN Office on Drugs and Crime estimates Southeast Asia’s scam-centre economy generates around US$40 billion annually.

Yet Liu sees a structural advantage for defensive AI: banks have access to the wider data network.

A scam syndicate sees its own operation. A bank, by contrast, can potentially see the relationships between accounts, devices, counterparties and behavioural histories across its own network.

Increasingly, national infrastructure such as Malaysia’s National Fraud Portal can extend that visibility beyond individual institutions.

“Coordinated fraud is inherently visible at the network level, because coordination leaves geometry,” Liu said.

Synthetic identities reuse fragments. Mule networks share devices and cash-out routes. Scripted operations create clusters of similar behaviour.

AI can make an individual scammer more convincing, but it cannot necessarily conceal the broader structure of a criminal network from a defender analysing the whole graph.

At the individual customer level, Liu believes offensive AI is currently ahead, meaning banks should assume almost anyone can be convincingly impersonated.

At the network level, however, defensive AI can gain the upper hand, provided financial institutions use network analytics, continuously retrain models against live threats and bring fraud and anti-money laundering intelligence together.

The danger lies with banks still defending accounts individually using static models against what has become an industrialised criminal operation.

The problem with AI is not always the algorithm

As banks adopt more AI-driven fraud systems, another problem emerges: too many alerts.

Liu, who has built and audited fraud systems across banking and digital platforms in Southeast Asia, argues that the difference between effective AI and an expensive source of operational noise rarely comes down to the sophistication of the algorithm itself.

The first differentiator is the breadth of signals being assessed.

Systems built around simple thresholds, such as transaction amounts, new beneficiaries or foreign IP addresses, inevitably generate false positives because legitimate customers cross these thresholds every day.

More effective systems instead analyse hundreds of signals spanning devices, behaviour, history and counterparty context.

Network context is particularly important because unusual behaviour is not necessarily fraudulent.

A customer making their first large transfer, using a new device while travelling or making a payment at an unusual hour could trigger an alert when viewed in isolation.

But the risk looks very different depending on who is receiving the money.

A new transfer to a family member’s long-standing account is fundamentally different from a transfer to a three-week-old account that is already receiving money from multiple strangers.

“Most false positives are innocent-but-unusual behaviour,” Liu said. “A decision corroborated by the network is simply more accurate than an isolated score.”

The feedback loop is another critical component.

Every investigated alert produces a verdict that can become training data. Effective institutions can feed that information back into their models weekly or even daily, allowing them to learn from mistakes.

Banks that retrain annually, by contrast, risk producing the same false positives repeatedly and leaving investigators to rediscover the problem.

For Liu, one of the strongest indicators of whether a bank is using AI effectively is what its management chooses to measure.

Institutions generating noise tend to focus on fraud detected. Those using AI effectively also track precision, alert-to-case conversion and the impact on legitimate customers.

This matters because alert fatigue can itself become a security risk.

Investigators overwhelmed by false positives can miss the genuine case hidden among them, while customers repeatedly exposed to unnecessary warnings may learn to ignore the one that actually matters.

“Every unnecessary alert quietly spends down the attention you will need in a genuine emergency,” Liu said.

Fraud prevention is becoming a race against time

This emphasis on speed is also changing the regulatory landscape.

Liu believes regulators across Southeast Asia are moving towards a model where banks will increasingly be assessed not only by the amount of money lost to fraud, but by how quickly institutions detect, respond to and contain it.

Malaysia is already building infrastructure that makes those timelines measurable.

The National Fraud Portal, operated by PayNet under BNM’s direction, has reduced fund tracing from what was previously a multi-day correspondence exercise to roughly 30 minutes and improved mule-account detection by about 14%, according to Liu.

The National Scam Response Centre also operates around the clock, while BNM and PayNet are developing a national AI-driven fraud detection capability designed to identify suspicious transactions before they are completed.

Once infrastructure can measure time-to-trace and time-to-freeze, Liu believes it is only a short step towards regulators supervising against those metrics.

Other countries in the region are moving in parallel.

Singapore’s Shared Responsibility Framework, which came into force in December 2024, assigns specific duties to banks and telecommunications companies and uses a waterfall model where the party failing its obligations bears the customer’s loss.

Thailand’s 2025 framework goes further, covering authorised and unauthorised fraud and involving telcos, social platforms and digital asset operators in shared responsibility.

Malaysia’s own fair-treatment framework currently centres on unauthorised transactions, although BNM has signalled that it is assessing an expansion. Liu believes this will become increasingly important given that 95% of online fraud cases involve authorised transactions.

“Accountability is shifting from how much was lost to what each institution did, and how fast,” he said.

For management teams, Liu recommends assuming that interception rates, time-to-detect and containment speed will eventually become reportable, comparable and potentially public metrics.

That would structurally favour pre-authorisation detection over batch-based fraud analysis.

Seeing the mule before the money arrives

One of the most significant opportunities for AI lies in tackling mule accounts before they are used to receive stolen funds.

Liu believes this is possible because a mule account can become identifiable as infrastructure before it becomes identifiable as a crime.

A mule account has a lifecycle. It can be recruited or purchased, opened or repurposed, connected to a criminal network, warmed up and eventually activated.

The actual crime becomes visible when stolen money enters the account. But the infrastructure connecting that account to the criminal operation may appear much earlier.

Patterns such as unrelated accounts being accessed from the same devices, identity fragments being reused across registrations, dormant accounts suddenly becoming active and session behaviour resembling an operator managing multiple accounts can all provide early warning signals.

Individually, each account may look legitimate. Viewed as a network, however, the picture can change dramatically.

This is where graph intelligence becomes important.

Liu said TrustDecision’s graph-based detection in banking deployments has increased mule-network identification three-to-five-fold compared with account-level approaches while reducing false alerts.

The reason is straightforward: a risk assessment supported by dozens of connected accounts is more reliable than dozens of isolated assessments.

That can allow banks to restrict, monitor or investigate high-risk networks before stolen money arrives.

Malaysia has already built significant infrastructure around the issue. The National Scam Response Centre blocked more than 160,000 mule accounts in 2025, while amendments to Sections 424A to 424D of the Penal Code have criminalised mule-account activity.

The National Fraud Portal also gives institutions a shared, data-driven view of mule risk.

But Liu believes the industry remains in transition.

Leading banks are already operating pre-emptively at network level, while the industry average remains more reactive, often beginning the investigation only after a victim reports a scam.

“Closing that gap is less a technology question now than a deployment one,” he said.

AI does not change who is accountable

As AI takes on a greater role in making financial risk decisions, the technology also raises questions about governance and accountability.

Liu’s position is unequivocal: banks cannot outsource responsibility for risk outcomes.

“The institution owns the risk. Management owns implementation, validation and operation,” he said.

Technology providers should be accountable for what they contractually represent, but a vendor cannot absorb a financial institution’s regulatory or fiduciary responsibilities.

The answer, in Liu’s view, is not a completely new governance framework but an extension of existing model risk management practices.

Banks have governed statistical models for decades through independent validation, documented assumptions, performance monitoring and clear ownership.

AI fraud models should be subject to the same discipline, adapted for systems that may retrain continuously against a rapidly changing adversary.

Boards should demand a complete inventory of AI decision-making models, with models tiered according to materiality.

Independent validation should include adversarial testing against AI-generated fraud, while explainability needs to be sufficient for banks to justify decisions to regulators or affected customers.

Performance drift should also be continuously monitored, with clear escalation thresholds for management and the board.

Most importantly, human authority over the machine must remain clear, including who can override a model, based on what evidence and within what timeframe.

If an AI system misses a major fraud pattern, Liu believes the board should not simply ask whose algorithm failed.

The more important question is whether the failure fell within the risk appetite the institution knowingly accepted and whether its governance framework identified the weakness before the losses did.

“An institution that can answer that question well was governing. One that cannot was merely deploying,” he said.

Malaysia is not under-teched

Despite Malaysia’s rapid digitalisation, Liu does not believe technology itself is the sector’s biggest weakness.

The bigger constraint is governance and human expertise.

An Asian Institute of Chartered Bankers survey found that more than 70% of Malaysian financial institutions have implemented or are actively exploring AI, while national infrastructure such as the National Fraud Portal and the planned national fraud-detection capability puts Malaysia among the stronger markets in the region.

“Malaysia is not under-teched,” Liu said.

Instead, the sector needs to strengthen model governance.

Fraud models can now retrain weekly or continuously against criminals who adapt within days, yet some institutions continue to govern them using processes designed around credit scorecards that might be reviewed annually.

“Governance that runs slower than the model it governs is decorative,” Liu said.

There is also a shortage of professionals capable of looking across traditionally separate disciplines.

Criminal organisations increasingly combine fraud, money laundering and cyber intrusion into one operation, while banks may still manage these threats across separate departments, data sets and teams.

The most valuable professionals, therefore, are not necessarily machine learning engineers who can be hired from the wider market, but specialists who can interpret a mule network, AML typology and session anomaly as parts of one picture.

That expertise needs to be developed internally through rotation and investment.

Frontline analysts also need to understand how to interpret model output, adjust thresholds and challenge AI when it is wrong.

Without that human layer, sophisticated technology can quickly become either shelfware or another source of noise.

The line between protection and privacy

The next frontier may be even more sensitive: using AI to determine whether customers are being manipulated while they are making a transaction.

Liu believes the technology can identify behavioural signs of coercion.

A customer being guided by a scammer may hesitate where they would normally act fluently, move mechanically quickly where they usually pause, make a transfer while on a call, send money to a first-time beneficiary or suddenly move an amount far outside their historical pattern.

None of these signals is conclusive on its own.

Combined in real time and compared against the customer’s individual baseline, however, they can distinguish routine behaviour from patterns associated with pressured compliance.

Importantly, Liu argues that banks are not necessarily required to collect entirely new categories of information to do this.

Much of the relevant data already passes through banking systems as part of executing transactions. The challenge is understanding the signals within it.

The ethical question, therefore, is about how that information is used.

Analysing transaction context in real time for the purpose of protecting a customer is fundamentally different from building behavioural profiles for marketing or pricing.

Liu points to established principles including purpose limitation, data minimisation, proportionate intervention and explainability.

Privacy-preserving technologies such as federated learning can also allow institutions to benefit from collective intelligence without pooling raw customer data.

Perhaps most importantly, he believes fraud interventions should return agency to the customer rather than remove it.

A generic block can frustrate customers. A targeted warning explaining that a transaction resembles a police-impersonation scam, for example, could interrupt the scammer’s script while giving the customer enough information to make a more informed decision.

Banks that make such protective analytics transparent could ultimately strengthen customer trust rather than undermine it.

Data sharing could reshape Southeast Asian fraud prevention

Looking five years ahead, Liu believes deeper industry-wide data sharing is likely to have the greatest impact on fraud prevention across Southeast Asia, with regulation acting as the enabler.

Better AI models will continue to improve regardless, while customer behaviour remains the least explored part of the equation.

The reason is the nature of the adversary itself.

Scam operations across Southeast Asia are transnational, operating across borders, banks, telecommunications companies and online platforms. Their structure deliberately prevents any single institution from seeing the full operation.

That makes intelligence infrastructure increasingly important.

Malaysia’s National Fraud Portal, Singapore’s COSMIC platform for financial crime information sharing and national-level AI fraud detection systems point towards a model where fragmented intelligence can be brought together.

If such systems expand across borders and sectors, potentially supported by privacy-preserving computation, individual institutions could begin to see a much more complete picture of criminal networks.

Regulation could provide the forcing function.

Without regulatory requirements, data sharing can move at the pace of the most cautious legal department. New frameworks can instead turn information sharing from a voluntary initiative into an obligation.

But Liu believes customer behaviour deserves much more attention than it currently receives.

Scam awareness campaigns have helped, but they have also reached a ceiling. People can be highly confident in their ability to recognise scams while still being manipulated when confronted with a convincing, emotionally targeted fraud.

The next step, therefore, should be decision design.

Instead of simply telling customers to be more careful, banks could redesign the moment of payment so that the safer decision becomes easier to make.

This could involve beneficiary verification before funds move, warnings that identify the specific type of scam at the exact moment of risk and reporting mechanisms designed to reduce the shame that can prevent victims from seeking help quickly.

“The industry spends billions on detection and comparatively almost nothing on the design of the three seconds in which a manipulated customer decides,” Liu said.

For Liu, that represents one of the cheapest and most underused forms of defence available to the financial sector.

As scams become increasingly automated and personalised, the future of fraud prevention may therefore depend not simply on building smarter machines, but on building systems capable of understanding the human being on the other side of the transaction.

Latest News

Must read