Sunday 04 Oct 2026
main news image

This article first appeared in Forum, The Edge Malaysia Weekly on May 5, 2025 - May 11, 2025

All it takes for a good scam to hit someone is for that person to let his or her guard down just once. The end result is a fraud that potentially changes the life of the victim forever. As for the scammers, they walk away with their loot without even needing to break open a safe.

Because scams rake in millions without the perpetrators getting caught, it is the most popular form of theft in the world today.

And nobody escapes the attention of scammers. Not even the stockbroking industry, which is largely made up of smart people who tend to be extra vigilant and may think that they are nobody’s fool to fall for a scam.

The truth is that these smart investors have just been plain lucky all these years that cheats on the dark side of technology have not encroached on their playground.

But two weeks ago, reality hit the Malaysian stockbroking industry. The industry was roiled by a breach in the trading system that resulted in numerous unauthorised trades taking place.

The breach comes two months after the departure of former Malayan Banking Bhd ­(KL:MAYBANK) chief financial officer (CFO) Khalijah Ismail, following an internal enquiry that revealed that the leading bank was nearly scammed in a dubious transfer involving US$985,426 (about RM4.77 million).

The former CFO almost fell victim to a deepfake where the perpetrators used artificial intelligence (AI) to conduct a Zoom call impersonating a colleague from Singapore. Apart from the Zoom call that lasted just a few minutes, the scammers bombarded the CFO with WhatsApp messages from two imposters who pretended to be her senior officers at the bank.

The incident, which was described as a “near miss” for Maybank, happened a year ago. But the details only emerged in February this year following Khalijah’s abrupt departure from the bank.

Although the transaction was called off on the same day that it was approved, Khalijah was subjected to disciplinary action by the bank for misconduct, including an alleged failure to fulfil her fiduciary duties as the CFO and for breaching the bank’s policies.

The matter is before the courts now.

Nevertheless, two incidents in the first four months of the year clearly show that AI and deepfakes are on Malaysian shores and have struck right at the heart of Corporate Malaysia, namely the banks and the stock market.

Hackers using AI to harvest thousands of ­datasets to breach the trading system and scammers using AI to create deepfakes such as video calls impersonating the target’s colleagues have surely caught the attention of bankers, Bank Negara Malaysia, stockbrokers, Bursa Malaysia and the Securities Commission Malaysia.

What is cause for concern is that a month ago, there was already a warning that the trading system could be compromised. Perhaps no one paid enough attention.

An investor claims to have lost RM500,000 in unauthorised trades about a month ago. The brokerage firm concerned was unable to get to the bottom of the breach. Eventually, the investor had to bear the losses which he is paying off over 13 months.

Nobody listened to this investor then. But now, after the trading system was hacked two weeks ago, it appears that the investor was probably a victim of a hack but nobody bothered about what looked like an isolated incident. The alarm bells finally rang when several accounts on the stock market were hacked simultaneously.

This happened on a Thursday afternoon when some investors could not log on to the trading system after lunch break. And then came a surge in the share prices of four stocks. After an investigation, the authorities confirmed that two stocks, namely Bina Puri Bhd (KL:BPURI) and Bina Puri Bhd Warrant (KL:BPURI-W) had seen unauthorised transactions.

The amount involved in these dubious transactions is not known but estimates based on the trading volume that day suggest that it could easily have been RM10 million.

Fortunately, the trades were done on a Thursday so the authorities had the weekend to investigate the abnormal price surge of the four stocks and separate the genuine trades from the unauthorised transactions. For now, the authorities have withheld the amount of proceeds from the unauthorised trades for 14 days.

What happens next is anybody’s guess. The high number of unauthorised trades and sudden jamming of the system is unprecedented. However, what is certain is that it can happen again.

The most vulnerable investors are those undertaking trades through online accounts. They buy and sell by themselves without going through a broker.

But considering that the system could be compromised with hackers using AI to harvest thousands of datasets, is it worth going back to the old practice of buying and selling stocks through a remisier?

The trading system used by local brokers is not the only target of hackers. Bourses in Japan and South Korea have also felt the brunt.

It is worth noting that it’s not only banks and stockbroking firms that have felt the adverse impact of AI-generated deepfakes.

The scams these days are high tech, where impersonation happens through video conferencing and WhatsApp messages targeting executives of companies. It is no longer about scamming some senior citizen into giving up their password and bank details.

The scammers imitate the voices and use the images of persons known to the victims so they let their guard down. They can copy almost anybody — from a son, daughter and parents to subordinates and bosses. Their aim is to reap millions from unsuspecting victims.

Last year, British engineering company, Arup, fell victim to an attack and lost £20 million. It happened when an employee in Hong Kong transferred the money in batches following a video call with a superior. It turned out that the superior was actually an AI-generated impersonator.

In Italy, a business tycoon transferred €1 million to scammers who mimicked the voice of defence minister Guido Crosetto, who was supposedly seeking cash to pay off kidnappers who had abducted some journalists.

Malaysia has launched several initiatives to counter AI-generated deepfakes. Among them is the rollout of MyDigital ID, which is supposed to reduce the risk of identity theft.

Banks also have in place measures to reduce the risk of scammers duping their customers into making money transfers. These include setting limits on transfers, requiring a one-time password and ensuring customers have a single device to authenticate online banking and e-wallet transactions.

But even with all these technological measures in place, the abuse of AI is here to stay. And scammers will always be looking to steal millions from the unsuspecting.

It’s only a matter of time before a victim is caught off his guard and gets sucked into a good scam.


M Shanmugam ([email protected]) is a contributing editor at The Edge

Save by subscribing to us for your print and/or digital copy.

P/S: The Edge is also available on Apple's App Store and Android's Google Play.

      Print
      Text Size
      Share