Thursday 17 Sep 2026
main news image

This article first appeared in Digital Edge, The Edge Malaysia Weekly on September 8, 2025 - September 14, 2025

In early 2024, a multinational firm reportedly lost over US$25 million to a deepfake-enabled scam. The attackers used artificial intelligence (AI) to convincingly impersonate a senior executive on a video call, successfully deceiving finance staff into transferring funds.

Not long after, similar deepfake threats were detected in Malaysia, including a thwarted attempt involving a prominent financial institution. These cases are a stark reminder that identity-based attacks powered by AI are no longer theoretical. They are here, they are growing, and they demand urgent action.

The rise of AI-generated deception, from deepfake videos to synthetic voice cloning, has introduced a dangerous new dimension to digital fraud. Malaysia’s rapid digitalisation and growing reliance on virtual communications make it especially vulnerable. As the country expands its digital economy, the security of its identity infrastructure is becoming mission-critical.

What makes deepfakes so insidious is their ability to hijack the most fundamental element of any interaction: trust.

In the past, phishing scams relied on poorly worded emails or fake websites. Today, an attacker can convincingly mimic the face and voice of a known colleague, appearing in a video call to request urgent financial action. For employees and systems alike, distinguishing real from fake is becoming increasingly difficult.

A 2023 study found that incidents involving deepfakes rose by more than 700% globally, with Southeast Asia seeing a marked uptick. These include impersonations of C-level executives, fake job interviews to harvest personal data and manipulated on-boarding processes to create synthetic employee identities within corporate systems.

These attacks aren’t just embarrassing or expensive, they strike at the credibility of institutions and expose critical infrastructure to systemic risk.

At the centre of this challenge is the need for more resilient digital identity frameworks. When identities can be convincingly forged with a few data points and AI models, traditional credentials — passwords, email verifications, even facial images — are no longer sufficient.

The concept of “trusted identity” must evolve. It’s not enough to verify that someone has the right username or even the right face. Organisations must ask: Is this identity real, alive and authorised, in real time?

Strong identity verification is becoming foundational to digital resilience. This includes:

● Biometric authentication with anti-spoofing safeguards to ensure a live, physical presence;

● Multi-factor authentication (MFA) that moves beyond SMS codes to biometrics, mobile tokens and behavioural analysis;

● Liveness detection and AI-based analysis to spot synthetic images or videos; and

● Behavioural biometrics that continuously verify identity through typing patterns, mouse movements and device usage.

Policy and infrastructure gaps

Malaysia’s ongoing rollout of MyDigital ID is a significant step toward modernising identity infrastructure. However, building technical capabilities is only one part of the solution. A resilient digital identity ecosystem also requires:

● Clear data governance frameworks, with well-defined responsibilities for issuers, holders and verifiers of identity;

● Cross-sector interoperability, so identity credentials can be securely used across government, finance, healthcare and commerce;

● User privacy and control, allowing individuals to manage and consent to how their identity data is used; and

● Continuous innovation, including investments in AI-powered threat detection and adaptive identity technologies.

Without these elements, even the best-intentioned digital identity systems can fall short in the face of evolving threats.

Countries around the world offer useful case studies. Estonia’s digital ID system has enabled secure, frictionless access to services for over two decades, grounded in strong encryption and user control. In India, the Aadhaar system combines biometric identity with layered authentication options. The European Union is advancing a pan-European digital identity wallet that gives citizens the ability to prove their identity across borders.

In each case, success depends not just on technology, but on public trust, strong regulation and coordinated action across sectors.

Malaysia has an opportunity to learn from these efforts — and to lead, particularly within Asean — by developing a digital identity system that is resilient against fraud, inclusive by design and secure against misuse.

While governments have a crucial role to play, private-sector organisations must not wait for regulation to catch up. Every company is now a digital identity provider, whether issuing employee credentials, onboarding customers or managing supply chain access.

Corporate leaders must recognise that identity is no longer an administrative concern; it is a cybersecurity imperative. Boards should be asking:

● Do we have systems in place to detect deepfake or synthetic identity attacks?

● How do we verify new customers or remote employees?

● Are our access controls and identity systems keeping up with the threat landscape?

Cybersecurity training also needs to be updated. Telling employees to “be vigilant” is no longer enough when fake videos and voices can mimic trusted individuals. Organisations must equip teams with tools and protocols that match the sophistication of modern threats.

Malaysia’s digital economy is poised for tremendous growth, with initiatives in smart government, digital banking and health tech gaining pace. But with increased connectivity comes increased risk and identity sits at the intersection of every transaction, every access point and every trust-based exchange.

The old model of identity — static, password-based, siloed — cannot withstand the speed and scale of AI-enabled fraud. What’s needed now is a national and sector-wide commitment to evolving digital identity into something that is secure, adaptive and rooted in privacy.

The solution to synthetic fraud isn’t fear — it’s investment in trust.


Vito Fabbrizio is vice-president of product management and innovation at HID, a leader in  identity management solutions

Save by subscribing to us for your print and/or digital copy.

P/S: The Edge is also available on Apple's App Store and Android's Google Play.

      Print
      Text Size
      Share