Compliance Hub

Fraud Prevention in Malaysia: BNM Requirements for Banks

Site Logo
Tookitaki
07 Sep 2026
6 min
read

Malaysia recorded RM1.57 billion in online fraud losses in 2024, up from RM1.22 billion in 2023 - an increase of approximately 29%. Home Ministry figures subsequently put 2025 losses at RM2.97 billion, an increase of roughly 89% year on year. Non-existent investment scams accounted for RM1.46 billion of the 2025 total, while telecommunications scams accounted for RM802.47 million.

The speed and scale of these losses matter for banks because scam proceeds can move through mule accounts and across institutions before a victim reports the incident. The challenge is not limited to unauthorised account takeover. Bank Negara Malaysia (BNM) reports that about 95% of online fraud cases in Malaysia involve authorised transfers, in which victims are deceived into sending the money themselves.

BNM's revised Risk Management in Technology (RMiT) policy, effective 28 November 2025, strengthens the fraud-detection and authentication baseline. It requires detailed customer risk profiles, behavioural analysis, real-time fraud analytics, the ability to detect and block suspicious transactions, and stronger multi-factor authentication.

The regulatory direction is technology-neutral but outcome-focused: institutions must identify suspicious activity in real time, stop or hold flagged transactions where appropriate, verify with customers and maintain authentication controls that resist phishing and interception.

Talk to an Expert

The fraud risks Malaysian institutions face

Mule-account exploitation

Mule accounts are a critical part of Malaysia's fraud infrastructure. Scam proceeds are paid into these accounts and then dispersed or withdrawn, complicating tracing and recovery. In September 2024, PDRM reported that the Semak Mule portal listed 216,074 mule accounts and 178,006 phone numbers used by scammers. The portal is a public checking service based on details previously reported in commercial-crime cases.

PDRM separately reported more than 208,000 mule accounts in August 2024, including accounts belonging to some university students. Students were reportedly offered amounts ranging from RM100 to RM1,000 to lend or surrender their accounts. These figures refer to accounts, not necessarily the same number of distinct account holders.

An individual transfer into a mule account may look ordinary. Stronger detection therefore combines customer-level behavioural monitoring with counterparty, device and network indicators. Relevant patterns can include rapid inflows from unrelated senders, quick dispersal to a concentrated set of destinations, sudden activity in a previously inactive account and transfers to accounts already identified in fraud repositories.

Impersonation and telecommunications scams

Telecommunications scams include impersonation schemes commonly described as Macau scams. Fraudsters may pose as police officers, regulators, bank staff or other authorities and claim that the victim is implicated in an investigation. The victim is then instructed to transfer money to a supposed 'safe' or designated account.

The relevant detection indicators depend on the customer's established behaviour. They may include unusually large transfers to new beneficiaries, multiple debits over a short period, changes to contact or device details, or withdrawals that leave an unusually low balance. These indicators should be treated as risk signals rather than proof that a transaction is fraudulent.

Investment scams and authorised payment fraud

Non-existent investment schemes produced the largest reported fraud losses in Malaysia in 2025. Victims may be recruited through social media, messaging applications, online advertisements or impersonated investment professionals. Payments can escalate over time as fraudsters display fictitious profits and request further deposits, taxes or release fees.

Because the customer often authorises these transfers, valid credentials and successful MFA do not establish that the payment is safe. Detection needs to assess the transaction context, including the beneficiary relationship, changes from prior behaviour, payment velocity, counterparty risk and any intelligence linking the destination to suspected fraud.

Unauthorised online-banking fraud and account takeover

Phishing, malware, credential theft and social-engineering attacks can give criminals control of a customer account or device. Relevant controls include secure device binding, robust verification when customer details change, cooling-off periods, device-fingerprint monitoring, hijacked-session detection and real-time anomaly analysis.

BNM's framework distinguishes these unauthorised transactions from scams in which customers knowingly initiate transfers under deception. The distinction matters because different prevention, investigation and compensation obligations apply.

DuitNow and the compressed intervention window

DuitNow enables instant, cross-bank transfers. That speed benefits customers but gives institutions less time to identify and interrupt suspicious payments before funds reach the recipient and potentially move onward.

DuitNow transactions should not be described as universally irreversible. PayNet supports defined reversal and refund processes, including certain dispute and suspected-fraud scenarios. Nevertheless, recovery can become much harder once funds have been credited, withdrawn or transferred through additional accounts.

fraud-prevention-malaysia-bnm-under-200kb

BNM's fraud-prevention requirements

RMiT November 2025: applicability and legal status

The revised RMiT policy took effect on 28 November 2025, except where the document states otherwise. Its scope includes licensed banks, investment banks, Islamic banks, insurers and takaful operators, prescribed development financial institutions, eligible e-money issuers, designated payment-system operators, qualifying non-bank merchant acquirers and qualifying intermediary remittance institutions. Some provisions contain entity-specific exclusions, so institutions should assess the detailed applicability clauses rather than assume that every requirement applies identically to every entity.

The 2025 policy superseded several earlier instruments, including the August 2022 specifications on electronic-banking fraud, the May 2022 measures addressing fraud monetised through internet and mobile banking, the June 2023 RMiT policy and the March 2024 Fraud Detection Standard. The current behavioural-profiling and real-time fraud-detection requirements are therefore best understood through the revised RMiT policy and its appendices.

Authentication controls

MFA for covered transactions. Financial institutions must adopt MFA for financial transactions and high-risk non-financial transactions, including registering favourite beneficiaries and subsequent transfers to them.

Protection against phishing and interception. The MFA solution must be resistant to interception or manipulation and use technology and channels more secure than unencrypted SMS.

Transaction binding. The payer must be shown the beneficiary and amount. The authentication code must correspond to those confirmed transaction details.

OTP requirements. If OTP is used as an additional factor, it must be dynamic, time-bound, bound to transaction details and generated locally on the customer's device rather than on the bank's server. This is more precise than describing RMiT as a blanket ban on every form of OTP.

Device binding. Authentication is restricted by default to one mobile or secure device per account holder, except when the customer specifically requests otherwise and understands and accepts the risk.

Fraud-detection controls

Detailed customer risk profiles. Institutions must create comprehensive profiles for behavioural fraud detection. Relevant inputs can include demographic and geographic information, historical transaction patterns, new beneficiaries, transaction velocity and behavioural indicators such as time taken to complete a transfer.

Real-time detection and blocking. Institutions must be able to detect and block suspicious or fraudulent retail digital-service transactions in real time using fraud risk analytics based on individual customer profiles.

Broad indicator coverage. The minimum indicators include account and credential changes, unusual transaction patterns, device-fingerprint changes, suspected mule recipients, previously reported accounts or devices, biometric changes and attempts to use advanced AI techniques to bypass controls.

Verification before release. Flagged transactions must be investigated and verified with the customer before release. Customers must be notified when a transaction is blocked, and institutions must maintain sufficient resources to contact affected customers within 30 minutes of the transaction, including during peak periods.

Continuous updating. Fraud rules, parameters and thresholds must be updated as new techniques and typologies emerge, including intelligence received from other institutions, industry groups, public-private partnerships and other sharing platforms.

SEFT: fair treatment of victims of unauthorised transactions

BNM's Policy Document on Ensuring Fair Treatment for Victims of Unauthorised e-Banking Transactions (SEFT) took effect in October 2024. It applies to unauthorised transactions, such as certain account-takeover, malware and phishing cases; it does not currently cover payments that customers initiate themselves under deception.

Under SEFT, banks must conduct robust and transparent investigations, assess their own controls before considering the customer's actions, communicate the reasons for the outcome and provide access to independent review and dispute channels. Compensation is not automatic: depending on the evidence, the bank, customer or both may bear responsibility.

National Fraud Portal and coordinated response

The National Fraud Portal (NFP) went live operationally in April 2024 and was publicly launched on 20 August 2024. It is an integrated platform developed through BNM, PayNet and the financial industry to strengthen the National Scam Response Centre. It automates case handling and fund tracing, supports information sharing among participating institutions and uses industry data to improve mule-account assessment.

PayNet describes the NFP as infrastructure through which the NSRC and participating institutions log fraud cases, issue alerts, trace transactions and coordinate actions such as freezing funds or blocking mule accounts. It also includes an industry mule database.

The NFP is distinct from the public Semak Mule checking portal. Each institution's NFP participation, data access and technical workflow must follow the applicable industry procedures, permissions and regulatory directions; these arrangements should not be assumed to create a universal requirement for any particular vendor integration.

What effective fraud prevention requires in practice

1. Customer-specific behavioural baselines

Risk profiles must evolve with actual customer behaviour. Static onboarding classifications alone cannot identify a transfer that is unusual for a particular customer, even when its amount sits below a generic threshold.

2. Decisions before suspicious funds are released

Real-time monitoring needs to evaluate transactions early enough to block or hold a flagged payment, perform customer verification and release it only when the risk has been resolved. Post-event monitoring remains important for investigation and reporting, but it cannot replace preventive controls.

3. Mule and counterparty intelligence

Institutions should connect customer behaviour with device, counterparty and network signals. For mule detection, useful indicators include rapid pass-through activity, many unrelated inbound senders, concentrated onward beneficiaries, account dormancy followed by sudden activity and matches against permitted fraud repositories.

4. Controls for authorised as well as unauthorised fraud

Authentication is essential for stopping account takeover, but it does not determine whether a customer is acting under manipulation. Effective programmes combine secure authentication with contextual warnings, risk-based friction, customer confirmation and verification procedures designed to identify coercion or social engineering.

5. Coordinated fraud and AML investigation

Mule accounts create both fraud and money-laundering risk. Connecting fraud alerts, transaction-monitoring indicators and case evidence gives investigators a more complete view of the account, related parties and movement of funds. For more on this operating model, see Tookitaki's FRAML guide.

Questions Malaysian institutions should test

Can the fraud engine build and refresh individual behavioural profiles using transaction, device, customer and counterparty data?

Can it score and stop suspicious transactions in real time, while preserving evidence of the decision and verification outcome?

Do authentication controls meet the transaction-binding, device and interception-resistance requirements in RMiT?

Can operations notify blocked customers immediately and support the required verification and contact process, including during peak periods?

Are external fraud and mule-account intelligence sources incorporated only through authorised, governed and auditable processes?

Do fraud and AML teams share relevant signals and case context without duplicating investigations or weakening accountability?

Does the institution have a documented SEFT process covering investigation, independent review, customer communication, compensation assessment and escalation to the Financial Markets Ombudsman Service?

How Tookitaki’s FinCense can support Malaysian institutions

Tookitaki's FinCense platform brings fraud prevention, transaction monitoring, customer risk scoring, screening and case management into a connected financial-crime operating environment. Its fraud-prevention capabilities include real-time anomaly detection, multi-channel analysis and customer-level risk scoring.

This architecture can support the behavioural profiling and fraud-risk analytics described in RMiT. Deployment design remains institution-specific: the bank must determine the relevant data, controls, thresholds, payment actions, authentication workflow and governance needed to meet its obligations.

FinCense also connects to the Anti-Financial Crime (AFC) Ecosystem, a repository of expert-validated financial-crime scenarios and typologies contributed by a community of more than 30 banks, fintechs and specialists across APAC and beyond. The ecosystem shares behavioural typology logic rather than customer, transaction or account data.

A community typology does not automatically become a live control. It is translated into machine-readable risk factors, calibrated using the institution's own data, simulated against historical activity and then approved for production under the institution's governance process.

FinCense’s case management can centralise alerts, investigation evidence, decisions and regulatory workflows. Where an institution is authorised to ingest external fraud intelligence, that information can be incorporated through an approved technical integration. Any connectivity with the NFP would need to be validated for the specific institution, access arrangement and deployment.

For authentication, FinCense transaction risk scores can provide an input to a bank's step-up or verification workflow when integrated with the institution's payment and authentication systems. The institution's authentication controls remain responsible for satisfying the detailed RMiT requirements.

Book a demo to explore how FinCense can support behavioural fraud analytics, mule-risk detection, real-time transaction decisions and integrated fraud and AML investigations for Malaysian financial institutions.

Frequently asked questions

What does BNM's November 2025 RMiT policy require for fraud detection?

RMiT requires detailed customer risk profiles, behavioural analysis, real-time fraud analytics, detection and blocking of suspicious transactions, investigation and customer verification before flagged transactions are released, and continuing updates to detection rules and thresholds.

Does RMiT ban SMS OTP?

RMiT requires MFA for financial and high-risk non-financial transactions and requires MFA technology and channels that are more secure than unencrypted SMS. If OTP is used as an additional factor, it must be dynamic, time-bound, transaction-bound and generated locally on the customer device. Therefore, describing every form of OTP as prohibited would be inaccurate.

How large is the mule-account problem in Malaysia?

PDRM reported 216,074 mule accounts and 178,006 scam-linked phone numbers listed in Semak Mule in September 2024. The continuing scale of mule activity makes customer, counterparty and network-level detection important. These figures describe listed accounts and identifiers, not necessarily an equivalent number of unique people.

What is the National Fraud Portal?

The NFP is an integrated platform supporting the NSRC, participating financial institutions, BNM and law enforcement. It supports scam-case handling, automated fund tracing, alerts, industry information sharing and mule-account assessment. It is managed operationally by PayNet and should not be confused with the public Semak Mule checking portal.

Why does DuitNow create a specific fraud-control challenge?

DuitNow moves funds instantly, compressing the period available for intervention. This makes real-time risk assessment and prompt action particularly important. Although PayNet supports defined reversal and refund processes, recovery is not assured and becomes harder after funds move onward.

How much did Malaysia lose to online fraud?

PDRM reported RM1.57 billion in 2024, approximately 29% above RM1.22 billion in 2023. Home Ministry figures reported in June 2026 put 2025 losses at RM2.97 billion, with non-existent investment scams responsible for the largest share.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
07 Sep 2026
5 min
read

Customer Risk Scoring in AML: Why Static Models Fail and What Dynamic Scoring Looks Like

Customer risk assessments must remain current as customer circumstances and behaviour change. Learn where static AML risk models fall short and how event-driven, explainable scoring can strengthen ongoing due diligence.

Customer Risk Scoring in AML: Why Static Models Fail and What Dynamic Scoring Looks Like
Blogs
31 Aug 2026
5 min
read

From Telegram Chats to Money Trails: The AML Risk Behind Penang’s Love-Scam Bust

Explore AML lessons from Penang’s love-scam bust, where Telegram-enabled deception exposed mule account, cross-border and money trail risks.

From Telegram Chats to Money Trails: The AML Risk Behind Penang’s Love-Scam Bust
Blogs
31 Aug 2026
5 min
read

Fraud Prevention in New Zealand: What Banks and Financial Institutions Need to Know in 2026

New Zealand banks reported NZD 194 million in scam losses in 2023-24. Investment fraud drove over NZD 100 million of those losses. This guide covers the regulatory framework, the new Banking Code scam protections, and what a fraud programme needs to address in the current environment.

Fraud Prevention in New Zealand: What Banks and Financial Institutions Need to Know in 2026