Online scams are among the biggest financial threats facing bank customers, and the syndicates behind them keep finding new ways to bypass existing defences. Banks introduced a core set of anti-scam measures in 2022 under the direction of Bank Negara Malaysia (BNM) and have since added more, including a formal compensation framework for victims.
Each protection covers a different part of the scam process, stopping a scammer from getting into your account, stopping money from moving out once they’re in, and what happens if the money’s already gone when you find out about the hack. The table below summarises what’s currently in place.
| Protection | What It Does |
| Real-time fraud detection | Flags suspicious transactions and alerts you by push notification, SMS or phone call |
| Bad software shielding | Restricts banking app access if bad software or suspicious remote access is detected on your device |
| Single-device registration | Limits online banking to one verified device, with extra verification for any device change |
| 12-hour cooling-off period | Delays activation after first-time enrolment or registration of a new device |
| Kill switch | Lets you instantly cut off online banking access if you suspect fraud |
| Shift away from SMS OTP | Moving to in-app authentication for most transactions; still allowed below RM250 for card payments |
| 24-hour NSRC hotline (997) | Connects you to police, BNM and your bank to help freeze stolen funds quickly |
| SEFT compensation framework | Sets out how banks investigate and compensate victims of unauthorised transactions |
There are some limitations, though. The compensation framework, for instance, only covers unauthorised transactions, not transfers you make yourself after being deceived.
How Banks Detect And Block Suspicious Transactions
Banks run automated systems that scan transactions for patterns associated with scams, such as unusual transfer amounts, new payees, or transfers made shortly after a login from an unfamiliar location. When a transaction is flagged, the bank verifies it with you via a push notification, SMS, or phone call before allowing it to proceed.
Bad software shielding adds another layer of protection on top of this. If a bank detects high-risk software or suspicious remote access on your device, it temporarily restricts access to its app until the threat is cleared. According to the Association of Banks in Malaysia (ABM), this feature helped prevent more than 60,000 malware-related scam attempts in 2025, involving an estimated RM22 million in potential losses.
Some banks also offer account-locking features that add extra protection. Maybank’s Money Lock on the MAE app, for example, lets you set aside part of your savings so it can’t be transferred out, even if a scammer gets into your account. ABM reports that more than 38,000 customers across its member banks were using similar lock features by 2025, protecting over RM600 million in combined value.
Kill Switch And Round-The-Clock Scam Reporting
If you suspect your account has been compromised, a kill switch lets you cut off all online banking access immediately, through the app or by calling your bank’s hotline. It stops every transaction, fake or not. Offering a self-service kill switch is now a formal BNM requirement under the Risk Management in Technology (RMiT) framework. Around 300,000 customers activated theirs in 2025, preventing close to RM7 million in potential losses, according to ABM.
Outside your bank, the National Scam Response Centre (NSRC) has operated 24 hours a day through its 997 hotline since September 2025, when it moved fully under the Royal Malaysia Police. A call to 997 is treated as an official police report, so you don’t need a separate trip to the station.
Call the NSRC specifically for online financial fraud, such as money being moved out of your account without your knowledge, or a transfer you were tricked into making yourself via your banking app or e-wallet. This covers phishing, Macau scams, love scams (sometimes known as a ‘pig-butcher’ scam) and job scams that end in a bank transfer.
Call as soon as you notice the loss, best within the first 24 hours. The NSRC exists to trace and freeze funds in real time, so it becomes less useful the longer you wait. You can also call if you've received a suspicious call or message and want a second opinion, even before any money has moved.
The centre also works with the National Fraud Portal, a system that connects BNM, PayNet and participating banks and can trace stolen funds within 30 minutes. Scammers typically move stolen funds through several mule accounts within hours, which is why tracing them that quickly keeps the money recoverable.
How Device Registration And The Cooling-Off Period Work
Malaysian banks restrict online banking to a single registered device at a time. Switching to a new phone or reinstalling the app triggers a fresh verification process, which may include in-app digital token authentication or e-KYC checks, such as fingerprint or facial recognition. New customers also start with a low default transfer limit and must raise it themselves through a secure channel. BNM’s own guidance sets RM1,000 per day as a conservative default. Maybank applies this figure to first-time registrations, though the exact amount varies by bank.
Registering a new device also starts a 12-hour cooling-off period, during which certain online banking activities are restricted. The same delay applies the first time you enrol in online banking. If a scammer registers your account on their device, they still have to wait out the cooling-off period before they can move money, giving you time to notice the problem and react.
These controls come from Bank Negara Malaysia’s Risk Management in Technology (RMiT) framework, which governs how banks secure the personal data you submit, or that they learn about you as you use your bank account.
RMiT also requires stronger verification for high-risk changes, such as updating your registered phone number. An OTP sent to your current number is no longer considered enough on its own, because a scammer who has already taken over that number could intercept it. Instead, banks are expected to confirm your identity another way, such as in person at a branch.
The Shift Away From SMS OTPs
SMS one-time passwords (OTPs) are being replaced by in-app authentication because scammers can intercept them or trick victims into forwarding them via phishing and malware. Banks are also required to remove clickable links from SMS messages sent to customers, which means any SMS claiming to be from your bank that contains a link is not actually from your bank.
SMS OTP is not being eliminated everywhere, though: under BNM's Credit Card and Credit Card-i policy, it will still be allowed for card transactions up to RM250 once that rule takes effect in January 2027, with anything above that threshold needing stronger authentication.
For card payments, banks now let you control your own settings. You can disable online card transactions if you rarely shop online. Or you can activate a card-level kill switch, separate from the account-wide one described earlier, that blocks your card the moment you report suspicious activity.
How SEFT Decides Who Gets Compensated
In October 2024, Bank Negara Malaysia introduced a policy known as SEFT, short for the Policy Document on Ensuring Fair Treatment for Victims of Unauthorised e-Banking Transactions. SEFT sets out how banks investigate scam claims and decide on compensation. Banks must first check their own systems for weaknesses, such as gaps in authentication or fraud alerts, before deciding whether the customer was at fault.
SEFT only covers unauthorised transactions: cases where a scammer got into your account and moved money without your knowledge. It doesn’t cover authorised transactions, where you approved the transfer yourself, even if you were tricked into doing so.
Most scams in Malaysia fall into the second category. BNM’s 2025 data shows that 95% of online fraud cases involve authorised transactions. Examples include a victim who transferred money after being convinced by a fake investment scheme, or one who paid after receiving a call from someone posing as a police officer. This means most scam losses currently fall outside SEFT’s protection. Malaysia’s official scam-loss figures, tracked by the Inspector-General of Police, show how large that gap is.
Where SEFT applies, banks are expected to complete their investigation within 14 days and provide temporary financial assistance if a case takes longer. If you disagree with a bank’s decision, you can ask for an independent review through the Financial Market Ombudsman Service (FMOS).
BNM has extended similar protection to e-wallets. Providers that fail to meet fraud safeguards must fully reimburse victims within seven working days, even if the customer shares some responsibility.
If You Think You’ve Been Scammed
- Contact your bank’s fraud hotline straight away and ask for the kill switch to be activated if you haven’t already done it yourself.
- Call the NSRC on 997, available 24 hours. This also counts as your police report, so you don’t need to visit a station separately.
- Note whether you authorised the transaction yourself or whether it happened without your knowledge. This affects whether SEFT’s compensation rules apply to your case.
- Keep a record of every call, email and reference number from your bank’s investigation, since you’ll need this if you ask the Financial Market Ombudsman Service for an independent review.
Always verify who you’re speaking to before sharing personal or banking details. Bank officers, police officers and couriers don’t ask customers to transfer money over the phone or through a messaging app.
Frequently Asked Questions
Does SEFT cover credit card fraud?
Not directly. SEFT applies specifically to unauthorised e-banking transactions, such as online transfers made without your knowledge. Credit card fraud is handled under BNM’s own Credit Card and Credit Card-i policy, which still requires banks to hold off on collecting the disputed amount and any related charges while they investigate.
What if my bank doesn’t have a kill switch?
Kill switches are now standard across licensed banks in Malaysia under BNM’s direction. If you can’t find the feature in your app, call your bank’s hotline and ask them to freeze your account directly.
Should I call my bank or the NSRC first?
Do both as quickly as you can. Your bank can freeze your account directly, while the NSRC works with BNM, PayNet and other banks to trace and freeze stolen funds across the banking system.
How long does an FMOS review take?
FMOS aims to resolve disputes within three to six months of receiving complete documents from all parties. If your case reaches a final Ombudsman review after an earlier stage, that decision is made within 14 days of receiving the complete documents.












