
Southeast Asia’s (SEA) rapidly growing digital economy is bringing about a new set of risks and challenges for its digital society.
INTERPOL 2025/2026 Asia and South Pacific Cyberthreat Assessment found that cybercrime now accounts for over 30% of all recorded crime in more than half of the countries it surveyed. Moreover, the Global Anti-Scam Alliance (GASA) report in 2025 found that 63% of adults in the region have experienced a scam attempt in the past 12 months. Children in the region are similarly exposed to these threats, with 79% having encountered a form of digital harm. Nonetheless, the region has made strides in the right direction. Malaysia’s Online Safety Act 2025 now provides an extensive definition of harmful content to cover child sexual abuse material, financial fraud, harassment, terrorism and indecent content. Moreover, the recent Cybercrimes Bill passed in July 2026 has expanded the definitions of computer-related offences to combat emerging cybercrimes that involve advanced technologies such as Artificial Intelligence (AI).
Against this increasingly complex digital environment, the institute shared TFGI’s findings on building digital resilience in SEA, focusing on digitally-enabled scams and fraud as one of the region’s most pressing online harms.
Key Takeaways
1. Confidence in threat detection does not translate to response readiness
Preliminary findings from TFGI’s upcoming report on the SEA-6 region (Indonesia, Malaysia, Philippines, Singapore, Thailand, and Vietnam) reveal that over 60% of Malaysians have personally encountered a scam or fraud attempt. Compounding this issue, 40% of victims suffered losses of money or sensitive personal information.
While 98% of Malaysian respondents express concern over scams and 84% feel confident in detecting them, only 13% are genuinely “scam-ready”, i.e. knowing how to take safe actions like reporting an attempt. The majority (63%) are only “moderately scam-ready,” frequently engaging in risky behaviour such as sharing suspicious links. These findings highlight that confidence does not equal resilience. National campaigns must shift focus from simply identifying scams to educating users on how to respond safely.
2. Combatting cyber threats requires a whole-of-society approach
No single entity can effectively tackle scams and fraud alone. As such, TFGI advocates for a whole-of-society approach which distributes responsibility between formal stakeholders such as the authorities (e.g., governments) and businesses, as well as informal players like civil society, digital society (e.g., community networks), and end users.
Malaysia has previously leveraged inter-agency coordination through initiatives like the National Scam Response Centre in 2022, which integrated the efforts of the Royal Malaysia Police, Malaysian Communications and Multimedia Commission (MCMC), Bank Negara Malaysia, and other institutions to ensure a timely response.
To operationalise a whole-of-society approach in Malaysia, TFGI recommended collaborating not only with the authorities, but also with other relevant stakeholders:
- Businesses that offer digital goods, services and infrastructure such as those in the e-commerce space (Shopee, Lazada), digital financial services (Touch ‘n Go) and telecommunications (Telekom Malaysia)
- Civil society organisations with advocacies for safe and inclusive digital spaces, like the Sinar Project, EMPOWER Malaysia and Scam Ready ASEAN
- Local community networks led by village heads, neighbourhood associations and religious leaders
Such an approach must also account for sociocultural nuances. Malaysia, for example, has a culture of underreporting scam or fraud attempts, with less than half of victims reporting incidents to authorities, as well as the prevailing stigma that prevents victims from seeking help. Understanding these subtleties ensures that the psychosocial factors of scams and fraud are addressed through multidisciplinary solutions.
3. Shifting the mindset from cyber safety and security to cyber resilience
Today, cyber threats exploit both human psychology and technical loopholes. As such, there is a need to shift the mindset from cyber safety and security to cyber resilience.
At the roundtable event, TFGI shared its cyber resilience framework, which spans four phases: Protect, Identify and Detect, Respond and Recover, and Adapt. This framework aims to guide appropriate interventions to build digital resilience. The Protect phase focuses on reducing the incidence and potential damage of cyberattacks through proactive, preventive measures. In the Identify and Detect phase, examples across the region show the significant role that citizen-driven reporting can play in building cultural vigilance. For instance, Vietnam’s ChongLuaDao enables the public to report suspicious activities, thereby supporting community-based verification systems. For Respond and Recover, the focus is on enhancing society’s capacity to act swiftly and effectively after a scam has occurred. Lastly, the Adapt phase means strengthening the long-term capacity of societies to stay ahead of emerging and evolving scam threats, which can include regulatory changes.
Beyond strengthening national response, regional coordination is essential as scam operations increasingly become transnational. A 2026 INTERPOL report reveals that over 300,000 victims trafficked into SEA scam operations originated from 66 different countries. Since online harms transcend borders, with perpetrators operating across platforms and jurisdictions at scale, recent ASEAN initiatives, such as the ASEAN Digital Economic Framework Agreement (DEFA), are critical for aligning regulatory and enforcement capacities to monitor, prosecute, and address cross-border crimes.
