Who Pays When You’re Scammed in Malaysia? The Answer Isn’t What BNM’s Rules Imply
If you got tricked into approving a bank transfer yourself, Bank Negara Malaysia’s own compensation rule almost certainly doesn’t cover you. That’s not a gap regulators forgot to close. It’s a deliberate line. Most Malaysian scam victims are losing money on the wrong side of it.
I write about digital safety for a living. Even I assumed a rule this widely reported would cover the obvious case. It doesn’t.
Police recorded 67,735 online crime cases and more than RM2.7 billion in losses between January and November 2025 alone, according to Bernama. Bank Negara’s own 2025 Annual Report puts a number on how those scams actually happen. Roughly 95% of online fraud cases in Malaysia involve a victim who approved the transfer themselves, deceived into doing it. That’s the category the compensation policy everyone assumes protects you was never made to cover.
What Bank Negara’s rule actually promises
Bank Negara Malaysia does have a rule for this. It’s called SEFT, short for the Policy Document on Ensuring Fair Treatment for Victims of Unauthorised e-Banking Transactions. On paper it looks like exactly what you’d want.
Introduced in 2024, SEFT requires banks to examine their own security gaps before assigning any blame to the customer. It also treats liability as shared rather than all-or-nothing, assessed case by case instead of against a fixed formula. It’s working, to a point. Bank Negara reports a 26% year-on-year rise in victims receiving full or partial compensation in 2025.
That’s the part most coverage stops at.
The catch nobody’s flagging
SEFT has a scope limit that decides almost everything. It rarely makes the headline.
Bank Negara’s compensation rule only covers unauthorised transactions. That means money moved by a fraudster without your knowledge, through malware or stolen credentials. If you were the one who logged in and approved the transfer, even because a scammer talked you into it, SEFT does not apply. The policy’s own wording excludes “cases where customers initiate transactions themselves, including those made under coercion or undue influence, such as love or investment scams.”
In practice, that line covers almost nobody. Bank Negara’s own 2025 Annual Report says about 95% of Malaysian online fraud cases are transactions the victim authorised themselves. Love scams, fake investment schemes, police-impersonation calls. The deception happens before you ever touch your banking app. The transfer itself looks completely legitimate to the bank that processes it.
But isn’t that my fault?
A bank genuinely cannot tell the difference between you sending RM50,000 to a legitimate supplier and you sending RM50,000 to a scammer who’s convinced you he’s one. Not at the exact moment you approve it. Both look identical from the bank’s side: your login, your device, your confirmed instruction. Bank Negara has said openly it’s weighing whether to widen SEFT to cover vulnerable consumers. It has said just as openly that doing so carries a real trade-off. Automatic reimbursement for every deceived transfer could quietly teach customers to stop checking who they’re paying.
That’s a fair concern. Turning banks into insurers against every bad financial decision isn’t obviously better policy than the line as it stands. But “fair concern” and “nobody’s ever liable” are two different claims. Malaysian courts have started drawing a harder line than SEFT does.
What courts have decided when banks look away
Two Malaysian court rulings in 2026 said a bank’s job doesn’t end the moment you make a mistake.
In Ng Choon Luk v CIMB Bank Bhd, an 85-year-old customer with a 30-year banking relationship was tricked by scammers posing as police officers into handing over his PIN and debit card. Over the next 14 days, his account saw near-daily maximum withdrawals totalling RM529,774.79. The pattern departed sharply from decades of normal use. The Johor Bahru High Court held CIMB 60% liable and the customer 40%, awarding the estate RM317,864.87. The court found the bank had the detection capability to catch the pattern and simply didn’t act.
A second case, Chan Yan Li v Malayan Banking Bhd, went further in the customer’s favour. The Kuala Lumpur Sessions Court found Maybank negligent for failing to detect RM166,000 in unauthorised transfers, some at unusual hours, without triggering an alert. It’s a different category from Ng Choon Luk, because those transactions were unauthorised outright rather than customer-approved and then abandoned. The theme is the same. A bank that ignores an obvious pattern doesn’t get to shrug at the outcome.
Neither ruling is the final word. Both are trial-level decisions, a High Court and a Sessions Court, not the Court of Appeal or Federal Court. Four earlier Malaysian cases between 2014 and 2025, documented by law firm IKC in its own review of the case law, went the other way. Those found banks not liable once a customer had authorised a transaction. Two wins for victims in one year is a real signal. It isn’t proof the law has settled.
How the UK draws the line differently
Malaysia isn’t the only country deciding where this line goes. The UK chose differently.
Since October 2024, UK regulators have required payment providers to reimburse victims of Authorised Push Payment fraud, the exact category SEFT excludes, up to £85,000. The cost is split 50:50 between the sending and receiving bank by default. It proves the gap in Malaysia’s rule is a policy choice, not an unavoidable feature of scam compensation. A regulator looked at the same “95% of cases” problem and decided to cover it anyway.
In early September 2026, Malaysia’s own Khazanah Research Institute made a version of that argument at home. It said banks, telcos, and digital platforms should share responsibility for the RM2.77 billion the institute says Malaysia lost to scams, rather than leaving individual victims to absorb it alone. It’s one research institute’s position, not policy yet. But it’s the same direction the UK already went.
Your fastest real path to a refund
One part of Malaysia’s rules is close to automatic, if you know to use it.
E-wallet providers must fully reimburse scam victims within seven working days. That only applies if the provider failed to implement Bank Negara’s required safeguards: app-based authentication in place of SMS OTPs, a cooling-off period for newly registered devices, a dedicated fraud hotline, and kill-switch account freezing. It isn’t a blanket guarantee. If the provider had those safeguards in place and you were still deceived, compensation is split according to each side’s share of the fault, decided case by case.
Even the Federation of Malaysian Consumers Associations isn’t satisfied that’s clear enough. “There should be a clear and standardised framework defining what constitutes negligence,” says Fomca secretary-general Saravanan Thambirajah, who has also called for mandatory timelines on complaint handling and written reasons whenever a claim is rejected.
If a bank or e-wallet provider turns you down and you disagree, you’re not stuck with their decision. You can escalate to the Financial Markets Ombudsman Service (FMOS) for an independent review. FMOS is the body that absorbed the old Ombudsman for Financial Services in a 2025 merger.
What to actually do if it happens to you
None of this is legal advice. If you’re mid-dispute with a bank or e-wallet provider, a consumer lawyer or FMOS can assess your specific facts. But the pattern above points to four concrete moves:
- Report it immediately, to your bank’s fraud line and to the National Scam Response Centre (NSRC). The NSRC is the joint hotline run by the National Anti-Financial Crime Centre (NFCC), PDRM, and Bank Negara. The 14-day gap that sank CIMB’s defence in court existed because nobody flagged the pattern sooner.
- Write down every red flag the bank or platform ignored: unusual amounts, unusual hours, a device you’d never used before. That’s the kind of evidence that turned Ng Choon Luk’s case.
- If an e-wallet provider rejects your claim, ask in writing which specific safeguard they say was in place. A vague answer is exactly what FMOS exists to test.
- Don’t assume SEFT covers you just because you were scammed. Don’t assume you have no case just because you approved the transfer yourself. Those are two different questions. This article just answered both.
The rule protects fewer people than its name implies. That doesn’t mean you’re out of options. It means you need to know which door to knock on.