AI-powered deception


This visual is human-created, AI-aided.
This visual is human-created, AI-aided.

Urgent need to equip youth with skills to recognise sophisticated scams, experts say

Despite growing up with technology, youth are especially vulnerable to scams due to their high level of trust in digital platforms, frequent online transactions and financial pressures such as participating in the gig economy or managing their student loans.

CyberSecurity Malaysia (CSM) acting chief executive officer Roshdi Ahmad said young adults and students are at higher risk of being scammed because much of their daily lives – from studying and job hunting to banking, shopping and socialising – now takes place online.

“Scammers are increasingly exploiting these digital habits through fake part-time job offers, phishing campaigns, fake investment platforms, malicious mobile applications, romance scams and money mule recruitment.

Roshdi
Roshdi

“Law enforcement agencies have also warned that students are being targeted by syndicates offering ‘easy money’ in exchange for allowing their bank accounts to be used for illegal transactions,” he said, stressing the need for cyber safety education to evolve alongside emerging threats and be tailored to different age groups.

For children aged seven to 12, cyber safety education should focus on basic cyber hygiene, including keeping passwords private and recognising gaming-related scams through storytelling and interactive learning, he said.

ALSO READ: Hands-on training key to cyber defence

Teenagers, meanwhile, should learn about managing their digital footprints, protecting their privacy and identifying online grooming attempts or fake online stores.

“For young adults aged 18 to 30, the emphasis should shift towards financial threats, including task and job scams, malicious application packages (APK files), fraudulent cryptocurrency investments and the legal consequences of acting as a money mule or ‘akaun keldai’,” Roshdi told StarEdu.

Malaysia’s scam landscape has evolved from generic phishing emails and text messages to highly organised, personalised and technology-enabled operations, with artificial intelligence (AI) making such scams far more sophisticated, he warned.

ALSO READ: ‘Learning when not to trust’

“In the age of AI, seeing or hearing is no longer sufficient proof that the online content is genuine.

“Criminals can now generate realistic fake videos, clone voices and create highly personalised messages impersonating family members, government agencies, employers, financial institutions or well-known public figures (see infographic),” he cautioned.

In June, it was reported that Malaysians lost RM2.97bil to scams last year, with losses continuing to increase this year as syndicates adopt increasingly sophisticated methods to deceive victims.

Last year, the Bukit Aman Commercial Crime Investigation Department said young adults, aged between 21 and 30, recorded the highest number of victims of telecommunications fraud in 2025, involving 8,789 individuals.

According to CSM’s Cyber999 data, fraud accounted for 75% of all incidents reported in the third quarter of 2025, with phishing making up 75% of those fraud cases.

New competencies

Young Malaysians, said Prof Dr Nor Badrul Anuar Juma’at from the Universiti Malaya Faculty of Computer Science and Information Technology, need to develop new digital competencies that go far beyond basic cyber awareness.

Students today must build three core competencies – verification literacy, AI literacy and privacy awareness, he said.

“Verification literacy means checking the source, date, account, URL, sender identity and whether the same information appears on official channels,” he said, adding that AI literacy is important for discerning the authenticity of voices, images and messages.

Prof Nor Badrul Anuar
Prof Nor Badrul Anuar

Privacy awareness, Prof Nor Badrul said, is another essential skill, as scammers increasingly exploit personal information that users have already shared online.

“Public photos, phone numbers, locations, school details, voice notes and social media posts can all be used by criminals to create personalised and convincing scams.

“Students must avoid oversharing, review their privacy settings regularly and understand that their digital footprints can later be weaponised against them,” he said.

Digital miconceptions

According to Prof Nor Badrul Anuar, the misconception that being tech-savvy is enough to prevent one from becoming a victim is among the reasons why more young people are letting their guard down.

“Being a digital native or technologically fluent does not mean being ‘digitally immune’.

“Knowing how to use digital platforms does not protect users from psychological manipulation, as scammers often exploit emotions such as fear, greed, urgency and the fear of missing out,” he said, adding that students must understand the psychology behind cyber fraud and recognise the tactics used.

Many underestimate AI-related threats because they still view AI primarily as a chatbot that answers questions, he observed.

“In reality, AI tools can now assist or act like agents that search, analyse, generate content, adapt messages and even run scam conversations with much less human effort.

“A convincing message that pressures immediate action should always be verified through a separate trusted channel,” he said, adding that AI has significantly changed the scale of online scams.

While phishing messages were once easier to identify because they were generic, AI can now produce polished messages in multiple languages, analyse information from public profiles, imitate a person’s writing style and generate text, voice or video to impersonate individuals, he said.

“The biggest change is not just fake content, but automated fake trust.

“Scammers can quickly test different messages, personalise them for different victims and adjust their approach when one method fails. Unfortunately, public awareness often moves slower than these tactics,” he said.

Another common misconception, said Roshdi, is the belief that callers are legitimate officials from the police force, the Inland Revenue Board or Pos Malaysia simply because they knew a person’s identification card number or full name.

“Data leaks mean personal information is readily available on the dark web. Knowledge of your basic details is never proof of identity,” he said.

Future workforce

Prof Nor Badrul Anuar said the growing sophistication of AI-enabled attacks also means future cybersecurity professionals must possess broader skill sets than before.

“Graduates will still need a strong foundation in network security, secure coding, digital forensics, incident response and cloud security.

“However, they must also develop AI security literacy, including understanding how attackers use AI agents to gather information about potential targets, conduct phishing attacks, impersonate individuals, assist with malicious code and automate social engineering,” he said.

He added that cybersecurity professionals must understand the broader digital ecosystem, including devices, applications, networks, cloud services, data flows, user behaviour and business operations, as well as how these elements are interconnected.

“This knowledge helps them see how one weakness can move across the whole environment,” he said, adding that graduates should also be equipped with skills in deepfake awareness, identity verification, data privacy, AI governance and the safe use of AI tools to detect and respond to cyber threats.

Equally important, he said, is the ability to communicate cybersecurity concepts clearly to non-technical users.

“AI-enabled attacks do not only target networks. They target trust, identity and behaviour. Many scams succeed by placing people under pressure at a critical decision point,” he said.

Can you spot an AI scam?

Digital exposure has taught us to question what we see. Recognise common scam tactics and look for inconsistencies rather than accepting information at face value. That said, I don’t think anyone is completely immune, which is why staying informed as the technology evolves is just as important. The one rule I think everyone should follow is to always verify before you trust. If someone claims to be from your bank, a government agency, a company or even a friend or family member, confirm it through an official platform such as an official website or app.

Keerat Wathan, 22

I don’t think anyone, including myself, can say they are fully confident in spotting AI-generated scams anymore. The real danger is not simply that AI can imitate faces or voices. It is that it takes advantage of how our minds naturally process trust. The moment we recognise a familiar voice, a known face, or a message that creates urgency, our brains are more likely to react emotionally before we pause to question whether it is real. One rule everyone should follow is to verify before reacting. In a world where technology can imitate almost anything, critical thinking is no longer just a useful skill. It has become one of our strongest forms of protection.

Isabel Lim, 15

AI cloning technology is becoming increasingly capable of mimicking the way we communicate as more advanced models emerge. Install caller identification and spam-filtering apps to help identify suspicious numbers and save time verifying whether a call is legitimate. And keep yourself updated on the latest scam tactics through newspapers and your bank’s official website.

Aaron Lim, 21

CLICK TO ENLARGE
CLICK TO ENLARGE

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Education

Squashing stress with mental skills
Kulai lass to represent M’sia in China challenge
Winning beyond pageant glory
‘Learning when not to trust’
Digital detour
Grab-bing the chance to make a change
Hands-on training key to cyber defence
BBGS legacy lives on
Creative skills for TVET
Navigating a mapless world with purpose

Others Also Read