For years, financial institutions treated fraud mainly as a technical security problem. Banks strengthened firewalls, introduced encryption, expanded biometric authentication and invested heavily in systems designed to detect account takeovers and suspicious transactions.
Those controls remain essential, but fraudsters are increasingly choosing a different route. Rather than breaking through the bank's infrastructure, they are convincing legitimate customers to unlock the door themselves.
Generative AI has accelerated that shift. Deepfake video, cloned voices, personalised scam messages and automated social engineering allow criminals to create believable situations at a speed and scale that would once have required a well-funded operation. The payment may appear properly authenticated, but the person approving it could be acting under carefully engineered deception.
JadePuffer Shows How Quickly Agentic Attacks Are Evolving
One of the clearest warnings came from a campaign that Sysdig calls JadePuffer. The company assessed it as the first documented agentic ransomware operation in which a large language model drove a complete extortion workflow across compromised systems.
The operation began by exploiting an internet-facing Langflow deployment through CVE-2025-3248. It then moved from the initial system towards a separate production database environment, conducting reconnaissance, handling credentials and carrying out destructive database-extortion activity. Sysdig said the generated payloads included unusually detailed natural-language reasoning and target prioritisation, making the activity look more like an AI narrating its own decisions than a conventional attacker writing quick operational scripts.
The most striking behaviour was its ability to adjust when something failed. In one observed sequence, the agent moved from an unsuccessful login attempt to a corrected approach in 31 seconds. Instead of waiting for a human operator to inspect the error and modify the command, the system interpreted the result, changed its parameters and tried again.
There is still debate over how completely autonomous the operation was. Independent reporting noted that human involvement remained somewhere in the wider chain, including obtaining access or credentials that were not clearly harvested by the AI itself. It is therefore safer to describe JadePuffer as a major step towards autonomous cyber operations rather than a completely independent digital criminal with no human assistance.
The broader lesson remains serious: attackers no longer need to automate only repetitive tasks. AI agents can begin interpreting results, selecting the next action and correcting mistakes while an intrusion is already underway.
Fraud Is Moving Towards the Human Layer
JadePuffer represents the highly technical end of AI-enabled crime, but the more immediate concern for ordinary Malaysians is fraud aimed directly at customers.
At the LexisNexis Risk Ready 2026 event in Kuala Lumpur, banking and fraud specialists discussed how attacks are moving away from directly compromising financial institutions and towards manipulating the people who use them. Panel coverage cited a global figure suggesting that about 97% of organisations had experienced some form of AI-assisted fraud-related security incident.
The discussion brought together representatives from AEON Bank, Boost Bank, Bank Simpanan Nasional and LexisNexis Risk Solutions. Their shared concern was that modern fraud is increasingly built around believable impersonation and psychological pressure rather than purely technical account compromise.
This changes the balance of responsibility. A bank may correctly authenticate the customer's device, password, fingerprint and transaction code, yet still process a fraudulent payment because the genuine customer has been manipulated into approving it.
Deepfake Fraud Is No Longer Reserved for Wealthy Targets
Deepfake attacks were once associated with major corporate fraud because producing convincing synthetic voices and video required considerable time, skill and computing resources.
That barrier has collapsed.
The panel highlighted the well-known Hong Kong case in which an employee transferred approximately US$25 million after joining a video call populated by digitally fabricated versions of colleagues. That operation was worth the effort because the potential return was enormous. Today, similar impersonation capabilities are becoming affordable enough to target ordinary consumers, smaller businesses and families.
A scammer can use publicly available photographs, social-media videos and voice recordings to imitate someone the victim trusts. The result does not need to survive forensic examination. It only needs to appear convincing during a rushed phone call or short video conversation.
This is why elderly parents, university students and ordinary employees may now face techniques once used primarily against senior executives and finance departments. The criminal no longer needs one victim capable of transferring millions. AI makes it practical to approach thousands of people and accept smaller returns from each successful deception.
Even Death May No Longer Prevent Impersonation
The emotional impact becomes even more disturbing when old recordings of deceased family members can be used to produce synthetic speech or video.
A criminal could imitate a relative asking for emergency assistance, a senior employee issuing urgent instructions or a bank representative warning that an account is under attack. The voice may sound familiar, the face may look convincing and the message may contain personal information collected from social media or previous data breaches.
Traditional advice such as "listen carefully to the caller's voice" becomes much less reliable when AI can reproduce tone, accent and speaking patterns.
Families and organisations may increasingly need agreed verification methods that do not depend solely on appearance or voice. A separate call to a known number or a private fact established in advance may be more valuable than trying to judge whether a digital voice sounds authentic.
The Most Dangerous Payment May Be Fully Authorised
Many banking controls are designed to stop unauthorised activity. They look for unfamiliar devices, incorrect credentials, impossible travel, unusual login locations or suspicious transaction patterns.
Authorised push-payment fraud is different.
The customer logs in successfully and willingly approves the transfer. From the bank's technical perspective, the payment may appear legitimate. The fraudulent element is the story that convinced the customer to send it.
Dr Mohanamerry Vedamanikam of Boost Bank discussed research involving Malaysian university students who were shown ten job offers containing embedded scam indicators. According to the panel coverage, 97% selected fraudulent opportunities even though 45% claimed they already understood fraud and money laundering before the exercise.
The finding illustrates the gap between knowing that scams exist and recognising one while emotionally involved in it. A person may understand fraud in theory but still respond differently when offered an attractive salary, threatened with legal consequences or told that a loved one needs urgent assistance.
Education Can Change Behaviour
The same research also offered a more encouraging result.
Participants were divided into groups, and one group received detailed education explaining not only common warning signs but also where those signs could lead. When tested again, approximately 98% of that educated group correctly rejected the fraudulent opportunities.
This suggests that awareness campaigns can work, but only when they go beyond generic warnings.
Telling people to "beware of scams" is unlikely to change behaviour. Effective education needs to show realistic scenarios, explain how manipulation unfolds and allow participants to practise making decisions under controlled pressure.
People should understand why a scammer creates urgency, why a job offer may involve receiving and forwarding money, and why a caller claiming to be from a bank may insist that the customer must move funds immediately.
Training becomes more useful when people recognise the sequence of manipulation rather than memorising a short list of suspicious phrases.
Too Many Warnings Can Become Background Noise
Banks have responded to rising scam losses by adding confirmation screens, warning messages and additional steps before certain transactions.
Those interventions are useful, but they can lose their effect when customers see them constantly. A person who has clicked through the same warning dozens of times during legitimate payments may approve it automatically during a real scam.
The United Kingdom offers an important example of how regulation can shift responsibility. Its authorised push-payment reimbursement framework requires eligible victims to be reimbursed in many circumstances, with the cost generally divided equally between the sending and receiving payment firms. The intention is to motivate institutions on both sides of the transfer to prevent fraud instead of leaving the sending bank or victim to absorb the entire loss.
That creates a strong incentive for banks to intervene, but more customer prompts are not enough on their own.
The better approach is to use data behind the scenes to determine when friction is genuinely needed. A routine payment to a long-established recipient should not necessarily receive the same treatment as a first-time transfer to an account linked to suspicious activity.
Fraud Intelligence Must Follow the Entire Network
A single transaction can appear normal when examined alone.
The destination account becomes more suspicious when the bank can see that it recently received money from several unrelated customers, rapidly transferred those funds elsewhere or forms part of a wider mule-account network.
This is why cross-industry intelligence sharing matters. One institution may see only the victim's outgoing payment, while another sees the receiving account collecting funds from multiple scams.
LexisNexis argues that effective fraud prevention combines digital identity, behavioural information, transaction history and collaborative intelligence rather than relying on one authentication event. Its fraud-management guidance recommends layered controls that apply different levels of friction according to the risk of each interaction.
The goal should not be to challenge every customer constantly. It should be to identify the small number of transactions where intervention may prevent serious harm.
Banks Must Use AI Against AI
Criminals can use AI without worrying about regulation, explainability, fairness or customer experience. Banks do not have that freedom.
Financial institutions must ensure that their models do not unfairly block legitimate customers or produce decisions that cannot be justified. They must also comply with privacy, security and governance requirements while attackers continuously modify their methods.
Even so, human-only fraud analysis cannot keep pace with machine-generated attacks operating across millions of transactions.
Defensive AI can identify patterns that are difficult to see manually: groups of accounts sharing devices, unusual behaviour preceding a transfer, synthetic identity signals, repeated recipient details and networks of mule accounts.
LexisNexis promotes the use of AI-based identity and fraud analysis to distinguish legitimate customers from suspicious activity in real time. It also emphasises combining machine intelligence with broader behavioural and identity context rather than treating a successful login as proof that every subsequent action is trustworthy.
The contest is not simply AI against AI. It is criminals using AI without constraints against banks using AI within highly regulated environments.
Banking AI Must Be Auditable, Trackable and Explainable
At the Kuala Lumpur panel, AEON Bank's Irfan Amer argued that trusted AI inside financial institutions must meet three fundamental conditions: its decisions must be auditable, its actions must be trackable and its reasoning must be explainable.
Auditable means the institution must know where AI is being used and whether that use meets an approved standard.
Trackable means there must be a record showing what information entered the system, what changed and what action followed.
Explainable means the bank cannot simply tell a customer or regulator that "the algorithm decided." It needs to provide a meaningful reason for blocking a payment, rejecting an identity or escalating an account.
These requirements may slow deployment, but they are essential when AI decisions affect someone's savings or access to financial services.
Customer Protection Cannot Depend Entirely on Automation
The strongest example from the panel came from Bank Simpanan Nasional.
Lolitta Suffian described a case in which a fraud specialist spent approximately three hours speaking with a customer and explaining how a Macau scam worked. The time was necessary because the customer had already accepted the criminal's version of events and needed patient, human guidance before recognising the manipulation.
An automated system may identify a suspicious transaction within milliseconds. It may temporarily block the payment and display a warning. What it may not do effectively is stay with a frightened or confused person for several hours while rebuilding their understanding of what has happened.
That distinction matters.
Fraud prevention is not always a classification problem with a simple safe-or-dangerous answer. Sometimes it requires empathy, cultural understanding and the ability to recognise that a victim's confidence has been deliberately undermined.
Human intervention should therefore be reserved for moments where it adds the greatest value. AI can examine the transaction stream and identify the danger, while a trained employee handles the difficult conversation.
Customers Need a Safe Way to Pause
Scams often succeed because criminals create urgency.
Victims are told that their account will be frozen, they will be arrested, an investment opportunity will disappear or a family member is in immediate danger. Every minute spent verifying the story is presented as a threat.
Banks can weaken that technique by making it normal and easy for customers to pause a payment.
A high-risk transaction could be placed into a temporary review period instead of being completed instantly. The bank could provide a direct fraud-support channel and encourage the customer to verify the request using independently obtained contact information.
The purpose is not to make all digital payments slow. It is to interrupt the small number of transactions where urgency, unusual behaviour and an unfamiliar recipient appear together.
Customers Should Never Be Treated as the Weakest Link
Security discussions sometimes describe people as the weakest link, but that wording can become unfair.
Victims are not failing because they are unintelligent. They are facing criminals who study behaviour, collect personal information and deliberately exploit trust, fear and authority.
AI makes those attacks more personalised. A generic phishing email may be easy to dismiss, while a voice message that sounds like a family member and mentions a real workplace or recent event can be far more persuasive.
Banks should therefore design security around realistic human behaviour rather than expecting every customer to remain perfectly rational while frightened or pressured.
Warnings should be understandable, interventions should occur at the right moment and customers should have immediate access to a real person when something feels wrong.
The Post-Quantum Concern Adds Another Layer
The panel also raised the longer-term danger of criminals collecting encrypted information now in the hope that future computing capabilities will allow them to decode it later.
This "harvest now, decrypt later" strategy is one reason governments and financial institutions are preparing for post-quantum cryptography. Sensitive information stolen today may retain value for many years, even when attackers cannot immediately read it.
The threat extends beyond encrypted documents. Biometric information is particularly sensitive because a person can change a password but cannot easily replace their face, voice or fingerprints.
Banks adopting facial or voice verification must therefore protect the underlying biometric material as carefully as financial credentials. AI-generated impersonation makes this even more important because stolen samples can potentially be used to train more convincing synthetic identities.
Final Thoughts
AI-assisted fraud is changing the target more than the objective.
Criminals still want money, credentials and access, but they increasingly pursue those goals by manipulating legitimate customers rather than directly defeating the bank's strongest technical controls.
JadePuffer demonstrates where highly autonomous cyberattacks may be heading: AI agents capable of interpreting results, correcting failed steps and moving through an environment at machine speed. At the consumer level, deepfakes and personalised social engineering bring similar automation to impersonation and payment fraud.
Banks cannot answer this development by placing another warning screen in front of every transaction. Customers eventually learn to dismiss repetitive prompts, while sophisticated scams are designed to make clicking "continue" feel like the safest choice.
The more effective response combines real-time behavioural analysis, shared fraud intelligence, carefully targeted transaction friction and human intervention when a customer has been psychologically manipulated.
AI will become an increasingly important defensive tool, but it must remain auditable, trackable and explainable. Human judgement still matters, particularly when preventing a scam requires patience and empathy rather than faster computation.
The fight against AI-assisted fraud will not be won by choosing between people and machines. It will depend on giving each the work it does best: allowing AI to detect patterns at scale while ensuring humans remain available to understand, protect and reassure the customer behind the transaction.


Comments 0