Why Malaysians Still Fall Victim to Scams

Bolttech: Insurtech Provider and Cyber Scam Awareness Report
Bolttech is a Singapore-based digital insurance technology (insurtech) company that enables partners to embed insurance products into their platforms. It operates in multiple markets, including Malaysia. The company’s “Cyber Scams in Malaysia” report, cited by Lowyat.net, investigates the paradox of high scam awareness yet continued victimisation among Malaysian consumers. The report aims to identify behavioural and demographic factors that undermine preventive action, informing strategies for insurers, policymakers, and cybersecurity advocates.
According to the Bolttech report as summarised by Lowyat.net, Malaysians exhibit a high level of anticipated scam exposure—over 80% of respondents said they expected to encounter a scam in the next 12 months—yet a comparable proportion still fell victim to at least one scam during the survey period.
Key Facts
| Attribute | Value |
|---|---|
| Survey scope | Malaysian adults (n=1,000), nationally representative |
| Date of data collection | Q4 2025 (fielded by Bolttech, published February 2026) |
| Percentage who expected a scam in next 12 months | 83% |
| Percentage who fell victim to a scam in past 12 months | 67% |
| Most common scam type | Phishing via SMS and messaging apps (62% of incidents) |
| Average financial loss per victim | MYR 3,200 (approximately USD 680) |
| Primary reason for falling for scam | Trust in official-looking branding and urgent tone (mentioned by 71% of victims) |
| Demographic most likely to fall victim | Adults aged 25–34 (73% victim rate vs. 63% national average) |
Why Do Malaysians Fall Victim Despite High Scam Awareness?
The Bolttech report identifies a gap between awareness and behaviour: while 83% of Malaysians expect to encounter a scam, 67% still become victims. The primary driver is cognitive overload under urgent, emotionally charged messages, which overrides precautionary intentions.
Among victims, 71% stated that the scam’s use of official-looking branding—such as fake bank logos or government agency headers—convinced them of legitimacy. The report also notes that 58% of victims admitted they “knew something was off” but proceeded anyway because the message demanded immediate action (e.g., “your account will be closed in 24 hours”). Lowyat.net quotes a Bolttech spokesperson:
“Malaysians are not ignorant—they are overwhelmed. The very tactics that trigger a stress response also disable the rational checks they would normally apply. Awareness alone is insufficient. The industry must design friction into the process, such as mandatory two-step verification before any payment link is clicked.” — Bolttech report, as cited by Lowyat.net (2026)
In the same age cohort (25–34), the victim rate was 73%, ten percentage points higher than the national average, suggesting that digital-savvy groups are not immune to well-crafted social engineering.
How Does the Bolttech Report Define a “Cyber Scam”?
A cyber scam is defined in the report as any digital communication (email, SMS, social media, messaging app) that uses deception to extract money, personal data, or login credentials from the recipient. The report excludes phone calls (voice phishing) unless they originated from a digital message.
The report categorises scams into three tiers: phishing (fake logins), advance-fee fraud (promises of reward), and impersonation (fake authority figures). Phishing via SMS—often called “smishing”—accounted for 62% of all incidents. The report further breaks down the financial impact: losses ranged from MYR 50 (token fraud) to MYR 28,000 (investment scams), with a median loss of MYR 400.
Only 12% of victims reported the scam to authorities, while 44% said they felt too embarrassed to tell anyone, a barrier that Bolttech recommends addressing through anonymised reporting channels.
Who Is This Report For?
The report is primarily aimed at Malaysian insurance providers, banks, telecommunications companies, and government cyber-crime units. It provides demographic and behavioural data that can inform targeted public education campaigns, product design (e.g., scam cover insurance), and real-time alert systems.
For individual consumers, the key takeaway is that trust in branding and urgency overrides caution. The report recommends enabling multi-factor authentication on all financial accounts, using a password manager to avoid credential reuse, and installing a scam-call/message blocker app from the official app store. Organisations are advised to run simulation phishing tests quarterly and to integrate “cooling-off” warnings into payment flows.
Common Questions
What is the most effective single step to avoid falling for a phishing SMS?
Enable a two-second delay before any link opens—manually type the official website URL instead of clicking embedded links. The Bolttech report found that 79% of victims who clicked a link later recognised suspiciously poor grammar, but the damage was already done.
Does being younger or more tech-savvy reduce scam risk?
No. The 25–34 age group had the highest victim rate (73%), likely because they interact with more digital services and are more accustomed to fast-paced online interactions, making them less suspicious of urgent messages.
How much money do Malaysians typically lose to cyber scams?
The average loss per victim is MYR 3,200 (approximately USD 680), but losses vary widely. The median loss is MYR 400, indicating that most scams involve smaller amounts that victims often dismiss without reporting.
Sources and Methodology
This article is based on the Lowyat.net article titled “Why Malaysians Still Fall Victim to Scams” (posted February 2026), which itself cites Bolttech’s “Cyber Scams in Malaysia” report. The Lowyat article paraphrases survey data and includes a direct quote from a Bolttech spokesperson. All numerical facts are derived from that secondary source; the original Bolttech report was not accessed independently. Currency conversions from Malaysian Ringgit to US Dollars use the approximate exchange rate of 1 USD = 4.70 MYR (February 2026).
This article was last updated on 27 February 2026.