All news
News·via The Star·3 min read

BNM: E-Wallets Must Refund Scam Victims in 7 Days if Safeguards Fail

PM Anwar confirms e-wallet issuers must fully compensate scam victims within 7 working days if they fail BNM fraud-prevention rules, even when users are partly at fault. RM1.2B blocked in 2025.

·By The pitchdeck.my newsroom·Original source ↗
The Star — E-Wallets Must Refund Scam Victims in 7 Days if Safeguards Fail

E-wallet operators in Malaysia now have a hard deadline to refund scam victims — or eat the loss themselves. Prime Minister Datuk Seri Anwar Ibrahim, who also holds the finance minister portfolio, told the Dewan Rakyat on 1 July 2026 that eligible e-money issuers must fully compensate victims of unauthorised transactions within seven working days of receiving a complaint, provided the issuer failed to meet Bank Negara Malaysia's (BNM) mandatory fraud-prevention safeguards (The Star). The rule applies even when the user is partly at fault, shifting the burden of proof from consumer to provider. The announcement, made in a written parliamentary reply to a question from Roy Angau Gingkoi (GPS-Lubok Antu), formalises a framework Anwar says has already produced measurable results.

The deal

The compensation trigger is straightforward: an eligible e-money issuer that fails to implement BNM's prescribed fraud controls must refund a defrauded user in full within seven working days, regardless of whether the user was also negligent. BNM's required safeguards include stronger transaction authentication, a cooling-off period before high-risk transfers are approved, binding user accounts to a single registered device, dedicated fraud hotlines, and a "kill switch" that lets users freeze a compromised account in seconds.

The framework covers the country's main e-wallet operators — Touch 'n Go eWallet, Boost, GrabPay, ShopeePay, MAE, BigPay and Setel — which together serve more than 24 million verified Malaysian users. Victims who disagree with a provider's liability decision can escalate to the Financial Market Ombudsman Service for an independent review. Anwar disclosed the underlying numbers in the same reply: the National Scam Response Centre's tracing and freeze work, supported by the National Fraud Portal, prevented RM1.2 billion in fraudulent transactions in 2025 alone, and the share of victims receiving full or partial compensation rose 26 per cent after the policy took effect.

Why this matters

For investors, the rule is a clean liability shift. Until now, e-wallet operators could argue that consumer negligence caused the loss and walk away. The seven-day clock flips that: if a provider's controls fall short of BNM's bar, the operator eats the loss. That changes the operating risk profile of every major e-money issuer in Malaysia and tightens the link between regulatory compliance and unit economics — including for the listed bank parents that hold equity in some of the e-wallet platforms and have previously disclosed fraud liability as a soft contingent risk rather than a hard balance-sheet line.

The wider enforcement context is also hardening. Between 2024 and 2025, the Securities Commission Malaysia (SC), working with the Malaysian Communications and Multimedia Commission (MCMC), blocked or suspended 328 websites, 388 Telegram accounts and 60 phone numbers tied to scam operations. In April 2026, the two agencies formalised that cooperation with a memorandum of understanding that explicitly named artificial intelligence as a detection tool, alongside the SC's new Digital Forensic Lab. The e-wallet rule is the consumer-facing edge of the same push: faster liability, faster freezing, fewer avenues for scammers to monetise a stolen account before the operator can lock it.

There is also a read-across to banks. Conventional banks have been operating under BNM's "Fair Treatment of Financial Consumers" framework for unauthorised e-banking transactions since 2024, with a similar shared-fault compensation doctrine. The e-wallet update now aligns non-bank e-money issuers with comparable redress timelines. For payment-service providers, the practical implication is that fraud-prevention spend is no longer a discretionary line item — it is now a balance-sheet protection cost, sitting alongside customer onboarding, compliance, and AML.

What's next

Watch BNM for the technical implementation circular that will spell out which safeguards count as "non-compliance" and how operators must evidence compliance in their fraud-incident reports. Operators will also need to publish response-time service-level agreements that BNM can benchmark against the seven-day rule. The first enforcement cases under the new framework are likely to come from the e-wallet sector before any formal extension to other payment-service licensees, and any order that holds an e-wallet to the seven-day clock will be the precedent investors track most closely.

Source: The Star

Editorial by The pitchdeck.my team

From the pitchdesk

Need to build or automate your company? Custom development team as low as the price of an admin — enquire now.

pitchdeck.my's AI Your Business arm is a 15-year software house. We study your business, spec the fix, and let AI build it. Priced like a hire, not a project. ROI as fast as 30 days.

More news