Visa has launched a third edition of its Malaysia security roadmap, extending its scope through 2028 to address a shift toward AI-enabled scams. The plan follows record scam losses in Malaysia and sets six industry-wide priorities spanning authentication, tokenisation and real-time fraud detection.
Key Facts At A Glance
- This is the third edition of Visa’s Malaysia security roadmap, following its 2019 debut and a 2023 update
- The roadmap targets AI-driven fraud through 2028
- Malaysians lost RM2.97 billion to scams in 2025, the highest figure recorded in three years
- Information and communications technology combined with e-commerce contributed 23.4% of Malaysia’s national economy in 2024, valued at RM451.3 billion
- The roadmap sets six priorities, including stronger cybersecurity readiness, authentication beyond SMS one-time passwords, and wider tokenisation adoption
- Visa has developed AI-based fraud tools since 1993 and now runs more than 150 AI and machine-learning models across its network
- Visa has invested more than US$12 billion in technology over the past five years to reduce fraud and strengthen network security
- Visa’s Scam Disruption programme reports intercepting more than US$1 billion in attempted fraud in a single year and has worked with law enforcement to shut down over 25,000 scam merchants worldwide
Roadmap Responds To Record Scam Losses
Malaysia’s scam losses reached RM2.97 billion in 2025, the highest level in three years, according to figures cited alongside the roadmap’s launch. Jason Phua, Head of Clients at Visa Malaysia, said the roadmap sets a common direction for the industry to strengthen the resilience of Malaysia’s payments ecosystem while continuing to enable secure digital commerce. The update lands against the backdrop of a payments industry increasingly intertwined with the broader digital economy, with ICT and e-commerce together accounting for close to a quarter of national economic output in 2024.
Six Priorities Spanning Authentication To Ecosystem Resilience
The roadmap’s six priorities center on moving authentication beyond SMS one-time passwords toward biometrics and in-app methods such as payment passkeys, alongside stronger cybersecurity readiness and closer oversight of third-party risks. It also backs wider use of tokenisation to replace sensitive card numbers, reducing the value of stolen data to criminals, and supports streamlined checkout methods such as Click to Pay. Additional priorities call for tighter baseline standards across fraud reporting, merchant onboarding and third-party compliance, alongside broader efforts to build ecosystem resilience through real-time risk detection and cross-sector cooperation.
The roadmap assigns distinct responsibilities across the payments ecosystem: issuers are tasked with strengthening real-time risk decisions, acquirers and merchants with tightening onboarding and checkout security, and third-party providers with reinforcing data protection and compliance. Regulators are called on to support intelligence sharing and common standards, while consumers are encouraged to use secure authentication, enable transaction alerts and remain alert to scam tactics.
Visa’s Existing Fraud Prevention Infrastructure
The roadmap builds on infrastructure Visa says it has developed since 1993, including more than 150 AI and machine-learning models covering transaction risk assessment, online authentication and token-provisioning fraud detection. These systems are supported by behavioural analytics from Featurespace, a fraud detection technology Visa has integrated into its network, which tracks over 400 signals to flag unusual activity within milliseconds.
Publicly available reporting on the roadmap’s launch did not specify implementation timelines for individual priorities within the 2026-to-2028 window, nor did it detail how compliance or progress against the six priorities will be measured across the industry.

