Fraud in Southeast Asia has stopped resembling petty crime and started resembling an industry with shift schedules, performance quotas, and AI adoption that challenges legitimate call centres. Synthetic identities, deepfake video calls, and cloned voices are no longer experimental novelties. They are production line equipment for organised fraud. For organizations practicing cyber risk management across Indonesia, this shift matters directly, since Indonesian banks, businesses, and citizens are on the front lines of an expanding regional criminal economy.
Synthetic identity fraud once meant pairing a stolen number with a fabricated name. Generative AI has removed manual labour entirely. Criminal groups now produce a complete digital persona, including a photorealistic face, a cloned voice, and a fabricated document trail, within hours rather than weeks.
These personas pass facial recognition checks, open bank accounts, and secure loans, often without using any real victim data. This evolution has become one of the defining cyber threats in Indonesia and across the wider region that we face today, since the same automated tooling scales effortlessly across borders.
Scam operators rely on a working toolkit built almost entirely from commercially available software:
These AI-powered tools have significantly lowered the barrier to entry, enabling criminal organisations to train inexperienced recruits to operate sophisticated fraud software rather than relying solely on seasoned fraudsters.
A finance employee at a multinational firm’s office in Hong Kong once joined what looked like a routine video conference with the company’s chief financial officer and several colleagues. Every participant except the employee was an AI recreation built from public footage. Convinced by the realism, the employee authorised fifteen transfers totalling HK$200 million, roughly $25.6 million. Police called it the first known case involving a fabricated, multi-person video conference, and it remains the reference point for any conversation about deepfakes in Indonesian businesses or any market that should now be preparing against them.
Singapore has faced a wave of scams built around senior officials. In one case, a businessman wired roughly SGD4.9 million after attending a fabricated Zoom call featuring AI-generated versions of the prime minister, the president, and asset management executives. In a separate case, criminal groups combined a deepfake video of the prime minister with legitimate advertising platforms and counterfeit news websites to promote an unlicensed investment scheme.
The incident illustrates how synthetic media can be paired with trusted digital channels to create a false sense of credibility, making fraudulent campaigns more convincing and difficult to detect.
A related pattern, the digital arrest scam, involves fraudsters posing as police or government officials who tell victims, often over video call, that they face arrest unless they transfer money immediately. Investigations have traced a significant share of these operations to call centres in Myanmar, Laos, and Cambodia, confirming that the same infrastructure powering investment fraud also drives impersonation scams against ordinary citizens worldwide.
The industry’s roots trace back to casinos that lost customers during pandemic travel restrictions. Operators pivoted to organised fraud, exploiting weak governance, remote border regions, and trafficked labour. Researchers estimate that more than 80% of the world’s large scam compounds now sit inside Southeast Asia, concentrated across Cambodia, Myanmar, and Laos, and the region has become synonymous with industrial-scale fraud.
AI chatbots conduct outreach to thousands of targets at once, escalating promising leads to human operators only after initial engagement. Voice cloning and deepfake videos remove the need for native fluency or improvisation, allowing trafficked workers with zero fraud experience to execute scripted, AI-assisted deceptions once reserved for skilled criminals.
The scale of cyber-enabled fraud in East and Southeast Asia has reached alarming levels. In a single recent year, scams originating from the region were estimated to have caused between US$18 billion and US$37 billion in global losses. Criminal networks operating across Cambodia, Myanmar, and Laos are believed to generate approximately US$43.8 billion annually — equivalent to nearly 40% of the three countries’ combined formal GDP. Separately, the U.S Department of the Treasury estimated that Americans lost at least US$10 billion to scams linked to Southeast Asia in the same period.
What Defenders Need to Do Right Now
Organisations must strengthen identity verification beyond conventional authentication methods by implementing liveness detection, voice biometrics capable of identifying synthetic or cloned audio, and mandatory out-of-band verification for high-value transactions. As AI-enabled fraud becomes more sophisticated, the cyber risk management strategies adopted by Indonesian institutions today will play a critical role in determining their resilience against the next generation of cyber threats, both nationally and across the wider region.
Regulators need cross-border data-sharing agreements, mandatory incident-reporting timelines, and coordinated pressure on the banking and crypto infrastructure that launders proceeds from these operations.
Addressing a threat of this scale requires coordinated action that extends beyond individual organisational efforts. The IndoSec summit brings together regulators, financial institutions, cybersecurity leaders, technology experts, and policymakers to examine the evolving fraud landscape facing Indonesian organisations.
Scheduled to take place on 15–16 September 2026 at The Ritz-Carlton Jakarta, Pacific Place, the summit provides a platform for security leaders to exchange threat intelligence, evaluate emerging technologies, share proven defence strategies, and strengthen collaboration against AI-enabled cyber threats.
Register today!
What is synthetic identity fraud?
It combines real and fabricated data, often AI-generated, to create a convincing fake identity for financial fraud.
How do deepfake scams typically work?
Criminals clone a target’s face or voice from public footage to impersonate them during live calls.
Why is Southeast Asia central to this fraud economy?
Weak governance, trafficked labour, and former casino infrastructure created ideal conditions for scam compounds.
What is a digital arrest scam?
Fraudsters impersonate officials, falsely claiming the victim faces arrest unless they transfer money immediately.
Can businesses detect deepfake video calls?
Yes, through liveness detection, voice biometrics, and mandatory secondary verification for sensitive requests.