For years, spotting a scam email was almost comical. We all know the drill: an urgent request from a “prince” or a bank manager, riddled with glaring grammatical errors and bizarre phrasing. But if you’re still relying on broken English to flag a malicious message, you are already behind the curve.

During a recent exclusive media briefing in Kuala Lumpur, ESET’s Senior Research Fellow, Righard Zwienenberg, made it clear that Malaysia is entering a new era of AI-powered social engineering. The anatomy of modern scams has undergone a fundamental change, with AI now deeply embedded in the process. Today’s malicious messages no longer arrive with generic requests or broken English. Instead, criminal groups leverage AI to generate highly convincing communications. These messages feel precise and personalised, engineered to match corporate tones, utilise local slang, and hit emotional triggers designed to prompt swift action.
The tactics are evolving beyond text, too. Emerging local threats now include high-fidelity voice impersonation for operational and financial instructions. Attackers are also manipulating chatbot interactions, specifically targeting AI-powered service channels.
By the Numbers: What’s Actually Hitting Our Inboxes
To understand the daily-use implications of this shift, we have to look at the hard data. ESET’s telemetry from December 2024 to May 2025 paints a stark picture of the threats targeting Malaysia:
- Phishing attacks are the undisputed leader, accounting for roughly 37% of all detected threats in the country.
- When it comes to information-stealing malware (infostealers), a threat known as Formbook represents about 26% of all detected infostealers in Malaysia.
- Perhaps the most significant technical shift is the delivery mechanism: scripts and executable files now constitute over 75% of all email threats, easily surpassing the use of malicious Office documents.
What does this mean for the average user? It means the automated filters looking for dodgy Word documents aren’t enough anymore, as attackers rely on AI-assisted automation to scale these script-based campaigns globally.
Oversharing and FOMO: The Perfect Attack Surface
While the technology behind the attacks is getting smarter, our daily habits are making us easier targets. Malaysia boasts a massive digital footprint, with 99.5% of households owning a mobile phone and 96.8% having internet access.

However, our behavioural trends actively amplify this exposure. Despite expressing worries about privacy, Malaysians overshare more than ever, particularly on messaging apps and social platforms. When you combine this wealth of public digital footprints with the country’s strong FOMO driven culture, social engineering techniques absolutely thrive. These habits are the direct fuel for credential theft, ransomware cases, and severe financial losses.
Securing the Daily Grind
Ultimately, cybercriminals heavily rely on human error. The goal of these AI-driven attacks isn’t just to trick you into clicking a link; it’s to influence your judgment during a moment of trust or urgency.
For consumers, the best defence is a combination of the right tools and heightened awareness. Moving forward, it is critical to treat any emotionally charged or urgent digital requests with extreme caution. Even if a caller sounds exactly like someone you know, you must validate voice-based instructions.
The “broken English” safety net is gone. It’s time our daily digital vigilance gets an upgrade to match.
