No, E-Wallets Don't Have to Refund Every Scam. Read the Rule Before You Relax.
The headline said scam victims get repaid in seven days. The actual rule has a condition attached, and if you misread it, you drop your guard at the worst possible moment.
In early July the news ran under headlines like “Consumers get greater protection from scams” (The Star, 2 July 2026), reporting a written reply the Prime Minister gave to Parliament the day before. The takeaway most people carried away: e-wallet providers must fully repay scam victims within seven working days. A lot of readers turned that into “if I get scammed on Touch ‘n Go or GrabPay, I get my money back.” That reading is wrong, and believing it is exactly how you talk yourself into being careless.
What the rule actually says
The seven-day full repayment is conditional, and the condition is sitting right in the first sentence of the report. The Prime Minister’s words, as quoted: providers must fully compensate victims within seven working days “if they fail to implement Bank Negara’s preventive measures.”
That last clause is the whole ballgame. The full payout is triggered when the e-wallet provider failed to put Bank Negara’s required safeguards in place. If the provider did everything it was told to do and you still got scammed into sending the money yourself, the seven-day rule is not a guarantee you walk away whole.
| What people think it says | What it actually says |
|---|---|
| ”If I lose money to a scam, my e-wallet refunds me in 7 days.” | The provider must fully compensate you in 7 working days only if it failed to implement BNM’s mandated safeguards. |
| ”It’s automatic, no matter what I did.” | The rule can apply even where your own negligence played a part, but only against a provider that dropped its safeguards. |
| ”The provider always pays 100%.” | Where both sides share fault, compensation is split by each party’s level of negligence. |
That first row is the whole point. The rule is a stick aimed at negligent providers, not a safety net stretched under every careless tap. It exists to force e-wallets to build proper fraud defences, and the compensation is what happens when they don’t.
The provider is on the hook: full compensation within 7 working days, even if you were partly careless.
Shared responsibility. Compensation is split by each side’s level of negligence, and can come to little or nothing.
Disagree with the outcome? You can escalate to the Financial Market Ombudsman Service.
The safeguards that decide who pays
Because the rule turns on whether the provider met Bank Negara’s requirements, it’s worth knowing what those requirements are. These are the measures BNM first announced in December 2022 and set out in its 2024 annual report, rolled out across all banks and, more recently, the major e-money issuers. Most are things you can switch on or use right now.
| BNM safeguard | What it does | Your move |
|---|---|---|
| Move off SMS OTP to stronger authentication | Stops a scammer using an SMS code they phished or intercepted to approve a transfer | Switch to the app-based approval your provider offers |
| Cooling-off period on first-time device enrolment | Adds a delay when your account is set up on a new device, so a hijacked login can’t transact straight away | Don’t rush past the wait. It’s there to give you time to realise something’s wrong |
| Controls on new devices | Flags or blocks your account being activated on an unfamiliar device without your knowledge | Treat any “log in on our device” or “approve this new device” request as a red flag |
| Dedicated fraud hotline | A direct line to report fraud fast, while the money may still be traceable | Save your provider’s fraud number now, before you need it |
| Kill switch | Lets you instantly freeze your own account the moment you suspect fraud | Learn where the freeze button is in your app today. Minutes matter |
Read that table twice, because it cuts both ways. If your provider offered all of this and you still approved the transfer, that’s the “shared responsibility” case where your payout can shrink or vanish. And if you never turned any of it on, you handed the scammer the easy version of you.
The numbers behind the rule
The reason the government is legislating provider accountability at all is that the old approach, chasing the money after it’s gone, barely works. Once you’ve authorised a transfer to a scammer, getting it back is the exception, not the rule.
| Figure | What it tells you |
|---|---|
| RM2.8 billion | Reported lost to scams in Malaysia in 2025 |
| RM10.9 million | Total returned to victims by the National Scam Response Centre since it started in 2022 |
| RM1.2 billion | Fraudulent transactions that banks’ security controls prevented in 2025 |
| +26% | Rise in victims getting full or partial compensation after the policy was fully implemented |
Put the first two numbers side by side. Billions leave, a rounding error comes back. That gap is the entire argument for prevention over recovery. The compensation rule helps at the margin, and the 26% jump is real progress, but the money you never send is worth vastly more than the money you fight to claw back.
If you think you were shortchanged
The framework covers cases where the bank and the customer share responsibility, and compensation is assessed on each side’s level of negligence. If you disagree with your provider’s decision, you can take it to the Financial Market Ombudsman Service for an independent review. That is your escalation path, and it’s worth knowing it exists before you’re in the situation rather than after.
The reframe
The headline told you someone else now has to make you whole. The rule quietly told you the opposite: your protection is mostly still your job, and the compensation only lands if the provider was the one who slipped. So don’t file this under “good, I’m covered now.” File it under “the kill switch, the cooling-off delay, and device binding are the actual safety net, and they’re already in my hands.” A rule that pays out after the money’s gone is worth far less than the five seconds where you freeze the account before it moves.
Action step
Open your main e-wallet or banking app this week and do three things: find the account-freeze or kill-switch function so you know where it is under pressure, turn on device binding and app-based approval if you haven’t, and save the provider’s fraud hotline into your phone. If a transfer ever feels rushed or someone is talking you through it live, that urgency is the scam, not the exception to it. The four scripts every money scam runs on haven’t changed just because the refund rule did.
Check it at the source
- Consumers get greater protection from scams (The Star, 2 Jul 2026). The Prime Minister’s written parliamentary reply: the seven-working-day full compensation, the condition that the provider failed BNM’s safeguards, the shared-responsibility framework, and the RM1.2 billion prevented in 2025.
- Building a United Front Against Online Fraud Risk (Bank Negara Malaysia, Annual Report 2024). BNM’s own rundown of the safeguards (SMS OTP migration, cooling-off, new-device controls, kill switch), the shared-responsibility policy, the 14-day assessment, and the FMOS review path. Check your own e-wallet or bank’s help pages for how to switch each one on.
This is a policy statement to Parliament, not the full regulatory text, and scam rules are being tightened continuously. Confirm the current terms with your provider before you rely on them, and if you’re in the middle of a live scam, act first and read later.
Want the cheat sheet?
📥 The free Adulting Money Starter Kit includes a scam red-flag checklist and the official links worth bookmarking, so the fraud hotline and the freeze button aren’t something you’re hunting for while the money’s moving. Get it here →
Get the free Adulting Money Starter Kit
The money stuff school skipped, on a few pages, before you actually need it.
No spam. Unsubscribe anytime. Just the good stuff.
Check your inbox
You're on the list. Confirm via the email we just sent and the Starter Kit lands in your inbox.