AI financial fraud in Southeast Asia — Korea is next
What was discussed

Frederick Chung has spent more than ten years on financial crime response for banks. He works with the Royal Thai Armed Forces, ASEAN Interpol and Malaysian regulators, and runs a bank consortium in Thailand himself. He dropped out of engineering, came back through accounting and finance, and started the company in his final year; this is year eleven. He knew nothing about cybersecurity or fraud when he began. Introducing himself, he said he liked that Bloom's name runs from AI Blue to Bloom — then added that his own work, unfortunately, is on the AI Blue side.
He opened with a Chinese government public-service ad. A mother is on a video call with her daughter, who says money is tight this month and asks her to send some. Just before she hits send, the doorbell rings — and her real daughter is standing there. On the laptop, someone is still speaking with her daughter's face and voice. That a government makes an ad like this to warn its own citizens tells you how common it is. Then came the number that landed hardest: cloning a voice takes four seconds.
What changed the room's understanding was that the clone is not a whole voice profile, only tone and timbre. Four seconds gets the tone; a real person then speaks through a voice changer, carrying their own delivery in that tone. To impersonate someone you do not need to sound like them — you only need their voice profile. That is why live deepfake calls feel natural: a person is talking, not a machine. The voices mostly come from social media, and robocalls are used to record answers that are then sold on the dark web. Unless you are a public figure, he said, keep your profiles private and your own video offline. Korea, exporting K-pop and entertainment, has the world's most mature voice-cloning models; Thailand is harder to clone simply because there is less content.
At the flashier end sits deepfake investment fraud — videos of a public figure promoting a coin, seeded across social media and boosted with ads. In Singapore a Zoom call impersonating the prime minister ran live. It is not the most common attack, but it takes the most in one go. The most common is still the plain impersonation call: government, police, immigration, a company, with romance scams attached. The root is data leakage — your information is out there, so the caller can talk as though they know you. He got a robocall impersonating Singapore's immigration authority himself, and knew it was fake the moment it asked whether he spoke Chinese. The real authority would not need to ask.
The direction shifted when it stopped being about individuals. A security lead at a large company posted that he was going on holiday, with a public profile. The attacker cloned his voice from his videos, called an employee while he was away, and asked for an OTP because his credentials were locked. The voice matched, the holiday matched, the details of where he was matched — so the employee reset it. They caught it soon after, but too late. Ten minutes is enough to plant a backdoor, and the actual breach came through it six months later.
The contrast on detection was the heart of the evening. In a controlled environment, detection runs above 99 percent. In the real world it drops to 50 or 60, because network quality strips out the signal detection depends on — which is why fraudsters deliberately hide behind poor networks. The problem is the volume a bank processes daily: everything not filtered out has to be reviewed by a person, and no bank can staff that. Ninety-nine percent is a fine number, he said, but asked whether it is operationally practical, the answer is no. Banks need something closer to 99.999, and short of that the bottleneck is not the technology but the bank's fraud operations team.
So he looks at the device rather than the face. In a digital economy, what matters is not the person but the phone they are holding. Model and screen resolution, whether it is jailbroken or rooted, whether developer mode is on. Behavioural biometrics sit on top: a phone that does not move at all during a transaction is odd, and a payment from a phone face-down on a desk charging is a problem. Hesitation while typing a name counts — nobody thinks about how to spell their own. People paste an address, but not their own name and phone number. Bypassing eKYC is simpler than expected: jailbreak the phone, play a deepfake on a high-resolution TV, point the camera at it, and the app accepts it. It is called camera injection. Asked whether a bank can tell if the caller is really the customer, he said honestly, no — the ID number, the last digits of the card, the phone number have all already leaked.
The most important point was that stopping fraud is not about fighting fraudsters but about stopping the movement of money. However much is stolen, if it cannot be withdrawn nobody bothers. The problem is that no single bank can do this. The same phone can defraud bank A and bank B will not know. But if A passes the device fingerprint to B, B can freeze the account the moment that phone logs in — and every other account the phone has touched surfaces with it. One device exposes the whole mule network. The UK shares a device-ID fraud list across member banks, Australia scores receiving accounts with behavioural biometrics before payment, and Singapore legislated the sharing of phone and account numbers. In Thailand, 30 people from 11 banks met at an event hosted by Bangkok Bank — the industry's first fraud consortium — and a device-fingerprint sharing pilot with two tier-one banks starts soon.
Why banks are only now coming together had a clean answer. Nine years ago he took the idea to a tier-one bank and was told their fraud losses were only $30,000, when a single case in the news had run to millions. He later learned why: the customer had made the transfer themselves, so it was not the bank's liability and never went on the books as fraud. Then Southeast Asian regulators changed the rules so banks bear 50 percent of the loss whether or not the customer was defrauded. The arithmetic changed completely, and with it the incentive to invest. After an evening of technology, what settled it was accounting.
Asked whether Korean banks are ready, he said they have started investing in detection technology, and what lags is not the technology but the regulation that would let customer data be used for fraud prevention. Collecting behavioural biometrics and device data is legal in Korea, but banks will not take on the privacy risk. Thailand has already been through this order of events: IP addresses counted as personal data under its privacy law until fraud grew beyond control and the central bank required banking apps to collect identifying data. It takes a large loss to move regulation. In Europe and the US, transfers take two or three days rather than clearing instantly, and that delay — the part we find frustrating — helps: you can still reverse a transaction after seeing the alert two days later. Korea and Southeast Asia settle immediately, and have no such window.
Asked in the fireside who is behind it, he said there are always criminals where the money is, and that these people are, when you think about it, entrepreneurs. It is a real industry rather than someone with a laptop in a garage — the scam centres have canteens, restaurants and a bowling alley for staff. Singapore's bank-side defences are strong enough that attacks fall back to basics, and impersonating police using leaked government data is one of its largest categories of loss. It is a country where everyone follows the rules, so convincing someone you are the police is enough. Malaysia is different: people simply hang up on a police call. Culture, not the level of defence, was setting the method.
On the last question — what he most wanted to know about the Korean market — he said he wanted to understand what Korea's real fraud problem is, and added that fraud is moving toward Korea because enforcement across Asia is tightening. It ran large in the Philippines, moved to Thailand when enforcement arrived, and moved to Cambodia when the Royal Thai Armed Forces cracked down. It keeps moving toward weaker control. Which means that if it feels like this kind of fraud has not reached us, that may not be because we are safe — only that our turn has not come.
The audience questions were good. Asked what becomes of existing security software companies as LLMs improve, he said some will become irrelevant, the way the job of clearing horse manure from the road disappeared in the move from horses to cars. He does not see AI replacing people so much as compounding productivity, and pointed to penetration testing as the opening: expertise is scarce enough that supply and demand are badly mismatched, and running automated pen tests continuously with an LLM closes that gap. Someone from a crypto exchange noted that Korea is extending regulation to exchanges with new rules from October, so they are building systems and will have to work with banks — and proof of assets and source of funds will tighten.
Today a payment is checked for whether a human is behind it. Once AI agents pay on our behalf, the question changes: you have to verify that this is genuinely an agent you own. Handing an agent credentials and permissions opens a new attack surface. People stayed on well after the session ended.
Read the full write-upGallery

















Next event






