ADUN SPEAKS | The tragic deaths of a husband, his wife and their two children in Desa ParkCity have shocked the nation.
According to the police, initial investigations found a note allegedly linking the tragedy to the wife’s involvement with a love scam, with losses and debts said to have reached approximately RM260,000.
The investigation is ongoing, and we must be careful not to prejudge the circumstances.
However, one thing is undeniable: online scams can destroy far more than a bank account - they can destroy families and lives.
This tragedy should therefore be a national wake-up call. Malaysia is already facing a serious and rapidly growing scam crisis.
According to available online portals and data, in 2025, 66,204 online fraud cases were recorded, an increase of 87 percent from the previous year, while total losses reached RM2.97 billion, compared with RM1.57 billion in 2024.
Love scams alone accounted for RM47.44 million in losses in 2025, according to government figures.
Scammers exploit emotions, information
These are not merely statistics. Behind every figure is a victim, a family, and often years of savings. Scammers are no longer simply sending random messages.
They exploit emotions, relationships, personal circumstances and information available about their victims.
A scammer who knows who you are, where you live, who your family members are and how to gain your trust has a far greater ability to manipulate you.

I myself have been receiving numerous phone calls and messages from those scammers. This brings me to a fundamental question which the prime minister and federal government must answer: who is ultimately accountable for protecting the personal data and digital identity of Malaysians?
The government requires Malaysians to provide highly sensitive information - including MyKad numbers, names, dates of birth, addresses, telephone numbers and other personal particulars.
Citizens often have no real choice because such information is required by law or to obtain essential government services.
Once the government requires citizens to surrender their identity information, the state must accept a corresponding and serious duty to protect it.
Fundamental gap
Malaysia already has the Personal Data Protection Act 2010 (Act 709), and the 2024 amendments have strengthened the framework, including data-breach notification requirements for those covered by the Act.
However, there remains a fundamental gap which government cannot ignore: the Personal Data Protection Department expressly states that the Act does not apply to the federal government and state governments.
This therefore raises a serious public-policy question: if some of the most sensitive personal information belonging to millions of Malaysians is held by the government itself, what comprehensive statutory framework protects that information?

Citizens are repeatedly told: do not disclose your one-time password (OTP), do not click suspicious links, do not reveal your personal information and do not give your banking details to strangers. All of that is correct.
But citizens cannot simply refuse to provide their MyKad information when the state requires it. The state's responsibility must therefore be greater, not lesser.
Not mere privacy problem
A data breach is not merely a privacy problem. It can become a scammer's toolkit. If personal information is compromised, criminals may use it for impersonation, social engineering, fraudulent accounts, financial applications and increasingly sophisticated scams.
If a citizen's identity is misused, the innocent victim may then be forced to prove: “that was not me.” A fine imposed after a breach does not restore a stolen identity.
A compromised MyKad number, name, date of birth or address cannot simply be replaced like a bank card.

I therefore call upon the prime minister and federal government to establish a clear national framework for the protection of government-held personal data and identity theft victims.
There must be clear responsibility for who controls access to sensitive databases, who is accountable when security fails, how third-party contractors are regulated, how breaches are independently audited and investigated, and how citizens are promptly notified and protected when their information is compromised.
There must also be a National Identity-Theft Response Mechanism, so that a victim does not have to navigate multiple agencies alone.
A Malaysian whose identity has been compromised should know immediately where to report it, how to place protective alerts on his or her identity, how fraudulent transactions can be challenged, what assistance is available and who bears responsibility when institutional failure contributes to the harm.
The Desa ParkCity tragedy should remind us that the human cost of scams can go far beyond money.
Malaysia cannot continue with a “breach happens - investigate afterwards” mentality.
We need a national approach based on prevent - detect - notify - protect - remedy.
The government must not merely tell Malaysians that their data is safe. It must demonstrate that it is safe.
If the law is inadequate, change the law. If accountability is unclear, fix the system. If citizens are increasingly exposed to identity theft and scams, protect the people.
Malaysians have entrusted their identities to the state. The state must not betray that trust. - Mkini
CHIN TEK MING is the state assemblyperson for Kapayan.
The views expressed here are those of the author/contributor and do not necessarily represent the views of MMKtT.

No comments:
Post a Comment
Note: Only a member of this blog may post a comment.