AI Financial Fraud in Southeast Asia, and Why Korea Is Next
๐ค Bloom ร Level Five Group ร Cafe Curious
๐ค Frederick Chung, Co-founder and Group CEO of Level Five Group
๐๏ธ Event page
We ran a Bloom meetup with Fred on financial security and fraud in the AI era. Level Five Group, the company he leads, is a Singapore firm that detects financial security threats across Southeast Asia, including Thailand, Malaysia, Indonesia, and Cambodia, as well as Japan and China. Preparing his Korean market entry, he has been flying in at least once a month, wandered into a Bloom meetup, and that accident became this event.
It was a short session and a heavy one. In Southeast Asia, AI now clones the tone of a voice in four seconds, and that capability feeds everything from voice phishing to bank fraud. AI-driven voice phishing is already an established category of cybercrime, and the evening was a wake-up call.

We put the room together on short notice and expected about 30 people; more than 45 came. The turnout said everything about how much this topic matters right now. Fred presented with depth and clarity, and I learned as much as anyone in the room.
What Fred most wanted from the evening was field knowledge: how fraud patterns differ by culture and economy, and what shape they take in Korea. He wanted practitioners, not research reports, so we kept the room small and curated it to people working in adjacent fields. Everyone sat close, and the conversation went deep.
Korea is still seen as a relatively safe country, and privacy concerns make user-data-based defense systems feel premature here. Global players, however, are already preparing for this market with real interest. Here is what we heard, in order.
Four seconds is enough
Fred opened with a joke. When I told him the Bloom story, from AI Blue to blooming, he said he loved it, then added:
Unfortunately, my business is on the Blue side.
Fred has spent over a decade fighting financial crime for banks. He works with the Royal Thai Armed Forces, ASEAN Interpol, and Malaysian regulators, and he runs a banking consortium in Thailand himself. The fun part: he dropped out of engineering school, re-entered through accounting and finance, and founded the company in his final year. Asked why he dropped out, he said he partied too much. And he started knowing nothing about cybersecurity or fraud.
The talk began with a public service ad produced by the Chinese government. A mother is on a video call with her daughter, who pleads that money is tight this month. The mother types in the account number, and just before she hits send, the doorbell rings. Her real daughter is standing at the door. On the laptop, someone is still talking in her daughter's face and voice.
When a government makes ads like this to warn its own citizens, it means the crime is common. Then came the strongest number of the night.
All it takes to clone a voice is four seconds.
They clone the tone, not the voice

I had assumed voice cloning meant collecting thirty to sixty minutes of audio and training a model for hours, the way it works in Mission Impossible.
We are not reproducing your entire voice profile. We only imitate the tone and timbre.
Four seconds extracts the tone. Then a real human speaks through a voice changer, laying their own delivery over that tone. To impersonate Trump you do not need to pronounce like Trump; you take his voice profile and copy the manner. Fred demonstrated it live, and it was convincing.
That is why live-call deepfakes feel so natural. A machine is not talking. A person is.
Where do the voices come from? Mostly social media: TikTok, Facebook, X, Threads, YouTube, television. Robocalls also harvest the 'hello, who is this?' that people answer with, and the recordings sell on the dark web. Fred's advice: unless you are a public figure, set your profiles to private and keep your videos off the internet.
There was a Korea-specific note. As a net exporter of K-pop and K-entertainment, Korea has the most mature voice cloning models in the world. Thai voices are actually harder to clone, because there is far less content.
The most common attack is still impersonation
On the flashy end there is deepfake investment fraud: pre-produced videos of a fake Elon Musk promoting coins, distributed and even advertised on social media. In Singapore, a live Zoom call impersonated the prime minister, inviting people into a government-backed investment opportunity. Not the most common attack, but the biggest single losses.
The most common is still the impersonation call: government, police, immigration, your company, plus romance scams. The root is data breaches. Because my information has leaked somewhere, the caller can talk as if they know me.
Fred's own story was telling. Right after his Singpass was approved, he received a robocall impersonating Singapore immigration.
The moment they asked whether I speak Chinese, I knew it was fake.
The real immigration office would never need to ask. He played along in Mandarin anyway. The caller claimed an error in his employment pass and demanded 33,000 Singapore dollars. Even people whose job is stopping fraud get targeted. One recent case he handled ran to 4 million ringgit, about a million US dollars.
One vacation post breached a company

Up to this point it sounded like a story about individuals losing money. Then the direction changed.
A security executive at a large company posted on social media that he was going on vacation. His profile was public. Attackers cloned his voice from his videos, then called an employee while impersonating the vacationing executive. His system credentials were locked, he said, and he needed the OTP.
From the employee's side, the voice matched and the vacation was real. Even the small talk about the destination lined up, so the reset went through. The company caught it soon after, but it was already too late.
Planting a backdoor takes ten minutes.
Six months later, an actual breach came through that backdoor. Voice phishing is no longer just personal fraud. It has become a door into corporate systems.
99 percent is a lab number
So can it be detected? The contrast here was the heart of the evening.
In controlled environments, detection exceeds 99 percent. That is with clean recordings in a quiet room. In real conditions it drops to 50 or 60 percent, because network quality strips out the signals detection depends on. Fraudsters deliberately hide behind bad networks, and Southeast Asia still runs plenty of 4G and 3G.
You might think 50 to 60 is not bad. Then consider how many transactions a bank processes in a day. Everything that is not filtered must be reviewed by human eyes, and no bank can staff that.
The room went quiet here. It was the moment I finally understood: the problem is not missing technology. It is operations.
99 percent is an excellent number. Is it operationally practical? No.
What a bank needs looks more like 99.999 percent. Without it, the bottleneck is not the technology but the bank's fraud operations team.
So they watch the phone, not the face

Trying to catch deepfakes is a fine starting point, Fred said, but you cannot stop there. So they watch something else.
In the digital economy, the most important thing to watch is not the person. It is the phone the person is using.
iPhone or Android, whether the screen resolution matches the device, whether it is jailbroken or rooted, whether developer mode is on. Then behavioral biometrics: if the phone does not move at all at the moment of a transaction, something is off. A phone lying face down on a desk, charging, should not be making payments.
The details were fascinating. They watch whether you hesitate while typing your name; nobody stops to think about how to spell their own name. They watch copy-paste; you might paste an address, but nobody pastes their own name and phone number. They watch whether you are on a call during a banking session; weak signal for the young, who are always on calls, but a strong one for older customers.
Bypassing eKYC turned out to be simpler than expected: jailbreak the phone, play a deepfake video on a high-resolution TV, and point the camera at it. The app decides the person is real. It is called camera injection.
So I asked: can a bank actually tell whether the caller is the real customer?
Honestly, we do not know.
Banks ask for ID numbers, card digits, phone numbers, but all of that has already leaked. Malaysia's answer was to bind accounts to a physical device the customer owns; unbinding freezes the account for 24 hours. Though, he added, an engineer could unbind it and move it to another phone.
No single bank can do this alone
This was the most important part of the night.
The way to stop fraud is not to fight fraudsters. It is to stop the movement of money.
Block the mule accounts and fraud stops. Steal a billion or a trillion, if you cannot pull cash out of an ATM, nobody bothers.
The problem is that one bank cannot do it. The same phone commits fraud at Bank A, and Bank B knows nothing; the two accounts have no relationship. But if Bank A hands that device fingerprint to Bank B, Bank B can freeze the account the moment that phone logs in. Better still, every other account that phone has ever touched surfaces with it. One device exposes an entire mule network.
Some countries already do this. The UK maintains a confirmed-fraud list keyed on device IDs, shared across member banks. Australia scores receiving accounts with behavioral biometrics before payment. Singapore wrote it into law: past a certain threshold, phone numbers and account numbers must be shared.

Fred is building this in Thailand. At a session hosted by Bangkok Bank, 30 people from 11 banks gathered, the first fraud-response consortium in the industry there. He sits in that room as the only non-banker, persuading banks to share data. A device-fingerprint sharing pilot with two tier-one banks starts soon.
Who eats the loss decides the investment
Why would banks come together at all? The answer was crisp.
About nine years ago he pitched the idea to a tier-one bank and got this reply: our fraud losses are only 30,000 dollars. That made no sense to him; a single case involving that bank in the news was worth millions. Much later, after many conversations with bankers, he learned the reason.
We are not liable for that loss, so we do not record it as fraud.
The customer sent the money themselves, so it is the customer's fault, and it never enters the bank's books as fraud. Then Southeast Asian regulators changed the rules: scammed or not, the bank now covers 50 percent of the loss. The math flipped overnight.
Now do you have an incentive to invest in the technology?
After an evening of technology, what settles the question is accounting.
What Korea lacks is not technology
I asked whether Korean banks are ready.
Korean banks have started investing in fraud detection technology. What lags is not the technology but the regulation that lets customer data be used for fraud prevention.
Collecting behavioral biometrics and device data is technically legal in Korea. But banks will not carry the privacy risk to do it, so they keep asking whether customer consent is required.
Thailand went through this sequence already. Under the original Thai privacy law, even an IP address was personally identifiable information. When fraud spiraled, the central bank changed the rules: to use a banking app, you must provide identifying data. Regulation moves only after the damage is large enough.
Europe was an interesting aside. European and US transfers are not real time; they take two or three days. The delay we find frustrating is an advantage for fraud defense, because even if you see the alert two days later, you can call the clearing house and reverse the transaction. Korea and Southeast Asia settle instantly, so that window does not exist.
Fraud leaves the countries that crack down
At the fireside I asked who is behind all this.
Wherever there is money, there are criminals. Think about it: these people are entrepreneurs. In the end, they are business people.
It is literally an industry. Not a kid with a MacBook in a garage. Fraud centers have cafeterias, restaurants, and staff bowling alleys. They are companies. The Chinese film No More Bets, he noted, is set in a real fraud center.
Is Singapore safe? The banking defenses are good, he said, so attacks fall back to basics. Obtaining government data and impersonating the police is one of Singapore's largest loss categories.
Singapore is a country where everyone follows the law. If I can make you believe I am the police, you comply.
Malaysia is different: people just hang up on fake police calls, because Malaysians are not particularly compliant. Culture, not defense level, was deciding the playbook.
The most chilling story was about a person who escaped a fraud center in Cambodia, walked into a police station in another country, and was sent back to the fraud center by the police.
And the final question produced the answer I most wanted to hear. Asked what he most wants to learn about Korea, he said he wants to know what Korea's real fraud problem is. Then he added:
Fraud is moving toward Korea right now because enforcement is tightening across Asia.
It ran big in the Philippines until the crackdowns came, moved to Thailand, and when the Royal Thai Armed Forces cracked down, moved to Cambodia. It keeps migrating toward weaker control.
So the fact that we do not see much of this fraud yet may not mean we are safe. Our turn may simply not have come.
The next question is not whether you are human
I did not open this room out of an interest in cybersecurity, but by the end it was clearly an AI story.
One passing remark keeps coming back to me: there is now AI that never sleeps and keeps searching for ways in. Ask regulators and they say detection rates are rising; in reality, he said, there is simply more fraud to catch.
And one thought has stayed with me since. Today, payment systems judge whether you are human. When AI agents start paying on our behalf, the question changes: is this really the agent I own and authorized? Fred agreed that the moment you hand credentials and authority to an agent, a new attack surface opens.

People stayed long after the program ended. A founder of a deepfake detection startup talked through detection rates, and a guest from a crypto exchange said regulation extends to exchanges from October, so they are building systems alongside the banks. Automated penetration testing, someone argued, is currently the market with the widest gap between demand and supply.
Whenever we build a room like this, I am the one who learns the most.
FAQ
What is Level Five Group? A Singapore-based company detecting financial security threats across Southeast Asia, Japan, and China, led by Frederick Chung, who also hosts a fraud-response banking consortium in Thailand. It is now preparing to enter the Korean market.
How real is 4-second voice cloning? Four seconds of audio captures a tone and timbre profile; a human then speaks through a voice changer over it. Detection that reaches 99 percent in the lab drops to 50 or 60 percent over poor networks.
What actually stops fraud? Stopping the movement of money rather than fighting fraudsters: sharing device fingerprints across banks to expose mule account networks, the model already emerging in the UK, Australia, Singapore, and Thailand.
Scenes from the night



Join Bloom
Bloom builds offline rooms where people and technology meet. We run them in Seoul, and now beyond it.
- ๐ฌ Discord community, where events are announced first
- โถ๏ธ YouTube, full talks from past events
- ๐ธ Instagram, photos from our events
- ๐๏ธ Upcoming events