
The next thing hackers could steal is our trust
I HAVE a new fear – not of ghosts, flying or even my children growing up and answering me with “okay, whatever”.
It’s hackers. Okay, okay, I know. We have been talking about hackers for years. Usually, when I hear the word “hacker”, I still imagine some fellow sitting in a dark room, wearing a hoodie, surrounded by five computer screens, typing away like he is trying to save the world – very Hollywood.
But apparently, we have entered a new era. Hackers now don’t even need to be particularly clever when they have AI. And suddenly, I am looking at my phone differently. Because Malaysians already live half our lives inside our phones – our banking is there, shopping is there, children’s school groups are there, photos are there, work is there, family arguments are there. Even our most embarrassing moments are probably somewhere in a WhatsApp chat.
And we happily give away information about ourselves every single day.
“Please enter your full name.” Okay.
“IC number?” Okay.
“Phone number?” Okay.
Date of birth?” Okay.
“Email?” Okay.
“Location?” Okay.
“Allow access to contacts?”
Hmmmm. Okay-lah.
Then six months later, we get a strange message: “Dear customer, your account has been suspended. Click here.” And suddenly we wonder: “How do they know my name?”
They know because we have been feeding the internet information about ourselves for years.
Now AI is making things even more interesting. A recent BBC report about an AI system being used in a cyberattack made me stop and think about where this is all heading.
AI does not get tired, it does not need lunch, it does not go home at 5pm, it does not say: “Sorry boss, today I got a headache.”
It can process information at a speed none of us can match, and if the wrong people get hold of that power, the problem is no longer about just someone trying to guess your password. It could be someone using technology to understand you.
What scares me is not the idea that someone can hack a computer. What scares me is the idea that someone can hack our trust.
Think about how many scams we are already dealing with – fake police officer, fake bank officer, fake delivery company, fake government officer, fake “boss” asking you to transfer money, fake son or daughter saying: “Mummy, I need money.”
We have become so suspicious that when an unknown number calls, some of us answer: “Who are you?” “Where did you get my number?” “What do you want?” “Which bank?” “Give me your name.” “Give me your IC.” “Wait, I call you back.”
We have become our own amateur cybercrime investigators. Now imagine the scammer using AI, and the voice on the phone sounds exactly like your child. Not “sounds a bit like” but exactly – same voice, same accent and the same way of saying “Mummy”.
Would you know? Would I? I honestly don’t know. And that is frightening because our first instinct when something happens to the people we love is not to investigate but to react. If my child calls me crying, I am not going to stop and analyse the frequency of his voice. I am going to panic, and that is what makes this so dangerous.
AI doesn’t necessarily have to steal your money; it can exploit the things that make you human: fear, love, urgency, curiosity and trust. And this is where Malaysia needs to have a serious conversation. Because we are already seeing how AI can be used to manipulate people online.
Anthropic, the AI company behind Claude, recently said it had disrupted an operation involving about 1,000 fake social-media accounts and a fabricated news site targeting Malaysian voters by constituency.
That line really got me – by constituency – not just random fake accounts throwing random nonsense into cyberspace. The operation was reportedly designed around particular groups of people. Which means technology can potentially be used to understand what different people care about and then tell them exactly what they want to hear.
Suddenly, this is bigger than somebody stealing your online banking password. What if the next thing someone tries to steal is your opinion? Your confidence in something? Your trust in someone? Your understanding of what is true? That is where I think all of us need to be careful because Malaysians love forwarding things.
We see a message in the family WhatsApp group and before we have even finished reading it: “Forwarded many times.” Aiyo.
Then somebody’s aunty sends: “Please share urgently!!!” And suddenly 14 family members are discussing whether drinking hot water can cure something.
We laugh. But AI-generated content is going to make that much harder. A fake photograph can look real. A fake video can look real. A fake voice can sound real. A fake article can read like real journalism.
So what do we do? For starters, maybe we should slow down. If something makes us angry, scared or excited, maybe that is exactly when we should stop and check.
If someone calls asking for money, call them back on the number you already have. If your “bank” calls, hang up and call the bank yourself. If a photograph looks unbelievable, maybe it is. If a video confirms exactly what you already believe, perhaps that is the moment to question it even more.
And please, for the love of God, stop using your birthday as your password. I know – I am judging you. Because I know some of you are still using 123456 – don’t lie. I know. The funny thing is, technology is supposed to make our lives easier – and it does. But the smarter technology becomes, the smarter we have to become too. Not necessarily technically but as human beings.
We need to ask questions, verify, pause and stop assuming that something is true simply because it looks real. Because, maybe, that is the biggest lesson from all this.
The biggest weakness in cybersecurity may not be our computers or even AI. It may be how badly we want to believe the things that feel familiar to us – a familiar voice, face, headline or WhatsApp message. We trust what feels real and AI is getting very good at making things feel real. So yes, I will continue to be suspicious when a stranger messages me, “Hi dear”.
But now I have a new rule. If my mother suddenly sends me a voice note saying, “Hi darling, please transfer RM5,000…”, I am calling her. Because in 2026, apparently even “Mummy” may need two-factor authentication. And honestly? That scares me more than any hacker in a hoodie ever could.
Hashini Kavishtri Kannan is the news editor at theSun. Comments: letters@thesundaily.com
