BANGKOK, THAILAND – A tougher cybercrime decree failed to stem online fraud in Thailand, prompting consumer advocates to demand faster interventions, shared liability and delayed bank transfers.
New decree brought little relief
The second version of the Royal Decree on Measures to Protect Victims of Technology Crime, in force since April 2025, had not delivered the expected impact, according to consumer advocates. The core problem of recovering stolen funds had barely improved, while key safeguards before transactions, such as transfer delays, were still missing. Reported cases continued to fall into two broad groups: phishing and spoofing scams covered by the decree, and schemes in which victims were persuaded to transfer money themselves, including alleged investment offers.
Fraud grew more complex across platforms
The secretary-general of the Thailand Consumers Council, Saree Ongsomwang, said cyber fraud had not eased but had instead “become more complex,” pointing to major gaps between platforms, banks and telecom operators. She cited app stores on iOS and Android where fake apps were listed without sufficient checks on their authenticity, and said the state Electronic Transactions Development Agency (ETDA) still could not effectively register platforms or enforce their obligations.
“Consumers remain unprotected because new fake offers can go online without effective barriers,”
said Saree Ongsomwang, secretary-general of the Thailand Consumers Council.
Banks struggle with mule accounts
In the banking sector, the council acknowledged progress in implementing Bank of Thailand measures but highlighted critical weaknesses, especially so‑called mule accounts used by criminals to move funds. Saree argued such accounts should be blocked from making transfers from the outset, yet many could still move money in practice, and there was no clear shared liability when these accounts were used for fraud. She also criticised mule accounts held by legal entities, noting some companies had failed to file financial statements for more than five years but were not removed by the Department of Business Development, allowing repeated misuse to deceive consumers.
Narrow protection for vulnerable groups
Saree said the BOT’s definition of “vulnerable groups” was too narrow, as it focused on people aged 65 and above, even though those from 60 years old were often targeted by scammers without receiving the same protection. Many victims were forced to file lawsuits themselves because legal measures had not effectively contained digital fraud, and some were told they did not legally qualify as “consumers” and thus had no right to support. She said many had to hire lawyers, typically paying around 10% of their losses and in some cases up to 20%, even after winning their cases, leaving numerous victims near financial ruin and unsure how to proceed.
Telecom rules slow SIM card shutdowns
The council also voiced concern over the telecom sector, saying new National Broadcasting and Telecommunications Commission (NBTC) rules had made it harder to deactivate fraudulent SIM cards. Providers now had to wait for a regulator’s order before blocking suspicious SIMs, whereas mobile operators had previously been able to detect SIM boxes themselves and shut them down immediately. Saree said some firms that once reacted quickly were now much more constrained, while ID registration rules were still not strict enough, allowing fake sites and apps to be registered again and again.
Fragmented responses and unclear compensation
Victims often received differing answers depending on which agency they contacted, and there was no uniform standard on compensation, leading Saree to call for a joint compensation fund to support those affected. She criticised what she described as a “patchwork approach” by authorities, noting that requirements for platforms to respond to reports of false content within 24 hours were too slow, as criminals could shift money across multiple layers in minutes.
“Technically, maximum response times of two hours, ideally 30 to 60 minutes, are feasible and would significantly reduce damage if authorities and companies genuinely coordinated,”
said Saree Ongsomwang, secretary-general of the Thailand Consumers Council.
Calls for automatic liability and transfer delays
The Thailand Consumers Council pushed for a system of automatic liability to hold platforms and financial institutions more accountable, saying many countries had clear penalties and compensation mechanisms while victims in Bangkok and other regions still had to initiate proceedings themselves. To limit losses effectively, Saree said preventive measures were crucial, especially a system of delayed transfers so consumers had time to review transactions before funds irrevocably left their accounts. She noted the council had advocated transfer delays for more than two years, pointing to similar measures in Singapore that had already shown measurable results, and argued that automatic compensation and shared liability had to be introduced in parallel rather than leaving victims to struggle alone in a slow system.
Complaint figures highlight systemic gaps
Between October 2024 and September 2025, the council received 18,687 complaints related to digital risks, with the most common involving SMS messages containing fake links, online purchases where goods were never delivered and call‑centre scams that tricked victims into making transfers. In addition, it assisted in 111 cases where consumers were sued by credit card companies and banks after fraud incidents, which the council viewed as evidence of structural weaknesses in existing mechanisms. Victims often had to contact multiple agencies because no single body took direct responsibility, even though most cases clearly involved internet‑based financial fraud rather than simple telephone tricks.
