Medical identity theft has entered a disturbing new dimension in Malaysia, where artificial intelligence technology is being weaponised to impersonate healthcare professionals and peddle fraudulent treatments. Consultant cardiologist Dr Onn Akbar Ali recently encountered a manufactured video bearing his likeness and voice, fraudulently endorsing herbal tea as a cure for diabetes. The incident underscores how deepfake technology—once confined to entertainment speculation—has evolved into an operational tool for health-related scammers targeting patients, credibility, and public trust in medical institutions.
The implications for Malaysian healthcare extend far beyond a single physician's misappropriated identity. Deepfake videos deployed to promote wellness products exploit a known gap in digital literacy, particularly among older demographics susceptible to chronic diseases like diabetes and heart conditions. When AI-generated content purporting to come from respected doctors carries the veneer of medical authority, patients may abandon evidence-based treatments in favour of unverified botanical preparations, creating genuine health risks alongside financial loss. The scam fundamentally compromises the doctor-patient relationship by eroding confidence in whose medical advice is authentic.
The technical barrier to creating convincing deepfakes has diminished dramatically. Commercial and open-source tools now enable bad actors to synthesise facial movements, lip-sync voices, and maintain lighting consistency with minimal expertise or investment. A scammer requires only publicly available footage—conference presentations, television appearances, social media clips—to construct a functional facsimile of a real physician. For doctors of prominence, this vulnerability is almost unavoidable; their professional visibility becomes a liability. The effort required to debunk each fraudulent video far exceeds the effort to create one, giving perpetrators a structural advantage in the arms race between verification and deception.
Malaysia's regulatory and enforcement apparatus remains substantially unprepared for this emerging threat category. Medical boards focus on professional conduct and credentials within the healthcare system itself; cybercrime units concentrate on conventional fraud and identity theft. Deepfake health fraud occupies an intersection that existing institutional frameworks address only partially. Platform policies around synthetic media vary widely, and the threshold for removal often requires clear evidence of harm or impersonation—criteria difficult to meet and document swiftly. Meanwhile, misinformation spreads exponentially faster than corrections, and patients may purchase products or delay treatment based on false videos before any corrective action occurs.
The economic stakes are substantial. Malaysia's wellness and herbal supplement sector attracts considerable consumer spending, creating financial incentive for sophisticated fraud networks. Vulnerable populations—rural patients with limited internet literacy, elderly individuals, those in early disease stages seeking alternative options—form attractive targets. A single deepfake video linked to multiple product sales channels could generate millions in revenue before detection. The perpetrators face relatively low legal exposure compared to potential profits, particularly if they operate across jurisdictional boundaries or obscure their operations through cryptocurrency and forwarding networks.
Regional healthcare systems face compounded risks. Throughout Southeast Asia, trust in formal medical institutions sometimes remains fragile due to accessibility barriers, cost constraints, and historical variances in healthcare quality. Deepfake scams exploit these vulnerabilities by positioning themselves as accessible, low-cost alternatives endorsed by legitimate authorities. The scam undermines not only individual patient safety but also public health messaging around disease prevention and treatment, which depends on clear communication channels and trusted messengers. When patients cannot reliably distinguish authentic medical guidance from artificial imitations, they retreat into confusion, scepticism, or dangerous self-treatment.
Dr Onn Akbar Ali's situation reflects a growing complaint pattern among Southeast Asian medical professionals. Cardiologists, oncologists, and other specialists have reported similar incidents, yet a comprehensive data collection mechanism does not exist. Individual doctors may choose not to publicise violations to protect their reputation, creating an undercounting that masks the true scope. This information gap prevents systematic analysis of targeting patterns, geographic concentrations, or evolving techniques—all essential for developing effective countermeasures.
Technological solutions are emerging, though none yet provide comprehensive protection. Blockchain-verified credentials, digital signature verification, and platform-level synthetic media detection tools offer partial mitigation. Some hospitals are introducing verification systems where patients can confirm whether medical endorsements are genuine. However, these approaches require widespread adoption and digital infrastructure investment often absent in less-developed regions. The burden cannot fall solely on medical professionals to authenticate their own identities repeatedly across platforms.
Policy responses in Malaysia must address multiple dimensions simultaneously. Healthcare regulators should issue guidance helping patients identify fraudulent content and report suspicious videos. Medical boards need protocols for members to formally notify peers and patients when impersonation occurs. Cybercrime authorities require training specific to synthetic media forensics. Telecommunications and internet service providers should cooperate on rapid removal of verified deepfake health content. Social media platforms operating in Malaysia must commit to stricter synthetic media policies in healthcare advertising, including verification requirements for medical endorsements and rapid response mechanisms for removal requests from affected professionals.
The deepfake health fraud phenomenon also highlights urgent need for public digital literacy campaigns. Mass media, community health workers, and primary care clinics should educate populations about synthetic media risks, verification methods, and reporting channels. When patients understand that they should independently verify unusual medical claims—particularly those promising miraculous cures—they become less vulnerable to manipulated content regardless of artistic quality.
Dr Onn Akbar Ali's discovery signals that Malaysia's healthcare sector has entered a new era of information security challenges. The threat is not speculative but operational, actively harming real patients and undermining medical credibility. Addressing it requires coordinated action from healthcare institutions, regulators, technology platforms, law enforcement, and citizens themselves. Without rapid institutional adaptation and public awareness, deepfake health fraud will likely proliferate across Southeast Asia, exploiting vulnerable populations and corroding the scientific foundation upon which public health depends.
