Maya and GCash say AI scams are now a top threat to your e-wallet
At a Pasay summit this week, Maya's information security director said AI lets one scammer go from 10 victims to 10,000. GCash, which serves over 94 million people, named AI-powered manipulation among its biggest risks.
The two biggest e-wallets in the Philippines were asked what worries them most, and they said close to the same thing. At the BusinessWorld Cybersecurity Summit in Pasay City on Tuesday, Jan Martin Encina, director of information security at Maya Philippines, and Ingrid Rose Ann Beroña, chief risk officer at GCash, both put AI-enabled attacks on their shortlist of top threats, alongside ransomware, which is malware that locks up your files until you pay, and phishing, which is a fake message that tricks you into handing over your login.
What is new is not the trick. It is the volume and the polish. Encina said attackers are using AI because it multiplies how many people one scam can reach, and it cleans up the writing that used to give the scam away.
With AI, you can actually scale that up, take that victim count from 10 to 10,000. You can create better emails, get rid of all the grammatical errors that you see in phishing attacks. Jan Martin Encina, director of information security, Maya Philippines
Why it matters
For years the advice on how to spot a scam text was simple: look for the bad grammar, the weird spacing, the name spelled wrong. That tell is going away. A scam message written by AI can be clean, correctly worded, and personal enough to pass a quick glance on a crowded jeep. Beroña made the sharper point about where the attack actually lands. She said the use of AI in social engineering, meaning tricking a person rather than breaking a system, is a threat precisely because it targets the consumer, not the technology. Your e-wallet does not have to be hacked for you to lose money. You only have to be convinced.
The numbers make the exposure plain. Beroña said GCash serves over 94 million consumers, and she maintained the platform stays secure regardless of transaction volume. Encina said Maya has put technical safeguards in place, including multi-factor authentication, which is a second check on top of your password, and biometric login using your face or fingerprint. Maya also uses AI on its own side to spot unusual activity faster, and runs regular staff training on spotting phishing. Encina said Maya's own employees have been targeted by people trying to compromise their passwords and identities, so the training is not hypothetical.
The catch to watch
Neither executive said the attacks are getting fewer. Encina said these threats have stayed persistent for years, and the forecasts around them are grim: the cybersecurity firm Fortinet expects some 2026 attacks to be run by AI systems working without a human steering them, and the World Economic Forum projects the global cost of cybercrime will pass 23 trillion US dollars by 2027. Treat both as predictions, not measurements. The part worth sitting with is smaller and closer to home. Multi-factor authentication, biometrics, and anomaly detection all guard the door. None of them help if a very convincing message talks you into opening it and reading out the one-time PIN yourself. That is the gap AI is widening, and it is the one no app setting closes for you.