Skip to main content
Back to News
News

Cambodia’s New Anti-Scam Law Raises the Compliance Bar for Businesses

Cambodia’s new Law on Combating Technology-Based Scams creates specific offences covering online fraud, scam-centre management, recruitment, misuse of personal information and related money laundering. Legitimate businesses should now review how they manage tenants, employees, payments, customer data and third-party relationships.

Cambodia’s New Anti-Scam Law Raises the Compliance Bar for Businesses

Cambodia has introduced a dedicated legal framework to combat technology-based fraud and the criminal networks that support it.

The Law on Combating Technology-Based Scams was promulgated on April 6, 2026, and took effect the following day. It contains five chapters and 24 articles and creates five specific criminal offences: committing technology-based fraud, organising or leading an online scam centre, recruiting or training people to conduct scams, maliciously collecting personal identification information, and laundering proceeds connected to these activities.

Although the law is primarily directed at criminal operations, it also has practical implications for legitimate companies operating in Cambodia. Businesses may face greater scrutiny over who uses their properties, payment systems, communications services, employment channels and customer information.

Why the law matters to legitimate businesses

Technology-based scam operations rarely function in isolation. They can depend on rented buildings, company registrations, bank accounts, payment services, telecommunications infrastructure, recruitment advertisements and access to personal information.

This means businesses should consider whether existing controls are strong enough to identify suspicious customers, tenants, suppliers, employees or transactions before a serious problem develops.

The sectors most likely to require additional attention include:

  • Property and hospitality: Owners and managers should understand who is occupying their premises, the nature of the activities taking place and whether actual operations match the stated purpose of a lease.
  • Recruitment and employment services: Agencies should verify employers, job advertisements and working conditions, particularly when workers are recruited from abroad or transferred across borders.
  • Banking and payment services: Financial institutions and payment providers should remain alert to unusual transaction patterns, rapid movement of funds and accounts controlled by unidentified third parties.
  • Telecommunications and digital services: Providers may need stronger controls around bulk accounts, unusual device activity, identity verification and the misuse of communications platforms.
  • Businesses collecting personal data: Companies should limit unnecessary collection of passports, identification cards and customer records and ensure that access is properly controlled.

Practical steps companies can take

The new law does not mean that every business must redesign its compliance system. However, companies should review whether their current procedures reflect the risks associated with technology-enabled fraud.

Practical measures may include:

  • Verifying the identity, ownership and genuine business activities of higher-risk customers and counterparties.
  • Keeping clear records of leases, contracts, payments and authorised users of company services.
  • Reviewing unusual use of buildings, accounts, equipment or internet infrastructure.
  • Confirming that recruitment partners and job advertisements are legitimate.
  • Restricting employee access to customer identification documents and sensitive information.
  • Creating a clear internal process for reporting suspicious activity to senior management or qualified legal advisers.

Businesses should also avoid assuming that company registration documents alone provide sufficient assurance. Effective due diligence requires an understanding of who ultimately controls an organisation and what it is actually doing.

Investment confidence will depend on enforcement

The Cambodian government has presented the law as part of a broader effort to eliminate online scams, protect victims and restore confidence in Cambodia as a safe place to live, visit and invest.

For the private sector, the long-term impact will depend on consistent enforcement. Clear investigations, fair legal processes and action against both criminal operators and the businesses knowingly supporting them would help reduce reputational and counterparty risks across the wider economy.

Responsible companies can support this effort by treating fraud prevention as an operational responsibility rather than only a legal or public-relations issue.

Companies with exposure to higher-risk transactions, property arrangements, recruitment activity or personal data should seek advice from qualified Cambodian legal counsel when reviewing their obligations under the new law.