Independent Outside-In Case · Trust & Safety · Reader Edition
Public platform materials, national enforcement and survey data, documented incidents, comparative product patterns, and product hypotheses. This case does not describe Zalo's internal systems, establish wrongdoing, provide legal advice, or guarantee fund recovery.
#Decision at a glance
Mission. Help people see and act on safety evidence forming inside a Zalo conversation before social trust becomes an irreversible payment—and preserve one connected recovery case if harm occurs.
Ownership. Zalo owns the safety explanation and evidence continuity. Zalopay owns payment-specific evidence, controls, and transaction execution. Support, banks, and authorities own downstream actions within their authority.
Core hypothesis. Source-aware evidence plus an independent next action will outperform a generic warning without creating unacceptable harm to legitimate users.
#1. Why the intervention begins in conversation
Scams that lead to a transfer often begin as conversations, not transactions. An account creates familiarity or authority; messages build pressure; then a link, QR code, file, phone number, credential request, or payment instruction moves the user toward action. By the payment confirmation screen, much of the evidence explaining the risk remains behind in the chat.
Zalo already occupies the start of that pathway. Its public safety surfaces include suspected scam-link warnings, account reporting, account-security guidance, and education on impersonation and account takeover. Zalopay supports transfers inside Zalo chat. The opportunity is not another isolated warning—it is continuity across those moments.
The evidence establishes urgency and real pathways, not a Zalo-specific scam rate. VNG reported 81.3 million monthly active Zalo users and 2.2 billion messages per day in the first half of 2026. Vietnamese authorities reported more than 6,000 online scam-related cases detected in 2024 with losses above VND 12 trillion, while a separate large survey estimated VND 18.9 trillion in losses. These figures describe different universes and must not be combined.
#2. Product thesis
Zalo Scam Emergency Mode should be a conversation-safety and evidence-continuity layer, not a payment-only warning.
When meaningful evidence appears, Zalo should show a compact, source-aware explanation without turning uncertainty into an accusation. If payment starts in Zalopay, the minimum relevant context should remain visible while Zalopay adds payment-specific evidence and applies its own controls. If harm has already occurred, the same pathway should preserve the original records, report, current owner, and next protective action.
The value is not a more dramatic risk score. It is a more complete decision and recovery pathway.
#3. The product experience
- Open chat — Safety Context Card. Explain why the conversation may require verification and offer four bounded actions: view evidence, verify safely, block or report, or continue with safety context when payment is relevant.
- View evidence — Evidence Map. Show what happened, where the signal came from, its status and time, what remains unknown, and the action it supports. Do not collapse unlike evidence into one unexplained score.
- Verify safely. Suggest an independent action appropriate to the scenario: call through a previously verified number, compare a known payment destination, open an official channel independently, stop sharing credentials, or report the account or object.
- Start payment — Zalo-to-Zalopay handoff. Carry only the minimum decision-relevant context. Zalopay adds recipient, destination, transaction-history, identity-consistency, and available-control states under its own authority.
- After action — Emergency Mode. Preserve originals first, connect the chat and payment evidence, identify the accepted owner, and make the next protective action visible without promising recovery.
#Evidence language is part of the product
| Status | User-facing meaning |
|---|---|
| Observed by platform | The event or object exists; intent may still be unknown. |
| Reported | A concern exists but has not been confirmed. |
| Pattern detected | A model or rule found a relevant pattern; review context rather than treating it as fact. |
| Confirmed unsafe | An authorized process established the unsafe status of a specific object or event. |
| Matched / mismatch / unable to verify | A bounded comparison was made; the product should explain the result without exposing unnecessary identity data. |
| Unknown | The platform cannot establish the fact; independent verification may be required. |
Every displayed item needs a source, timestamp or validity period, status, relevance to the current decision, correction or expiry rule, and a proportionate next action.
#4. Ownership must survive the handoff
The experience crosses products, but ownership cannot disappear between them.
| Stage | Decision owner | Required output |
|---|---|---|
| Conversation evidence | Zalo Safety Product / Trust & Safety | An explainable evidence state and user action. |
| Payment decision | Zalopay risk and payment operations | Payment-specific evidence and governed control. |
| Cross-product incident | Zalo Scam Mode journey owner | One visible case status and next action. |
| External action | Bank or authority | A verified contact route and reference where available; no promised outcome. |
| Correction or appeal | Owner of the disputed status | A review result propagated to dependent warnings and case states. |
No handoff is complete until the next owner has the evidence needed to act, accepts responsibility, and exposes a status the user can understand.
#5. AI can connect evidence; it should not become the evidence
AI can detect patterns developing over time, connect relevant account, conversation, object, and payment references, translate mixed signals into concise explanations, recommend the next safe action, and structure an incident summary while preserving the original records.
It should not declare a person fraudulent from a model score, convert report volume into fact, expose protected security or reporter data, generate a permanent reputation label, replace payment policy or human adjudication, rewrite originals, or promise recovery.
Conversation-level protection also does not require an all-or-nothing privacy choice. Candidate approaches include user-invoked analysis, bounded rules, high-risk-object analysis, or on-device processing for selected patterns. The lawful purpose, necessity, retention, user expectation, explainability, and operating accountability still require internal review.
#6. Recovery is a case, not a checklist alone
After suspected harm, the first principle is to preserve the original conversation, unsafe object, payment receipt, user report, and relevant account or security events. A generated summary can help navigation, but it must not replace the original evidence.
The user should see what has been preserved, what remains missing, who owns the next action, the verified route to the relevant provider, and what the platform cannot control. Zalo can preserve continuity even when a bank or authority owns the downstream decision.
#7. Recommended first version
The first version should test one coherent and bounded pathway:
- A conversation contains a confirmed unsafe object or a user invokes Check this chat.
- Zalo shows the Safety Context Card and a five-item Evidence Map.
- The product recommends one independent verification action.
- If payment starts in Zalopay, the unresolved context remains visible.
- If the user reports harm, one case preserves the original chat and payment evidence.
- One owner accepts the next action and exposes a visible status.
The north-star outcome is correct protective action before irreversible harm. Supporting measures include evidence comprehension, correct next-action rate, harmful continuation, independent verification, time to protective action, evidence completeness, accepted handoffs, repeat-explanation rate, time to a named owner, and legitimate-interruption or false-warning guardrails.
The concept should be narrowed, redesigned, or stopped if the Evidence Map does not outperform a concise generic warning; users repeatedly misread detections as confirmed fraud; privacy or data-sharing cannot be justified; legitimate interruption outweighs safety value; the Zalo–Zalopay handoff cannot preserve useful context; correction and appeal states cannot be maintained; or users still have to reconstruct the case manually.
#Evidence boundary
Public evidence establishes scale, urgency, and documented pathways. It does not establish which internal signals Zalo or Zalopay retain, whether those signals can be combined lawfully, model precision, a Zalo-specific scam denominator, technical feasibility, or the final ownership model. Every proposed signal remains a candidate evidence source until validated internally.
#Related work
Zalopay for SMEs: When “Paid” Does Not Mean “Done” examines transaction state and operational closure. Explainable Trust explores source-linked case reconstruction and correction.