Cybercriminals operating in Malaysia have begun shifting their phishing campaigns away from traditional SMS channels to alternative messaging platforms, according to officials from the Malaysian Communications and Multimedia Commission. The migration follows enforcement of stricter regulations that prohibit telecommunications companies from transmitting hyperlinks through standard text messages, signalling an evolving cat-and-mouse game between scammers and regulators seeking to protect the public from fraud.
Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at the Selangor branch of MCMC, outlined the emerging threat during a panel discussion at the National Digital Scam Forum held in Petaling Jaya. He explained that Rich Communication Services—a more advanced texting protocol that sits between traditional SMS and full messaging apps—and Apple's iMessage platform have become the channels of choice for criminals attempting to circumvent newly implemented safeguards. Both services still permit the unrestricted transmission of hyperlinks, making them attractive vectors for delivering malicious content to unsuspecting users.
The problem extends beyond RCS and iMessage, however. Over-the-top messaging services including WhatsApp and Telegram have similarly become conduits for phishing operations. These platforms, which operate independently of traditional telecommunications networks, present particular enforcement challenges because they fall outside the direct regulatory authority that MCMC exercises over SMS channels. The prevalence of these applications across Malaysian mobile devices means millions of citizens remain vulnerable to carefully crafted fraudulent messages designed to steal financial credentials or personal information.
In response to the escalating threat, MCMC has signalled its intention to work directly with technology companies operating RCS, iMessage and other communication services to develop countermeasures comparable to those now restricting hyperlink transmission through SMS. This proactive engagement reflects the commission's understanding that regulatory frameworks must evolve in tandem with criminal methodologies. The approach acknowledges that unilateral action by a single regulator cannot adequately address threats propagated through platforms owned by multinational corporations with global operations and varying compliance obligations across different jurisdictions.
The blocking and takedown process deployed by MCMC demonstrates a multi-agency coordination model. When content suspected of containing fraudulent elements surfaces—whether involving unlicensed investment schemes or impersonation of legitimate financial institutions—MCMC verifies such allegations with relevant bodies before taking enforcement action. Investment-related fraud is referred to the Securities Commission Malaysia, while banking-sector scams are validated through Bank Negara Malaysia or affected financial institutions themselves. Only after verification do authorities proceed to block affected accounts, messaging channels, or services to prevent further dissemination.
Beyond hyperlink restrictions, scammers have adapted their methodologies in other sophisticated ways. Authorities have documented increasingly elaborate schemes targeting individuals to establish shell companies, which are subsequently utilised as conduits for mule account operations. These accounts serve as intermediaries in money laundering networks, receiving proceeds from fraud and transferring them onwards to conceal the criminal origin of funds. The involvement of unwitting company founders—often duped through promise of easy income or recruitment—adds layers of complexity to law enforcement investigations.
Digital banking platforms, which operate without physical branch networks, have become particular points of vulnerability in this ecosystem. Account opening processes relying on electronic Know Your Customer verification—which utilises facial recognition and identification document scanning—are theoretically designed to ensure that the person establishing an account is genuinely the individual presenting themselves. However, the speed and convenience of these digital processes, combined with potential gaps in verification protocols, have created opportunities for criminals to establish accounts in victims' names without their knowledge or consent.
Hasjun Hashim, representing Bank Negara Malaysia's LINK and Offices Department, advised the public to remain alert to such infiltration. She explained that individuals discovering unauthorised bank accounts opened in their names should immediately lodge formal complaints with the relevant financial institution. Each bank and insurance company maintains dedicated complaints units designed to investigate such breaches and potential misuse. The investigation into account opening procedures should reveal whether proper verification protocols were actually followed or whether systematic weaknesses were exploited.
For complainants who do not receive satisfactory resolution within fourteen days of submitting concerns to their bank, escalation to Bank Negara Malaysia represents the next formal step. This two-tier approach—initial complaint to the financial institution, followed by regulatory oversight if necessary—provides a structured mechanism for investigating fraudulent account openings and recovering compromised accounts. The existence of such protocols underscores the reality that while technological solutions offer important defences, they cannot entirely eliminate human vulnerability to sophisticated social engineering and fraud schemes.
The National Digital Scam Forum, convened alongside the Communications Ministry's 2026 National Anti-Scam Awareness Programme, brought together senior officials from the National Financial Crime Centre, Commercial Crime Investigation Department, Bank Negara Malaysia and MCMC. This coordinated approach reflects broader recognition that tackling financial fraud requires sustained cooperation across telecommunications regulators, financial sector supervisors, and law enforcement agencies. The forum served as a platform to align strategies and share intelligence about emerging threats and criminal methodologies.
For Malaysian consumers, the implications are sobering. The shift towards RCS, iMessage and messaging apps indicates that scammers will continue adapting faster than regulatory responses can be implemented. Users must exercise heightened vigilance when receiving unsolicited messages requesting personal information, directing them to click links or verify banking credentials. Similarly, approaches from unknown parties suggesting lucrative business opportunities—particularly those involving company formation—warrant extreme scepticism. The sophistication of current fraud operations demonstrates that technological literacy alone offers insufficient protection.
Regional observers should note that Malaysia's experience mirrors challenges faced across Southeast Asia, where rapid digital adoption has outpaced consumer awareness and regulatory evolution. The country's proactive engagement with platform providers to extend restrictions beyond SMS suggests a model that other regional governments might emulate. However, the fundamental tension remains unresolved: as regulators close one channel, criminals exploit alternatives. Meaningful progress requires sustained investment in public education, international cooperation with platform providers, and continuous evolution of regulatory frameworks.
