Scammers operating across Malaysia are actively relocating their phishing operations to alternative messaging platforms after telecommunications regulators successfully clamped down on hyperlink distribution through traditional SMS channels. The Malaysian Communications and Multimedia Commission (MCMC) disclosed this concerning shift during the National Digital Scam Forum held in Petaling Jaya on August 20, where industry officials and enforcement representatives convened to address the escalating threat posed by organised fraud networks to Malaysia's financial stability and citizen security.
Mohd Amirul Hakim Abdul Rahim, deputy director of the Selangor MCMC's Telecommunications Fraud division, explained that the regulatory environment has fundamentally changed for SMS-based attack vectors. Following enforcement of directives that prohibit telecommunications companies from transmitting hyperlinks, callback requests, or personal data solicitations via official SMS channels, criminal syndicates have adapted their strategies with surprising agility. Rather than abandoning phishing campaigns, they have identified and migrated toward messaging services that remain relatively unregulated, particularly Rich Communication Services (RCS) and Apple's iMessage platform, which continue to permit unrestricted hyperlink sharing.
The problem extends well beyond proprietary messaging protocols. Criminals are simultaneously leveraging over-the-top services such as WhatsApp and Telegram, which offer encryption, larger user bases, and greater difficulty for authorities to monitor systematically. This multi-platform approach creates a fragmented enforcement challenge, as no single regulatory intervention can address the entire attack surface. The sophistication of this migration reveals that organised fraud operations maintain sufficient technical capacity and market intelligence to identify regulatory gaps and exploit them rapidly before countermeasures can be implemented.
The MCMC has signalled its intent to address this emerging threat vector by engaging directly with RCS and iMessage platform providers to negotiate restrictions mirroring those applied to SMS. However, the regulatory complexity of such negotiations differs significantly from the SMS case, where MCMC could mandate compliance from domestic telecommunications operators. RCS involves multiple international carriers, while iMessage remains controlled by Apple—a foreign technology corporation with limited vulnerability to Malaysian regulatory pressure. These structural obstacles suggest that platform-level restrictions will prove more challenging to implement than their SMS predecessors, potentially extending the window during which criminals can operate without constraint.
When fraudulent content is identified, the MCMC has established a verification protocol involving multiple government agencies depending on the nature of the suspected scam. Investment-related schemes are referred to the Securities Commission Malaysia for assessment, while cases involving banking fraud are coordinated with Bank Negara Malaysia or directly with affected financial institutions. Only after verification of fraudulent intent does the MCMC proceed with blocking or removal actions targeting the compromised channels—a measured approach that balances the need for swift intervention against the risk of censoring legitimate content. This multi-agency coordination represents a more sophisticated fraud response infrastructure than existed in previous years, though questions remain about whether response times keep pace with criminal innovation.
A particularly troubling development emerging from enforcement discussions involves the weaponisation of company formation processes against unsuspecting individuals. Fraud syndicates are actively recruiting victims—often through social engineering—to establish legitimate business entities that subsequently serve as conduits for money laundering and mule account schemes. The tactics exploit gaps in digital banking onboarding procedures, specifically leveraging the electronic Know Your Customer (e-KYC) authentication process. Victims are deceived into completing account applications themselves, thereby satisfying identity verification requirements while legally establishing accounts that the syndicates subsequently control.
Hasjun Hashim, deputy director of Bank Negara Malaysia's LINK and Offices Department, emphasised that e-KYC procedures employ facial recognition and identification document verification specifically to prevent account fraud. However, criminals have effectively circumvented this safeguard by involving the victim themselves in the account opening process, thereby making it appear legitimate. The deception operates at the social engineering rather than technical level—victims are convinced that opening a company account for seemingly beneficial purposes like investment opportunities or quick income schemes, only to discover later that the account has been compromised and utilised for illicit fund transfers.
The divergence between technical security measures and social engineering vulnerability reveals a systemic weakness in Malaysia's fraud prevention architecture. Banks have implemented sophisticated biometric and cryptographic authentication systems, yet remain vulnerable to attacks that target human judgment rather than technological defences. This asymmetry suggests that future anti-scam initiatives must place greater emphasis on victim awareness and education rather than relying exclusively on technological hardening.
Institutions have established formal complaint mechanisms to address instances where accounts are opened fraudulently or without proper consent. Bank Negara Malaysia has mandated that every bank and insurance company maintain dedicated complaints units capable of investigating account opening irregularities. If victims identify unauthorised accounts bearing their identification, they should lodge formal complaints with the relevant institution immediately. The bank is obligated to investigate the account opening process and respond within fourteen days. Should a victim find the bank's response unsatisfactory or incomplete after this period, escalation to Bank Negara Malaysia itself provides an additional recourse mechanism.
The National Digital Scam Forum was convened as part of the 2026 National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil, signalling political commitment to addressing organised fraud at the highest levels. The forum assembled representatives from the MCMC, the National Financial Crime Centre, Selangor's Commercial Crime Investigation Department, and Bank Negara Malaysia, indicating a whole-of-government approach to the problem. This coordination infrastructure has evolved considerably, yet the fundamental challenge remains: scammers operate with greater speed and flexibility than regulatory bodies can match, and they continuously identify and exploit emerging vulnerabilities before defences can be established.
For Malaysian consumers and businesses, the emerging threat landscape demands heightened vigilance across multiple communication channels. The days when SMS served as the primary vector for phishing attacks are ending, replaced by a more distributed attack surface spanning messaging apps and platforms that remain beyond effective regulatory oversight. Citizens should assume that any unsolicited message requesting personal information, offering investment opportunities, or requesting account verification via hyperlink should be treated with extreme suspicion, regardless of the platform through which it arrives. Verification through official banking or investment channels rather than links provided in messages remains the most reliable defence against increasingly sophisticated phishing campaigns.
