Cybercriminals operating in Malaysia are rapidly adapting their tactics to circumvent newly tightened regulations, with documented evidence showing a shift towards alternative messaging platforms in the wake of stricter controls on traditional SMS channels. The Malaysian Communications and Multimedia Commission disclosed this concerning trend at a major anti-scam conference in Petaling Jaya, revealing that fraudsters have identified and begun exploiting loopholes in less-regulated communication systems to maintain their phishing operations despite enforcement measures designed to protect consumers.
Mohd Amirul Hakim Abdul Rahim, deputy director of Selangor MCMC's Telecommunications Fraud division, explained the mechanics of this criminal migration during his remarks as a panellist at the National Digital Scam Forum. After Malaysian telecommunications providers implemented directives prohibiting hyperlinks, callback number requests, and personal information solicitations through official SMS channels, scammers simply relocated their activities to platforms that currently lack equivalent restrictions. This regulatory arbitrage demonstrates how criminal enterprises continuously hunt for weaknesses in the security infrastructure, particularly targeting channels that occupy a middle ground between mainstream social media and traditional SMS services.
Rich Communication Services and Apple's iMessage represent particularly attractive alternatives for fraudsters because they retain the legitimate functionality of transmitting clickable links while operating under less stringent oversight compared to SMS. Unlike short message services, which are heavily monitored and subject to specific prohibitions, these platforms were designed for seamless link sharing and remain largely unencumbered by the same anti-fraud protocols. The shift underscores a fundamental challenge in cybersecurity: criminals operate with entrepreneurial flexibility, quickly abandoning compromised channels and finding refuge in emerging technologies that regulators have yet to fully address.
Beyond RCS and iMessage, phishing campaigns are flourishing across over-the-top messaging applications, with WhatsApp and Telegram serving as particularly effective distribution networks for malicious content. These platforms attract fraudsters because they combine user ubiquity with functional ambiguity—they appear legitimate and trustworthy to ordinary users, yet provide criminals with anonymity and difficulty in attribution. For Malaysian consumers who increasingly rely on these messaging services for daily communication, this convergence creates a deceptive landscape where the distinction between trusted contacts and sophisticated impersonators grows ever more blurred.
The MCMC's response involves proactive engagement with platform providers to develop and implement containment measures modelled on the approach taken with SMS. Mohd Amirul indicated that the commission plans to work directly with RCS operators and Apple to explore technical and operational restrictions that could parallel SMS safeguards without compromising legitimate functionality. This collaborative approach recognises that regulatory mandates alone prove insufficient; platform providers must be enlisted as partners in defending against evolving criminal techniques. However, the feasibility of applying SMS-style restrictions to more sophisticated messaging ecosystems presents technical and commercial complications that may slow implementation.
Content verification procedures form another critical layer in the MCMC's defensive strategy. When material suspected of containing fraudulent elements—such as counterfeit investment opportunities or impersonations of licensed financial institutions—is identified, the commission coordinates with sectoral regulators before taking enforcement action. Investment-related scams undergo scrutiny by the Securities Commission Malaysia, while banking-related fraud is verified in consultation with Bank Negara Malaysia and relevant financial institutions. This multi-agency coordination ensures that blocking decisions rest on substantiated evidence rather than algorithmic flags, reducing the risk of overzealous takedowns that might inadvertently suppress legitimate content.
Once fraud allegations receive confirmation through this verification process, the MCMC executes blocking measures against affected messaging channels, cellular networks, and SMS services to prevent fraudulent messages from reaching potential victims. The comprehensiveness of these interventions reflects the understanding that stopping scams requires intervention across the entire transmission infrastructure rather than reliance on end-user vigilance alone. Yet the arms race dynamic remains evident: as traditional SMS becomes inhospitable to fraud, criminals simply migrate to less-monitored alternatives, creating a perpetual cat-and-mouse dynamic that regulators struggle to outpace.
A particularly insidious variant of fraud increasingly targeting Malaysians involves the creation of shell companies and mule accounts used to launder illicit proceeds. Hasjun Hashim, deputy director of Bank Negara's LINK and Offices Department, cautioned the public against schemes whereby scammers manipulate victims into establishing companies ostensibly for legitimate purposes but actually to facilitate money laundering. This tactic exploits the general availability of online company registration and the lower initial scrutiny applied to newly formed entities, allowing criminals to create apparently legitimate corporate structures through which to channel fraudulent gains.
Digital banks have become particularly attractive targets for this fraud variant because their entirely online operational model theoretically reduces the identity verification friction that brick-and-mortar institutions impose. However, Hasjun emphasised that digital banking platforms maintain rigorous electronic Know Your Customer protocols employing identification documents and facial recognition technology to confirm applicant identities. These e-KYC systems, despite their automation, are designed to be difficult to circumvent; they serve as gatekeepers intended to prevent unauthorised account opening. Sophisticated fraudsters nonetheless occasionally succeed by obtaining victims' identity documents through deception or coercion, then using them in conjunction with spoofed facial recognition to establish accounts without the rightful owner's knowledge or consent.
Individuals who discover unauthorised bank accounts opened in their names face a structured complaint escalation process designed to facilitate investigation and remediation. Hasjun advised victims to immediately contact their financial institution's dedicated complaints unit, which exists specifically to handle matters unresolved at branch level. Should a bank fail to respond adequately within fourteen days or provide unsatisfactory resolution, complainants may escalate their case directly to Bank Negara Malaysia, which wields regulatory authority to compel financial institutions to investigate account opening irregularities and restore victim funds where fraud is confirmed. This framework acknowledges that while technological safeguards provide important baseline protection, human fallibility and sophisticated social engineering sometimes penetrate even well-designed systems, necessitating robust post-incident response mechanisms.
The National Digital Scam Forum, convened in conjunction with Communications Minister Datuk Seri Fahmi Fadzil's launch of the 2026 National Anti-Scam Awareness Programme, assembled Malaysia's primary anti-fraud authorities including the National Financial Crime Centre and Selangor's Commercial Crime Investigation Department. This coordination reflects official recognition that digital scamming has become a national security concern with cascading effects on financial stability and public confidence in digital systems. The intensity of government attention to fraud prevention suggests policymakers increasingly appreciate that consumer protection in digital channels requires not merely individual vigilance but systemic coordination among regulators, financial institutions, and platform providers operating within a coherent strategic framework.
