Fraudsters in Malaysia are adapting their tactics by exploiting messaging platforms such as Rich Communication Services (RCS) and iMessage to distribute phishing links, according to officials addressing the ongoing battle against digital scams. The strategic pivot comes after authorities implemented strict controls on traditional SMS channels, effectively blocking hyperlinks, callback requests, and personal information harvesting through conventional text messages. The shift highlights how criminal networks continuously evolve their methods to evade regulatory safeguards, creating fresh challenges for communications regulators and financial institutions tasked with protecting consumers.
Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at the Malaysian Communications and Multimedia Commission (MCMC) in Selangor, disclosed the emerging threat while addressing panellists at the National Digital Scam Forum held in Petaling Jaya. He explained that having successfully closed off the SMS avenue through industry directives that prohibit telecommunications operators from transmitting hyperlinks and solicitation messages via text, scammers have redirected their efforts toward alternative platforms that still permit such transmissions. The mobility of phishing campaigns demonstrates the adaptive nature of organised fraud operations, which treat regulatory interventions as operational obstacles to overcome rather than definitive barriers.
Beyond RCS and iMessage, over-the-top messaging services including WhatsApp and Telegram have become primary conduits for phishing operations. These platforms, which operate on internet protocols rather than traditional telecom networks, fall into a regulatory grey zone that makes coordinated enforcement more complex. Each platform operates under different jurisdictions and corporate policies, requiring individualised engagement strategies rather than a single regulatory approach. The proliferation of channels through which scammers operate underscores the asymmetry in digital fraud prevention, where criminals can shift tactics rapidly while authorities must navigate multiple regulatory frameworks and corporate partnerships.
Recognising the limitation of SMS-only restrictions, MCMC has signalled its intention to approach RCS and iMessage operators directly to negotiate enhanced security measures analogous to those already imposed on traditional messaging. Mohd Amirul indicated that the regulator would work collaboratively with platform providers to develop and implement comparable hyperlink restrictions and content validation protocols. This proactive stance reflects the reality that regulatory bodies cannot unilaterally control private messaging platforms; instead, they must leverage influence through partnerships and formal engagement. The success of such negotiations will significantly determine whether phishing actors are merely relocated to harder-to-monitor channels or genuinely constrained in their operational capacity.
The coordination required to address digital scams extends beyond telecommunications regulators. MCMC has established protocols to collaborate with specialised agencies depending on the nature of suspected fraudulent content. Investment-related scams are referred to the Securities Commission Malaysia (SC) for verification and appropriate regulatory action, while banking-sector fraud is escalated to Bank Negara Malaysia (BNM) or relevant financial institutions. This multi-agency framework recognises that phishing frequently targets specific sectors with tailored messaging, requiring domain expertise to evaluate authenticity and determine appropriate takedown procedures. Once fraudulent activity is confirmed through these interagency channels, MCMC can authorise blocking actions against messaging services, cellular networks, or SMS systems to prevent further dissemination.
The National Digital Scam Forum, held in conjunction with the 2026 National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil, brought together leaders from key institutions addressing fraud comprehensively. Participants included the National Financial Crime Centre (NFCC) represented by director-general Datuk Seri Shamshun Baharin Mohd Jamil, the Selangor Commercial Crime Investigation Department (CCID) under SAC Mohamad Rosni Mohamed Lazim, and BNM's LINK and Offices Department (JLPB) represented by deputy director Hasjun Hashim. This gathering reflected the complex, multi-stakeholder nature of anti-fraud efforts in Malaysia, requiring coordination between telecommunications authorities, law enforcement, financial regulators, and financial crime specialists.
A particularly insidious trend highlighted during the forum involves scammers manipulating victims into establishing companies as part of schemes to create fraudulent mule accounts. This social engineering approach exploits victims' trust and limited financial literacy, coercing them into becoming unwitting accomplices in money laundering operations. Hasjun Hashim cautioned the public against this tactic, noting that sophisticated criminal syndicates now target individuals by instructing them to register businesses or open bank accounts that can be used to funnel illicit proceeds. The modus operandi represents an escalation in complexity, moving beyond simple phishing to establishing structural fraud networks where victims themselves become implicated in the criminal ecosystem.
To counteract such schemes, financial institutions have implemented electronic Know Your Customer (e-KYC) protocols that deploy facial recognition technology and identification document verification during online account opening. These measures are designed to ensure that the person opening an account is genuinely the individual identified in supporting documents, creating a digital audit trail that theoretically prevents unauthorised account creation. However, Hasjun acknowledged that criminals continue to find workarounds, including coercing victims to participate directly in the e-KYC process. She emphasised that individuals discovering unauthorised accounts opened in their names should immediately lodge formal complaints with their respective banks to initiate investigations into potential breaches of account opening procedures.
For Malaysian consumers facing suspected fraud or account misuse, BNM has established formal grievance mechanisms designed to ensure accountability and timely resolution. Banks and insurance companies maintain dedicated complaints units that handle matters escalating beyond branch-level resolution. If a customer receives no satisfactory response within 14 days of lodging a complaint, they may escalate the matter directly to BNM for intervention. This tiered complaint structure provides consumers with recourse pathways and ensures that financial institutions maintain compliance with customer protection standards. Understanding these mechanisms is crucial for Malaysians seeking redress when they become victims of scam-related account misuse.
The evolution of scam tactics from SMS to RCS, iMessage, and OTT platforms reflects a deeper challenge in digital security governance: the inherent difficulty of regulating technologies that were never designed with fraud prevention as a primary consideration. As messaging platforms proliferate and criminals demonstrate remarkable agility in adopting new channels, Malaysian authorities face the ongoing task of remaining strategically ahead of fraudsters while respecting legitimate privacy interests and the operational independence of private technology platforms. The effectiveness of future anti-scam efforts will depend substantially on whether regulatory bodies can establish sufficiently rapid mechanisms to identify emerging threats, coordinate response across multiple stakeholders, and implement countermeasures before criminal networks achieve operational maturity in new channels.
