Fraudsters operating across Malaysia are adapting their tactics by switching to newer messaging platforms including Rich Communication Services and iMessage to circumvent tightening regulations on traditional SMS channels. The shift represents a significant challenge for law enforcement and communications regulators, who are now racing to close emerging vulnerabilities before scam networks can fully entrench themselves in alternative messaging ecosystems.
The migration was highlighted at the National Digital Scam Forum held in Petaling Jaya on August 20, where senior officials from the Malaysian Communications and Multimedia Commission detailed the evolving threat landscape. Mohd Amirul Hakim Abdul Rahim, deputy director of Telecommunications Fraud at MCMC's Selangor office, explained that criminal networks have actively exploited the regulatory gap left by SMS restrictions. After the commission mandated that telecommunications carriers block hyperlinks, callbacks, and personal data requests through official SMS channels, perpetrators began systematically routing phishing campaigns through less-regulated platforms.
The problem extends beyond just RCS and iMessage. Over-the-top messaging services, particularly WhatsApp and Telegram, have become equally attractive conduits for phishing operations. These platforms offer criminals significant advantages: they operate across multiple jurisdictions with fragmented regulatory oversight, they provide end-to-end encryption that complicates law enforcement investigation, and they maintain user bases in the hundreds of millions. The breadth of potential targets and the technical complexity of enforcement create a daunting scenario for Malaysian authorities attempting to protect consumers from increasingly sophisticated scam operations.
In response, MCMC is pursuing a proactive engagement strategy with platform providers to implement controls analogous to those imposed on traditional SMS. The commission plans to work directly with RCS operators, Apple's iMessage division, and other major messaging platforms to establish similar hyperlink restrictions and content verification protocols. This represents a significant escalation in regulatory intervention, moving beyond the telecommunications sector into the technology giants that dominate global messaging infrastructure. The approach reflects growing recognition that fragmented regulation across different communication channels simply displaces rather than deters fraud.
Parallel to technical interventions, Malaysian authorities are implementing content verification procedures that categorise fraud by type and route cases to appropriate regulatory bodies. The Securities Commission Malaysia receives referrals of suspected investment scams, while Bank Negara Malaysia handles cases involving banking impersonation. Once relevant agencies confirm fraudulent activity, MCMC escalates to blocking action against affected accounts and channels, attempting to sever the scammers' connection to potential victims. This multi-agency approach acknowledges that modern fraud requires coordination across financial, telecommunications, and law enforcement domains.
The banking sector faces particular pressure as criminal syndicates evolve their mule account recruitment tactics. Bank Negara's LINK and Offices Department highlighted a troubling trend in which victims are manipulated into establishing shell companies and opening corporate bank accounts ostensibly for legitimate business purposes. Digital banks, which lack physical branches and operate primarily through online channels, have become preferred targets because their streamlined account opening processes, while incorporating electronic Know Your Customer verification with facial recognition technology, can still be compromised when criminals obtain and leverage stolen identity documents.
The sophistication of these attacks underscores a fundamental vulnerability in the account opening ecosystem. While e-KYC processes are designed to confirm that an applicant is genuinely the person represented by their identity documents, they cannot detect scenarios where criminals have obtained legitimate identification through theft, extortion, or purchase on underground markets. Bank Negara Malaysia officials emphasised that individuals discovering unauthorised accounts opened in their names should immediately lodge formal complaints with their financial institutions, initiating investigation into how the account opening process was breached.
The escalating fraud crisis has prompted Malaysian authorities to strengthen the post-complaint resolution pathway. Bank Negara has implemented a fourteen-day service standard for initial responses to consumer complaints, with an avenue for escalation to the central bank if institutions fail to provide satisfactory resolution within this timeframe. This mechanism acknowledges that individual branch staff may lack authority to investigate systemic account opening breaches, necessitating centralised oversight. The framework also applies to insurance companies, broadening the protective net beyond banking alone.
Communications Minister Datuk Seri Fahmi Fadzil's decision to launch the 2026 National Anti-Scam Awareness Programme signals commitment to addressing the issue through public education alongside regulatory enforcement. The forum itself, bringing together the MCMC, National Financial Crime Centre, the Selangor Commercial Crime Investigation Department, and Bank Negara, represents an attempt to coordinate fragmented agencies operating within overlapping jurisdictions. However, the rapid migration of scam networks to new platforms suggests that technical measures and awareness campaigns must be implemented simultaneously to have meaningful effect.
For Malaysian consumers and businesses, the current period represents heightened vulnerability as regulatory frameworks lag behind criminal innovation. The shift to RCS and iMessage demonstrates that scammers will exploit any gap in oversight, making sustained vigilance essential. Individuals should exercise extreme caution with unsolicited messages requesting links to financial platforms, personal details, or urgent action on account matters, regardless of the messaging service used. Similarly, business owners and executives should be alert to social engineering attempts targeting corporate bank account creation, which has emerged as a primary vector for mule account recruitment.
