Fraudsters operating across Malaysia are strategically migrating their phishing campaigns away from traditional SMS channels toward messaging platforms including RCS and iMessage, according to findings presented at a national digital scam forum in Petaling Jaya. The shift represents an adaptive response to enforcement measures implemented by the Malaysian Communications and Multimedia Commission (MCMC), which has successfully restricted hyperlinks and suspicious requests in standard SMS messages through directives issued to telecommunications providers.

Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at MCMC's Selangor office, revealed during the National Digital Scam Forum that scammers have systematically repositioned their operations toward messaging services that continue permitting link transmission. The detection of this tactical pivot underscores how organised criminal networks respond with agility to regulatory interventions, seeking new vectors for distributing malicious content to unsuspecting victims.

Beyond RCS and iMessage, over-the-top messaging platforms such as WhatsApp and Telegram have also emerged as preferred channels for spreading phishing links. These services, which operate across multiple jurisdictions and employ end-to-end encryption, present particular challenges for regional law enforcement agencies seeking to intercept fraudulent communications. The diversity of available messaging platforms means scammers can distribute phishing attempts across multiple channels simultaneously, increasing the likelihood of reaching vulnerable targets.

MCMC's response involves proactive engagement with platform operators to explore implementation of similar restrictive measures applied to SMS. The commission recognises that technological adaptation by scammers requires corresponding evolution in regulatory frameworks and platform-level controls. Discussions are underway to establish protocols whereby messaging service providers can limit hyperlink transmission or implement additional verification steps before allowing suspicious links to reach end users.

The MCMC has developed a structured verification process for content suspected of containing fraudulent elements, including schemes promoting illegal investments or impersonating financial institutions. Investment-related frauds are referred to the Securities Commission Malaysia for assessment, while cases involving banking institutions are coordinated with Bank Negara Malaysia or the relevant banking entity. This inter-agency coordination ensures that blocking actions target confirmed fraudulent channels across messaging, cellular, and SMS services before malicious content reaches the broader public.

Mule account schemes represent a particularly concerning evolution in scam tactics, with criminals increasingly coercing individuals into establishing companies and related banking infrastructure to facilitate money laundering. The National Financial Crime Centre and Bank Negara Malaysia have observed that scammers now specifically recruit victims to open company entities, exploiting the legitimate process of digital bank account opening. This approach leverages the convenience of electronic Know Your Customer verification, which relies on identification documents and facial recognition technology, as unwitting accomplices facilitate criminal financial flows.

Bank Negara Malaysia has emphasised that the e-KYC process, while designed to ensure account applicants are legitimate account holders, remains vulnerable when individuals are coerced into opening accounts without their knowledge or consent. Hasjun Hashim, deputy director of Bank Negara's LINK and Offices Department, advised the public to remain vigilant against social engineering tactics that manipulate people into unknowingly establishing accounts. Every banking and financial institution maintains dedicated complaint units designed to investigate unauthorised account openings and assist victims in reclaiming control over compromised financial infrastructure.

Victims discovering unauthorised accounts opened in their names should immediately lodge formal complaints with the relevant financial institution. Banks and insurers are required to investigate account opening procedures to determine whether identity verification protocols were properly enforced. The 14-day response timeline established for customer complaints provides a critical window for initial investigation and resolution at the institutional level before escalation to Bank Negara Malaysia becomes necessary.

The proliferation of scam techniques across multiple messaging platforms and the increasing sophistication of mule account schemes suggest that Malaysian authorities face a continuously evolving threat landscape. The forum, held in conjunction with the 2026 National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil, brought together representatives from MCMC, the National Financial Crime Centre, Selangor Commercial Crime Investigation Department, and Bank Negara Malaysia to coordinate anti-fraud efforts.

This multi-agency approach reflects recognition that no single regulatory body or platform operator can effectively combat digital fraud in isolation. Scammers exploit fragmented oversight across different communication channels and financial institutions, requiring integrated responses that span telecommunications regulation, financial surveillance, and criminal investigation. The challenge for Malaysian regulators involves implementing controls stringent enough to prevent fraud without restricting legitimate communication and commerce across messaging platforms increasingly central to daily business and personal interactions.

Looking forward, the shifting threat landscape will likely prompt technology companies and regulators to develop more sophisticated filtering mechanisms and verification protocols. Malaysia's experience with SMS hyperlink restrictions demonstrates that enforcement measures do work—they simply redirect criminal activity toward less-regulated channels. Staying ahead of this adaptive threat requires sustained cooperation between government agencies, platform operators, and the financial sector, supported by public education programs that help citizens recognise and report emerging scam tactics before falling victim.