Cybercriminals operating across Malaysia are adapting their tactics in response to regulatory crackdowns, migrating phishing operations from traditional SMS channels to newer messaging technologies including Rich Communication Services and Apple's iMessage platform. The shift represents a familiar pattern in the digital crime landscape, where fraudsters quickly exploit regulatory gaps to maintain their illicit activities, according to officials who outlined the threat during a national forum on digital scams held in Petaling Jaya this week.
The Malaysian Communications and Multimedia Commission has enforced strict directives preventing telecommunications providers from transmitting hyperlinks, callback requests, or personal information requests through official SMS channels. This measure was designed to eliminate one of the primary vectors through which organised crime syndicates disseminate phishing content to unsuspecting victims. However, rather than abandoning their operations, scammers have simply redirected their efforts toward alternative messaging platforms that currently lack equivalent restrictions.
Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at the Selangor MCMC office, disclosed that RCS and iMessage have become primary vehicles for phishing distribution following the SMS crackdown. Beyond these mainstream messaging services, criminals are simultaneously leveraging over-the-top platforms such as WhatsApp and Telegram to cast a wider net for potential victims. The adaptation demonstrates how regulatory responses targeting specific channels often produce a cat-and-mouse dynamic, where enforcement in one area simply redistributes criminal activity elsewhere rather than eliminating it entirely.
The MCMC has signalled its intention to proactively engage with platform providers of RCS, iMessage, and other messaging services to develop comparable safeguards to those implemented for SMS. This coordinated approach would extend the hyperlink restrictions and other protective measures across the entire messaging ecosystem, closing the gaps that criminals are now exploiting. However, the regulatory process involving private technology companies, particularly international platforms, presents considerable complexity given jurisdictional differences and the technical challenges of implementing uniform security standards across diverse systems.
Beyond blocking specific hyperlinks, the MCMC has established a verification protocol for flagging content suspected of containing fraudulent elements, including suspicious investment schemes and impersonation of financial institutions. When such content is detected, the commission coordinates with relevant regulatory bodies before taking enforcement action. Cases involving illegal investment schemes are referred to the Securities Commission Malaysia for assessment, while suspected banking fraud is verified in consultation with Bank Negara Malaysia and individual banking institutions. Only after confirmation that content is linked to actual fraudulent activity does the MCMC proceed with blocking or removal actions targeting the affected channels.
A parallel and increasingly sophisticated threat involves the creation of mule accounts, where scam syndicates deceive individuals into opening companies or bank accounts that are subsequently used to receive and launder stolen funds. Bank Negara Malaysia has warned that criminals are deliberately manipulating victims into establishing corporate entities under false pretences, then utilizing those entities to open accounts at digital banking platforms. The tactic exploits victims' trust and creates layers of legal and operational complexity that makes it more difficult for authorities to trace the ultimate beneficiaries of fraudulent transactions.
Digital banking platforms employ electronic Know Your Customer processes designed to verify applicant identity through identification documents and facial recognition technology. These e-KYC procedures are intended to ensure that the individual physically opening an account is genuinely that person, and the authentication requirements are meant to operate as a strict control mechanism. However, criminals have demonstrated sophistication in circumventing or manipulating these processes, sometimes coercing victims to complete verification procedures using their own identification while the scammers retain operational control of the accounts.
Individuals who suspect fraudulent account activity are advised to immediately lodge complaints with their financial institution to trigger investigation into how the account was opened and verified. Each bank and insurance company maintains dedicated complaints units specifically designed to handle disputes that cannot be resolved at branch or customer service centre level. Bank Negara Malaysia has stipulated that if a customer does not receive a satisfactory response or fails to obtain any response within fourteen days of filing a complaint with their bank, they may escalate the matter directly to the central bank for intervention and investigation.
The evolution of scam methodologies reflects broader patterns in digital crime where fraudsters rapidly adapt to enforcement actions by shifting toward less-regulated channels or platforms. Malaysia's approach of extending regulatory restrictions across multiple messaging platforms and enhancing coordination between the MCMC, Bank Negara Malaysia, the Securities Commission, and law enforcement agencies represents a more comprehensive strategy than targeting individual channels in isolation. However, the success of this coordinated approach depends significantly on the willingness and capacity of private technology companies to implement equivalent protective measures and the ability of regulators to maintain pace with criminal innovation in an increasingly fragmented digital communications landscape.
