Organised scam operations in Malaysia have begun exploiting alternative messaging channels to circumvent recent hyperlink restrictions imposed on traditional SMS, according to officials from the Malaysian Communications and Multimedia Commission. The shift represents an escalating cat-and-mouse dynamic between regulators and fraudsters seeking new avenues to deliver phishing content and lure unsuspecting victims into financial traps. Authorities detected the migration pattern following the enforcement of directives that banned telecommunications companies from transmitting hyperlinks, callback requests, and personal information requests through standard short messaging service, a measure designed to reduce one of the primary vectors for scam dissemination.
Mohd Amirul Hakim Abdul Rahim, deputy director of the Selangor MCMC's Telecommunications Fraud unit, disclosed these findings while speaking at Malaysia's National Digital Scam Forum, an event coordinated with Communications Minister Datuk Seri Fahmi Fadzil's 2026 National Anti-Scam Awareness Programme initiative. The comments underscored the adaptive nature of criminal syndicates operating across Southeast Asia, which continuously search for regulatory gaps to maintain their operations. Rather than abandoning their phishing infrastructure entirely, scammers have redirected their efforts toward messaging platforms that still permit hyperlink transmission, taking advantage of the looser regulatory oversight these services currently face in most jurisdictions.
Rich Communication Services, commonly known as RCS, and Apple's proprietary iMessage platform have become particularly attractive to fraudsters precisely because they preserve link-sharing functionality while operating outside the established SMS regulatory framework. Beyond these two services, phishing campaigns are also flowing through over-the-top messaging applications including WhatsApp and Telegram, which benefit from enormous user bases across the region and limited real-time content moderation in many instances. This diversification strategy allows scammers to reach multiple demographic segments simultaneously—from older users still gravitating toward iMessage to younger populations embedded in WhatsApp and Telegram ecosystems—maximising their potential victim pool while fragmenting detection efforts across multiple platforms.
The MCMC's response strategy involves proactive engagement with platform providers to negotiate implementation of comparable restrictions to those already mandated for SMS channels. Officials signalled intent to work collaboratively with RCS operators and Apple to explore technical and policy-based measures that would curtail hyperlink transmission for suspicious or unverified accounts. This approach mirrors the commission's existing protocol of coordinating with telecommunications carriers, but faces considerably greater complexity given the global, decentralised nature of many messaging platforms and the jurisdictional complications inherent in regulating private technology companies headquartered overseas.
Concurrently, the MCMC has established internal verification protocols for flagged content suspected of containing fraudulent elements, including illegal investment schemes or impersonation of legitimate financial institutions. When suspicious material surfaces, the commission cross-references it with relevant sector regulators before authorising blocking or removal action. Investment-fraud allegations are systematically forwarded to the Securities Commission Malaysia, while banking-related scams undergo verification with Bank Negara Malaysia or the implicated financial institutions themselves. This collaborative validation system aims to prevent false positives while ensuring that confirmed fraudulent channels—across messaging services, cellular networks, and SMS platforms—face swift interdiction to prevent further user exposure.
Parallel to the technical and regulatory dimensions of the scam problem, law enforcement has increasingly focused attention on the infrastructure underlying fraud operations, particularly the network of money mule accounts that facilitate the movement and concealment of stolen funds. Bank Negara Malaysia's LINK and Offices Department deputy director Hasjun Hashim highlighted a sophisticated social engineering tactic wherein scammers manipulate targets into establishing company entities and opening associated bank accounts, which are then repurposed for laundering criminal proceeds. This approach exploits victims' limited understanding of banking procedures and their vulnerability to authority figures who present themselves as representatives of official bodies or legitimate business opportunities.
The mule account problem has grown substantially across Malaysia and other Southeast Asian economies as transnational organised crime networks outsource their financial logistics to local participants, many of whom are unwitting accomplices. The mechanism typically involves recruitment of individuals through social media or messaging platforms, followed by instructions to establish companies and open digital bank accounts under their names. Perpetrators convince targets that they are participating in legitimate business ventures, employment opportunities, or investment schemes, when in reality the accounts serve as conduits for stolen funds derived from investment fraud, romance scams, phishing attacks, and other criminal activities. The deployment of digital banking platforms, which operate entirely online without physical branch presence, has inadvertently facilitated this abuse by creating a seamless account-opening process that criminals exploit at scale.
Bank Negara addressed the specific vulnerability of digital banking's electronic Know Your Customer verification system, which relies on identification documents and facial recognition to confirm applicant identity. While officials maintain that the e-KYC process itself contains stringent safeguards intended to verify that account applicants are genuine persons acting in their own interest, the system cannot prevent deliberate participation by individuals willing to establish accounts for criminal purposes. Victims who discover unauthorised accounts opened in their names are advised to lodge formal complaints with their respective banking institutions, triggering internal investigations into the account-opening workflow and potentially revealing systemic weaknesses or compromised verification data.
The regulatory and enforcement response also encompasses clear consumer escalation pathways for individuals dissatisfied with initial bank responses. Bank Negara stipulated that every financial institution and insurance company maintains dedicated complaints units designed to address grievances beyond the scope of branch-level resolution. Should a customer fail to receive satisfactory responses or experience undue delays exceeding fourteen days, the regulator itself provides a secondary avenue for complaint and investigation. This tiered approach reflects acknowledgment that financial institutions, despite substantial compliance investments, occasionally permit sophisticated fraud schemes to proceed undetected, necessitating independent regulatory oversight of customer complaints.
The convergence of messaging platform exploitation, money mule infrastructure, and digital banking vulnerabilities illustrates the comprehensive challenge confronting Malaysian financial crime prevention efforts. Scammers operate across multiple technical and social domains simultaneously—distributing phishing content through messaging services while recruiting money mule networks and targeting bank account opening procedures. Regulatory responses must therefore extend beyond individual platform controls to encompass coordination among telecommunications providers, technology companies, financial institutions, and law enforcement agencies. The 2026 National Anti-Scam Awareness Programme represents an effort to consolidate these disparate efforts into a coherent national strategy, though success will ultimately depend on sustained investment in detection capabilities, platform cooperation, and public education.
For Malaysian consumers and businesses navigating this deteriorating threat environment, vigilance must extend beyond recognising phishing links within SMS messages to encompassing scrutiny of messages arriving through alternative channels. Any unsolicited communications requesting personal financial information, urging account opening, or directing recipients to unfamiliar websites warrant immediate suspicion regardless of the transmission medium. Similarly, individuals approached regarding purported business or investment opportunities should independently verify any claimed affiliations before establishing accounts or providing identifying information. The sophistication and scale of contemporary scam operations suggests that traditional consumer caution will prove insufficient; meaningful protection increasingly requires collective action from regulators, platforms, and financial institutions operating in concert to disrupt criminal logistics networks and restrict fraudsters' capacity to reach and exploit vulnerable populations.
