Fraud syndicates have begun circumventing Malaysia's hyperlink restrictions on short messaging services by redirecting their phishing campaigns through alternative messaging platforms, according to officials at a national digital scam forum in Petaling Jaya. The tactical shift reveals how quickly organised scammers adapt their methods when one avenue of attack is blocked, presenting fresh challenges for regulators seeking to protect consumers in an increasingly digital financial ecosystem.
Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at the Selangor Malaysian Communications and Multimedia Commission, disclosed that scammers are now weaponising Rich Communication Services (RCS) and iMessage as primary distribution channels for fraudulent links after telecommunications companies implemented the MCMC's directive prohibiting hyperlinks, callback requests, and personal information solicitations via standard SMS. The observation surfaced during a panel discussion at the National Digital Scam Forum: Threat to National Financial Security and Mule Accounts, an event convened as part of Communications Minister Datuk Seri Fahmi Fadzil's 2026 National Anti-Scam Awareness Programme.
The evolution of scam tactics underscores a persistent problem in Malaysia's digital security landscape: messaging platforms remain fragmented in their approach to fraud prevention, creating gaps that criminals exploit. While RCS and iMessage represent newer messaging technologies that carriers and device manufacturers promote as more secure and feature-rich alternatives to SMS, their regulatory framework lags substantially behind traditional channels. The absence of coordinated hyperlink controls across these platforms has inadvertently created a refuge for phishing operations, allowing scammers to maintain campaign momentum despite SMS-level restrictions.
Beyond RCS and iMessage, law enforcement and financial regulators report that over-the-top messaging services including WhatsApp and Telegram have become entrenched as distribution networks for phishing campaigns. These applications, which operate independently of telecommunications carriers and employ end-to-end encryption, present particular enforcement challenges. Their decentralised architecture and the sheer volume of daily communications make real-time detection and intervention substantially more difficult than traditional SMS monitoring, where carriers maintain network-level visibility and control.
Responding to the emerging threat, the MCMC signalled intent to engage directly with RCS and iMessage platform providers to develop countermeasures comparable to those imposed on SMS. Mohd Amirul indicated that discussions would explore technical and procedural restrictions that might curtail hyperlink transmission for phishing purposes, though the complexity of coordinating across multiple private technology companies and international platforms presents considerable diplomatic and technical obstacles. The approach mirrors broader regulatory efforts to impose consistent safety standards across disparate digital communications channels, a challenge that has vexed regulators globally.
The MCMC's content verification process represents a parallel enforcement track, wherein suspected fraudulent content—including illegal investment schemes and impersonation of licensed financial institutions—undergoes cross-agency validation before removal. Investment-related fraud is referred to the Securities Commission Malaysia for assessment, while banking fraud allegations are verified with Bank Negara Malaysia or affected institutions directly. Once fraudulent linkage is confirmed, blocking actions target the affected messaging channels, cellular networks, or SMS services to interrupt scammer reach. This coordinated approach attempts to leverage sectoral expertise while maintaining proportionate enforcement, though gaps persist when fraudulent operations span multiple regulatory domains.
A complementary threat that emerged during the forum centres on mule account recruitment, wherein scammers deceive individuals into establishing companies or opening bank accounts that become conduits for laundered proceeds. Bank Negara Malaysia's LINK and Offices Department deputy director Hasjun Hashim cautioned the public that digital banks' online account opening procedures, while convenient, include electronic Know Your Customer (e-KYC) verification processes designed to confirm applicant identity through identification documents and facial recognition. The modus operandi increasingly involves tricking victims into opening corporate entities, with scammers then leveraging these structures to establish accounts that appear legitimate to regulators but are actually controlled by criminal syndicates.
Hasjun emphasised that individuals discovering unauthorised bank accounts opened in their names or without their presence should immediately lodge formal complaints with their financial institutions. Each bank and insurance company maintains dedicated complaints units equipped to investigate account opening irregularities, escalating cases that cannot be resolved at branch level. Critically, consumers possess formal recourse pathways: if a bank fails to provide satisfactory resolution or does not respond within 14 days, complainants may escalate matters to Bank Negara Malaysia for independent review and intervention.
The scammer migration to RCS, iMessage, and OTT platforms reflects an uncomfortable reality facing Malaysian financial regulators: technological infrastructure designed for consumer convenience frequently outpaces the policy frameworks governing its security. As digital communication channels proliferate and consumers adopt multiple messaging platforms, the attack surface expands faster than regulatory capacity to defend it. The coordinated response involving MCMC, Bank Negara Malaysia, the Securities Commission, and law enforcement agencies represents Malaysia's attempt at comprehensive digital fraud defence, yet success ultimately depends on sustained technology platform cooperation, consumer vigilance, and rapid regulatory adaptation.
For Malaysian financial consumers, the implications are sobering. The shift from SMS-based phishing to more sophisticated channels suggests that fraudsters possess technical sophistication and operational flexibility that outstrip current preventive measures. While hyperlink restrictions on SMS represented a meaningful friction point for criminal operations, it merely redirected rather than eliminated the underlying threat. Moving forward, the efficacy of anti-scam defences will hinge less on blocking individual channels and more on cultivating consumer scepticism toward unsolicited financial communications regardless of platform, combined with institutional responses that treat fraud allegations with appropriate urgency and transparency.
