Cybercriminals operating across Malaysia are rapidly adapting their tactics in response to tightening security measures, pivoting away from traditional SMS channels to exploit messaging alternatives that remain largely unregulated. This evolution in attack strategy emerged during discussions at the National Digital Scam Forum held in Petaling Jaya, where regulators and financial crime specialists outlined mounting concerns over the sophistication and speed at which scam networks evolve to circumvent protective measures.
The Malaysian Communications and Multimedia Commission (MCMC) has successfully enforced restrictions that prevent telecommunications operators from transmitting hyperlinks, callback requests, and personal information solicitations through standard SMS services. However, this defensive success has inadvertently created a compliance vacuum in adjacent communication channels. According to Mohd Amirul Hakim Abdul Rahim, deputy director of Selangor MCMC's Telecommunications Fraud unit, scammers have methodically shifted their phishing infrastructure to Rich Communication Services (RCS) and iMessage, both of which continue permitting unrestricted hyperlink transmission without current regulatory intervention.
The technical architecture of RCS and iMessage presents a particularly attractive alternative for fraudulent actors. Unlike the legacy SMS protocol, these services operate with enhanced functionality that mirrors consumer expectations for modern messaging while simultaneously creating regulatory blind spots. The shift represents a calculated response to MCMC's hyperlink ban on SMS—a regulatory measure designed to reduce exposure to malicious links that typically redirect users to fake banking portals or credential-harvesting websites. By transitioning operations to these platforms, scammers maintain their core operational capability while evading the specific controls now monitoring traditional text messaging infrastructure.
Beyond RCS and iMessage, criminal networks continue leveraging over-the-top (OTT) messaging applications, with WhatsApp and Telegram serving as particularly effective distribution channels. These platforms combine several characteristics that appeal to sophisticated fraud operations: massive user bases across Malaysia and Southeast Asia, end-to-end encryption that complicates law enforcement monitoring, and minimal content verification mechanisms. The diversity of delivery mechanisms now employed by scam syndicates underscores a fundamental challenge facing regulatory agencies: enforcement capabilities have not kept pace with the proliferation of communication channels available to consumers and, consequently, to criminals seeking to exploit them.
In response to this emerging threat landscape, the MCMC has committed to proactive engagement with platform providers operating RCS and iMessage infrastructure. The regulatory approach contemplates measures comparable to those already deployed against SMS carriers, potentially including hyperlink restrictions, content verification protocols, or sender authentication requirements. However, the international nature of these platforms—particularly iMessage's integration within Apple's ecosystem and RCS's multiple carrier implementations—complicates unilateral Malaysian enforcement. Regulatory coordination across borders may prove necessary to implement effective safeguards without fragmenting the user experience across regional markets.
The forum, convened in conjunction with Communications Minister Datuk Seri Fahmi Fadzil's launch of the 2026 National Anti-Scam Awareness Programme, brought together representatives from the National Financial Crime Centre (NFCC), the Selangor Commercial Crime Investigation Department (CCID), and Bank Negara Malaysia (BNM). This multi-agency coordination reflects recognition that scam proliferation transcends the jurisdiction of any single regulator. The NFCC director-general Datuk Seri Shamshun Baharin Mohd Jamil and BNM's Hasjun Hashim contributed specialized perspectives on financial crime patterns and banking sector vulnerabilities respectively, establishing a framework for coordinated response to criminal adaptation.
MCMC's verification protocol for suspected fraudulent content demonstrates an evolved understanding that blocking mechanisms must be coupled with rapid intelligence-sharing between regulatory bodies. Investment-related fraud cases now flow to the Securities Commission Malaysia (SC), while banking-related content undergoes verification with BNM or affected institutions before enforcement action. This routing system, though administratively complex, enables regulators to distinguish between legitimate financial communications and sophisticated impersonation schemes. Once confirmed as fraudulent, blocking actions extend across messaging channels, cellular networks, and SMS infrastructure, creating layered barriers that impede message distribution at multiple points in the communication pathway.
The emergence of mule account recruitment represents a secondary dimension of criminal innovation that compounds vulnerability. Rather than directly operating fraudulent accounts themselves, sophisticated scam syndicates now employ deception tactics that manipulate victims into establishing legitimate company entities and associated bank accounts. Hasjun Hashim warned the public that this modus operandi exploits psychological manipulation—convincing individuals that opening accounts constitutes a normal or beneficial business activity. The technical reality differs markedly: digital banks implement electronic Know Your Customer (e-KYC) procedures involving identification document verification and facial recognition technology. These safeguards theoretically prevent unauthorized account creation, yet their effectiveness remains contingent upon actual enforcement rigor at the point of account opening.
The vulnerability in account opening procedures extends beyond technical verification to encompass institutional accountability. Individuals discovering unauthorized accounts opened in their names face a remediation pathway requiring lodge complaints directly with affected banks, triggering investigations into account opening processes and controls. Bank Negara has established escalation procedures whereby unsatisfactory or delayed responses from banks trigger regulatory intervention. This two-tier complaint mechanism—initial resolution at branch level, with BNM oversight if resolution exceeds 14 days—acknowledges that fraud discovery often occurs long after account creation, necessitating retrospective investigation and liability determination. However, the burden of detection and complaint initiation rests entirely with victims, potentially disadvantaging individuals with limited financial literacy or awareness of fraudulent account creation.
The convergence of these regulatory and criminal developments creates an unstable equilibrium characteristic of asymmetric technological competition. Regulators implement static controls addressing known attack vectors, while criminal networks deploy dynamic adaptation strategies that systematically exploit regulatory gaps in emerging platforms. This cycle suggests that sustained effectiveness requires not merely reactive blocking of specific channels but rather proactive engagement with platform architecture—encouraging development of fraud detection mechanisms native to RCS, iMessage, WhatsApp, and Telegram systems. Such cooperation demands regulatory leverage that may prove elusive given the international scale and commercial interests of technology providers.
For Malaysian consumers and businesses, the strategic implication emphasizes personal vigilance as a primary defense mechanism in an environment where institutional safeguards lag emerging criminal methodologies. Recognition that scammers systematically migrate to less-regulated channels should prompt heightened skepticism toward unsolicited links arriving through any messaging platform, regardless of apparent legitimacy. The proliferation of attack vectors—SMS alternatives, investment fraud, company registration exploitation, and account manipulation—reflects criminal sophistication that individual awareness campaigns alone cannot adequately address. Sustained effectiveness depends on regulatory agencies maintaining detection and response capabilities that match the speed and adaptability of the criminal enterprises they oppose, a challenge that may ultimately require structural transformation of how communication platforms implement fraud prevention at a fundamental architectural level.
