Fraudsters operating across Southeast Asia are increasingly exploiting alternative messaging channels to circumvent telecommunications safeguards introduced to combat digital crime. The Malaysian Communications and Multimedia Commission (MCMC) has flagged a worrying trend of scammers migrating their phishing operations to Rich Communication Services (RCS) and Apple's iMessage platform, taking advantage of loopholes that remain open after the regulator successfully restricted hyperlinks through traditional short messaging service (SMS) networks.
The shift represents a classic cat-and-mouse dynamic between enforcement agencies and cybercriminals. As Mohd Amirul Hakim Abdul Rahim, deputy director of MCMC's Selangor Telecommunications Fraud unit, explained during the National Digital Scam Forum held in Petaling Jaya, scammers have simply relocated their operations to platforms that still permit the unrestricted transmission of suspicious links. This tactical repositioning underscores how quickly bad actors identify and exploit regulatory blind spots whenever one avenue of attack becomes restricted.
Widemouth adoption of over-the-top messaging services compounds the problem considerably. Beyond RCS and iMessage, criminals are weaponising WhatsApp and Telegram—platforms with hundreds of millions of Malaysian and regional users—to distribute phishing content at scale. These services offer scammers a degree of anonymity and reach that SMS networks, now fortified with hyperlink blocks, no longer provide. The transition also reflects broader consumer behaviour: as Malaysians increasingly shift away from traditional SMS toward data-driven messaging applications, fraudsters naturally follow their targets into these new digital spaces.
The MCMC's response centres on proactive engagement with platform providers to negotiate restrictions comparable to those already imposed on SMS. Officials are seeking to establish common standards across messaging ecosystems that would limit suspicious link transmission, mirroring the successful hyperlink prohibition framework already deployed at the telecommunications carrier level. However, negotiations with private technology firms—particularly international corporations like Apple and Google—involve significantly more complexity than directives to domestic telcos, introducing potential delays in implementation.
Parallel to restricting link distribution, Malaysian regulators have established a verification framework to address fraudulent content before it proliferates widely. When material suspected of containing scam elements emerges—whether investment fraud, financial institution impersonation, or other schemes—MCMC coordinates with relevant authorities before applying enforcement measures. The Securities Commission Malaysia handles investment-related cases, while Bank Negara Malaysia (BNM) manages matters involving banking fraud. This inter-agency coordination ensures blocking decisions rest on verified evidence rather than initial suspicion, balancing consumer protection with the need for due process.
Mule account schemes represent a particularly insidious evolution in Malaysian scam tactics. Perpetrators now routinely trick individuals into establishing shell companies or opening bank accounts under false pretences, creating a distributed network of accounts through which stolen funds are laundered. Hasjun Hashim, deputy director of BNM's LINK and Offices Department, highlighted this concerning development, noting that digital banks' streamlined account-opening processes—while convenient for legitimate customers—can be weaponised when victims are socially engineered into becoming unwitting accomplices.
The electronic Know Your Customer (e-KYC) verification system, designed to authenticate account applicants through identification documents and facial recognition, represents the primary technical barrier against such fraud. Yet the system's effectiveness depends entirely on the authenticity of documentation presented and the genuine consent of the person providing biometric data. Scammers circumvent these safeguards by coercing or deceiving victims into completing the e-KYC process themselves, effectively legitimising fraudulent account creation within the system's own parameters. This represents a fundamental challenge: no technology can reliably distinguish between authorised account opening and coerced account creation when a real person is providing genuine credentials.
For Malaysian consumers who discover unauthorised bank accounts opened in their names, BNM has established a complaints resolution framework. Individuals should immediately notify their bank and lodge formal complaints with the institution's dedicated complaints unit. Banks and insurance companies are required to investigate account-opening procedures, with 14 days serving as the expected response timeframe. Should initial complaint channels prove unresponsive or unsatisfactory, victims can escalate concerns directly to Bank Negara for independent review and intervention.
The broader strategic challenge facing Malaysian law enforcement and regulators lies in the fundamental asymmetry between defence and attack in digital spaces. Legitimate institutions must implement sophisticated verification systems, hyperlink restrictions, and inter-agency coordination—measures that burden ordinary customers while remaining imperfectly effective. Scammers, conversely, operate with minimal overhead, rapidly adapting their tactics whenever one avenue closes. The migration to RCS and iMessage exemplifies this dynamic: within weeks of SMS restrictions taking effect, criminals identified and began exploiting alternative channels.
This incident also illuminates the transnational dimension of digital fraud affecting Malaysia. Phishing operations targeting Malaysian consumers may originate from international criminal networks with minimal local presence, complicating jurisdictional enforcement. When scammers utilise cloud-based messaging platforms with servers spanning multiple countries, pursuit becomes exponentially more difficult. The 2026 National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil therefore rests partly on consumer education—empowering individuals to recognise suspicious communications regardless of the platform through which they arrive.
Moving forward, MCMC's negotiations with RCS, iMessage, and major OTT platforms will likely determine whether hyperlink restrictions can be meaningfully extended beyond the SMS ecosystem. Success would require these technology providers to implement sophisticated content detection and blocking mechanisms comparable to telecommunications carriers' existing systems. Failure to secure cooperation would leave scammers operating largely unimpeded through these channels, potentially rendering SMS restrictions merely an inconvenience rather than a meaningful defence. The resolution of these discussions will significantly shape Malaysia's capacity to protect consumers against evolving digital fraud threats in the coming years.
