Cybercriminals operating in Malaysia are increasingly turning to alternative messaging platforms to perpetuate phishing schemes, according to officials monitoring telecommunications fraud. The shift reflects a calculated response to regulatory measures that have successfully curtailed malicious activity through traditional SMS channels, creating a fresh challenge for authorities tasked with protecting consumers from financial fraud.

Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at the Malaysian Communications and Multimedia Commission (MCMC) Selangor office, highlighted the emerging threat during a national forum held in Petaling Jaya on August 20. The detection of fraudsters migrating to Rich Communication Services (RCS) and iMessage represents an adaptation to enforcement directives that prohibit telecommunications providers from transmitting hyperlinks, callback requests, or personal information solicitations through SMS channels. This regulatory success, while significant, has inadvertently motivated criminals to explore alternative digital pathways less encumbered by restrictions.

The problem extends beyond just RCS and iMessage. Over-the-top messaging platforms including WhatsApp and Telegram have simultaneously become vectors for phishing content distribution, creating a multi-front challenge for enforcement agencies. These services maintain substantially fewer barriers to hyperlink transmission than heavily regulated SMS infrastructure, offering scammers a more permissive environment in which to operate. The sophistication of such schemes has evolved considerably, with fraudsters refining their approach to target vulnerable users across multiple messaging ecosystems simultaneously.

The MCMC official articulated a forward-looking enforcement strategy when he disclosed that the commission intends to approach platform providers to negotiate implementation of measures analogous to those imposed on SMS services. Such engagement would likely focus on restricting suspicious hyperlinks, preventing unsolicited financial solicitations, and introducing content verification protocols. However, the complexity of coordinating with private technology companies operating across multiple jurisdictions presents considerable challenges, particularly when those firms prioritise user experience and platform openness as core business principles.

Content suspected of fraudulent characteristics undergoes a verification process before removal. When MCMC identifies material containing hallmarks of illegal investment schemes or impersonation of financial institutions, it works collaboratively with sectoral regulators to confirm whether fraudulent activity is actually occurring. The Securities Commission Malaysia handles investment-related complaints, whilst Bank Negara Malaysia and individual banking institutions verify allegations involving financial services. This coordinated approach aims to prevent false positives whilst ensuring genuine fraud is swiftly addressed through account blocking and content takedown actions targeting messaging channels and telecommunications services.

Parallel to these platform-level interventions, the National Financial Crime Centre director-general Datuk Seri Shamshun Baharin Mohd Jamil and other panellists addressed a concerning evolution in scam methodology. Perpetrators now exploit mule account schemes by manipulating victims into establishing companies and opening bank accounts on their behalf, typically through digital banking platforms. This layering technique obscures the criminal's identity whilst creating a legitimate-appearing financial infrastructure through which stolen funds can flow, effectively purchasing legitimacy using compromised personal information.

Hasjun Hashim, a Bank Negara Malaysia official, explained that digital banking account openings incorporate electronic Know Your Customer (e-KYC) verification procedures designed to authenticate applicant identity through identification documents and facial recognition technology. The security protocols are ostensibly stringent, requiring that the person opening the account is genuinely the account holder. Yet scammers circumvent these safeguards by coercing victims into completing the verification process themselves, effectively making victims complicit in their own financial victimisation whilst creating plausible deniability for the criminal beneficiaries.

Public awareness of account fraud remediation pathways remains inadequate. Citizens discovering that bank accounts have been opened without their knowledge or consent should immediately lodge complaints with their financial institution, initiating formal investigation into account opening procedures. Banks and insurance companies maintain dedicated complaints divisions to address cases beyond standard branch-level resolution capability. This escalation pathway, whilst established, remains underutilised by victims unfamiliar with their consumer protection rights.

The regulatory response framework includes temporal benchmarks designed to ensure timely resolution. If a complainant receives no satisfactory response from their bank within fourteen days, escalation to Bank Negara Malaysia becomes available. This formal process ensures that unresolved cases receive attention from the central banking authority, which maintains jurisdiction over banking sector compliance. However, the fourteen-day window creates a vulnerable period during which fraudsters may transfer or dissipate compromised funds, highlighting why prevention through platform-level controls remains preferable to post-facto investigation and recovery.

The forum, organised in conjunction with Communications Minister Datuk Seri Fahmi Fadzil's 2026 National Anti-Scam Awareness Programme, reflects governmental recognition that scam ecosystems operate dynamically, constantly adapting to new restrictions. The involvement of the National Financial Crime Centre, Selangor Commercial Crime Investigation Department, and Bank Negara Malaysia signifies whole-of-government coordination against financial fraud. Nonetheless, the lag between scammer innovation and regulatory response remains substantial, requiring sustained investment in platform engagement, investigative capacity, and public education to maintain protective effectiveness.

For Malaysian consumers and businesses, the expanding surface area of potential fraud delivery mechanisms underscores necessity for heightened vigilance across all digital communication channels. The migration from SMS to messaging applications may reduce visibility of scam attempts, as these platforms blend fraudulent messages with legitimate communications. Maintaining awareness of banking and investment sector best practices, resisting unsolicited requests for personal information regardless of platform, and understanding complaint escalation procedures represent fundamental defensive measures within an increasingly complex threat landscape.