Fraudsters operating across Southeast Asia are abandoning traditional SMS channels and migrating their phishing operations to alternative messaging platforms including Rich Communication Services and Apple's iMessage, according to a warning issued by Malaysia's communications regulator. The tactical shift represents an adaptation to growing enforcement efforts that have made it harder for scammers to deploy malicious links through conventional text messages. Speaking at the National Digital Scam Forum in Petaling Jaya, Selangor MCMC Telecommunications Fraud deputy director Mohd Amirul Hakim Abdul Rahim outlined how the criminal ecosystem continues to evolve in response to regulatory pressure.
The Malaysian Communications and Multimedia Commission implemented strict directives requiring telecommunications providers to block hyperlinks, callback requests, and solicitations for personal information transmitted through official SMS channels. While effective in closing off one avenue for attackers, the measures have accelerated movement toward less-regulated messaging ecosystems. Over-the-top services including WhatsApp and Telegram have become secondary distribution channels, but RCS and iMessage present particular challenges because these platforms maintain full hyperlink functionality without the restrictions now standard on SMS networks. This migration reflects how scam operations maintain operational flexibility, quickly pivoting infrastructure when one delivery mechanism becomes too costly or risky to use.
The implications for Malaysian consumers are substantial. Many users may incorrectly assume that messages arriving through platforms like iMessage carry inherent security safeguards simply because they operate on encrypted or premium networks. In reality, verified phone numbers do not guarantee message authenticity, and professional phishing operations increasingly exploit the psychological advantage that legitimate-seeming communications channels provide. A message from what appears to be a banking app or government agency retains its persuasive power even when transmitted through channels users perceive as more secure or trustworthy than SMS.
Mohd Amirul indicated that the MCMC intends to initiate dialogue with RCS and iMessage providers to explore implementing comparable restrictions to those applied across SMS infrastructure. Such negotiations face inherent complexity given that these platforms operate across international boundaries and serve billions of users globally. Apple and Google maintain strict control over their respective ecosystems, which provides both advantages and complications for regulators seeking to impose regional restrictions. The process of aligning security frameworks across multiple platforms and jurisdictions typically requires months of coordinated effort, creating a window during which scammers can operate with relative impunity.
The regulatory response will also depend on how Malaysia balances consumer protection against the operational capabilities that businesses and individuals depend upon these platforms for. Excessive restrictions on hyperlinks could impair legitimate communications, affecting everything from banking notifications to e-commerce receipts. The MCMC's approach involves collaborating with financial institutions and law enforcement to verify suspected fraudulent content before implementing blocking measures. When content suggests illegal investment schemes or impersonation of financial entities, the commission coordinates with the Securities Commission Malaysia or Bank Negara Malaysia respectively. This tiered verification process aims to prevent false positives while targeting genuinely harmful material.
Mule account schemes represent an increasingly sophisticated component of scam operations, according to Bank Negara Malaysia representatives presenting at the forum. Criminal networks recruit individuals—often through social media or job advertisements—to establish company entities and open associated bank accounts that receive and quickly transfer stolen funds. By inserting legitimate company shells and actual registered directors into the process, scammers create an additional layer of obscurity that complicates law enforcement investigations. The tactics exploit the streamlined onboarding procedures that digital banks have implemented, which prioritize user convenience and speed over intensive manual verification.
Digital banks utilise electronic Know Your Customer processes relying on identification document verification and facial recognition technology. While these systems create audit trails and security mechanisms, they remain vulnerable to individuals who willingly participate in account opening under false pretenses. Victims of recruitment scams often do not realize they are enabling money laundering operations until months later when they attempt to access their own accounts or discover unexplained transfer activity. Bank Negara Malaysia deputy director Hasjun Hashim advised consumers who discover unauthorised account openings to immediately lodge formal complaints with their financial institutions, initiating investigations into how identity verification safeguards failed.
The institutional response framework provides consumers with escalation pathways when branch-level resolution proves insufficient. Banks and insurance companies maintain dedicated complaints units designed to handle cases that cannot be resolved at standard service points. If satisfaction does not arrive within 14 days, consumers may escalate matters directly to Bank Negara Malaysia, which maintains oversight authority across the financial system. This mechanism theoretically protects depositors, though in practice the speed of fraud execution often means that stolen funds have already moved through multiple accounts by the time detection occurs.
The broader context involves a recognition that scam operations have professionalized substantially over the past decade. What began as opportunistic email phishing has evolved into sophisticated criminal enterprises operating across multiple jurisdictions with specialized divisions handling everything from technical infrastructure to social engineering and money laundering. The National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil represents Malaysia's attempt to build coordinated defences involving telecommunications regulators, financial intelligence units, commercial crime investigators, and banking supervisors. Coordination across these agencies improves response times but cannot eliminate the fundamental asymmetry that attackers choose the timing and methods while defenders must anticipate threats across countless vectors.
For Malaysian consumers and businesses, the practical implication is that vigilance must extend across all messaging platforms rather than concentrating on traditionally risky channels. Requests for financial information, urgent account verification, or suspicious callback numbers remain red flags regardless of whether they arrive via SMS, WhatsApp, Telegram, iMessage, or RCS. Banking institutions have steadily increased customer education around authentication procedures and legitimate communication channels, yet social engineering techniques continue to improve. The most effective protection remains scepticism toward unexpected messages requesting sensitive information, combined with knowledge of how to independently verify communications by contacting institutions directly through official contact details.
