Malaysian telecommunications regulators have detected a concerning adaptation in criminal tactics, with online scammers migrating from text messaging to alternative digital channels to continue launching phishing attacks. The shift comes in response to enforcement of hyperlink restrictions on SMS services, prompting authorities to broaden their defensive measures across multiple platforms. At the National Digital Scam Forum held in Petaling Jaya on August 20, the Malaysian Communications and Multimedia Commission revealed that Rich Communication Services (RCS) and iMessage have become favoured vectors for distributing malicious links to unsuspecting users.

Mohd Amirul Hakim Abdul Rahim, deputy director of telecommunications fraud at the Selangor MCMC office, explained that scammers have deliberately repositioned their operations toward messaging platforms that continue to permit hyperlink transmission. The regulatory body had previously issued directives to telecommunications providers nationwide, mandating the blocking of hyperlinks, callback number requests, and personal data solicitation through official SMS channels. This proactive measure succeeded in restricting one attack vector but inadvertently concentrated criminal attention on less-regulated alternatives. RCS, a next-generation messaging standard that enhances traditional SMS capabilities, and Apple's iMessage platform both remain comparatively permissive in their link policies, making them attractive targets for fraudsters seeking to maintain operational effectiveness.

Beyond proprietary messaging ecosystems, investigators have documented extensive use of over-the-top communication services including WhatsApp and Telegram as distribution channels for phishing campaigns. These globally-scaled platforms present particular enforcement challenges due to their decentralised architectures and encryption protocols. The proliferation across multiple channels underscores a fundamental shift in the sophistication of scam operations, moving away from reliance on any single communications method toward a diversified approach that maximises reach while complicating regulatory intervention. The flexibility of modern fraud syndicates demonstrates that blocking one avenue merely redirects criminal activity rather than eliminating underlying threats.

Responding to this evolutionary challenge, the MCMC has signalled its intention to engage directly with RCS and iMessage platform providers to explore implementation of equivalent safeguards. Mohd Amirul indicated that restrictions analogous to those successfully applied to SMS represent a realistic objective, requiring close cooperation with technology companies operating these services. However, such negotiations will likely prove more complex than previous telecommunications directives, given the international corporate structures and technical architectures governing these platforms. Apple's tightly-integrated ecosystem differs fundamentally from the standardised SMS framework previously regulated, and RCS operates within a competitive telecommunications landscape spanning multiple operators. The commission faces institutional challenges in extending its regulatory reach across platforms whose governance sits outside traditional telecommunications authority.

The forum, convened as part of the 2026 National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil, assembled key stakeholders from Malaysia's financial crime and cybersecurity apparatus. The National Financial Crime Centre, Selangor's Commercial Crime Investigation Department, and Bank Negara Malaysia representatives participated, reflecting recognition that scam prevention transcends any single regulatory domain. This institutional coordination suggests authorities understand that addressing sophisticated fraud requires integrated strategy spanning telecommunications, law enforcement, and financial oversight. The collaborative forum model recognises that information sharing and coordinated response mechanisms prove more effective than isolated regulatory interventions.

When content carries suspected fraudulent characteristics—including illicit investment schemes or impersonation of legitimate financial institutions—the MCMC conducts verification with relevant authorities before implementing blocking or removal actions. Investment-related cases route through the Securities Commission Malaysia, while banking fraud allegations receive verification from Bank Negara Malaysia and affected financial institutions. This tiered verification approach prevents overreach while ensuring legitimate blocking actions target genuine threats. Only after confirming fraudulent association does the MCMC proceed with infrastructure-level intervention, restricting access through messaging, cellular, or SMS services to prevent propagation. The procedural safeguard balances consumer protection against freedom of communication, maintaining proportionality in regulatory response.

Parallel to the messaging channel challenge, authorities highlighted an alarming trend involving mule account recruitment, where criminals manipulate individuals into establishing companies used for moving illicit funds. Bank Negara Malaysia's LINK and Offices Department deputy director Hasjun Hashim warned that sophisticated syndicates exploit legitimate digital banking infrastructure by convincing victims to open accounts under false pretences. The victims become unwitting participants in money laundering networks, their accounts serving as transaction nodes in larger criminal pipelines. This human engineering dimension demonstrates that technical security measures alone prove insufficient—criminal organisations succeed by exploiting psychological vulnerability and social trust alongside systematic weaknesses.

Digital banking institutions implement electronic Know Your Customer (e-KYC) procedures designed to establish applicant identity through documentation verification and facial recognition technology. These processes theoretically ensure that account openings involve authenticated individuals, creating an audit trail protecting against fraudulent account creation. However, criminals circumvent these safeguards through social engineering, convincing legitimate individuals to complete e-KYC processes on behalf of criminal enterprises. The distinction proves critical: the security technologies function as designed, but implementation depends on user cooperation. When victims complete authentication processes under deception, they inadvertently legitimise accounts intended for criminal use. This represents a vulnerability inherent to systems requiring human participation, difficult to address through technology alone.

Hasjun advised individuals discovering accounts opened without their knowledge or consent to immediately lodge formal complaints with affected banks, triggering investigations into account opening procedures. Every banking and insurance institution maintains dedicated complaints units designed to investigate cases escalated beyond branch resolution. The formal complaint process creates documented records and activates internal compliance reviews, potentially identifying systemic weaknesses enabling fraudulent accounts. However, institutional investigation timelines extend significantly beyond immediate consumer needs. Bank Negara Malaysia established a 14-day response threshold, after which unresolved complainants may escalate to the central bank for intervention. This escalation pathway provides recourse but places extended burden on defrauded individuals already experiencing financial disruption and identity compromise.

The migration of scam operations toward RCS, iMessage, and OTT platforms reveals adaptive criminal networks that quickly identify and exploit regulatory gaps. Malaysian authorities have moved decisively regarding SMS but face more complicated challenges engaging international platform providers and addressing social engineering tactics that leverage human psychology. The comprehensive forum approach suggests official recognition that scam prevention requires sustained coordination across telecommunications, financial, and law enforcement agencies. Yet the fundamental vulnerability remains: determined criminals will continuously adapt to regulatory measures by identifying less-protected communication channels and exploiting human trust. Meaningful progress likely demands not only enhanced platform controls but also sustained consumer education addressing psychological manipulation that enables mule account schemes and convinces individuals to participate unknowingly in fraud networks.