Scammers Transition to RCS and iMessage for Phishing Amid SMS Link Ban

Selangor: Online scams have been detected shifting to messaging services such as Rich Communication Services (RCS) and iMessage to spread phishing links following the enforcement of hyperlink restrictions on short messaging service (SMS). Malaysian Communications and Multimedia Commission (MCMC) Telecommunications Fraud deputy director Mohd Amirul Hakim Abdul Rahim said the shift was detected as these messaging services still allowed the transmission of hyperlinks to users for phishing purposes.

According to BERNAMA News Agency, besides RCS and iMessage, phishing links are also being spread through over-the-top (OTT) services such as WhatsApp and Telegram. Mohd Amirul Hakim noted that for SMS, MCMC has enforced a directive for telecommunications companies prohibiting hyperlinks, requests to call back numbers, or requests for personal details through official SMS, prompting scammers to shift to RCS and iMessage. MCMC plans to engage with these platform providers to explore measures that can be implemented, including approaches similar to the SMS restrictions.

The comments were made during Mohd Amirul's appearance as a panellist at the 'National Digital Scam Forum: Threat to National Financial Security and Mule Accounts.' The forum was part of the 2026 National Anti-Scam Awareness Programme launched by Communications Minister Datuk Seri Fahmi Fadzil. Other panelists included National Financial Crime Centre (NFCC) director-general Datuk Seri Shamshun Baharin Mohd Jamil, Selangor Commercial Crime Investigation Department (CCID) chief SAC Mohamad Rosni Mohamed Lazim, and Bank Negara Malaysia (BNM) LINK and Offices Department (JLPB) deputy director Hasjun Hashim.

Mohd Amirul explained that for content suspected of containing fraudulent elements, such as illegal investments or impersonation of financial institutions, MCMC would verify it with relevant agencies before taking action to block or take down the content. Investment-related cases would be referred to the Securities Commission Malaysia (SC), while cases involving banking would be verified with BNM or the relevant banking institutions. If the content or account was confirmed to be linked to fraudulent activity, blocking action would be taken against the affected channels, including messaging, cellular, or SMS services, to prevent it from reaching users.

Meanwhile, Hasjun Hashim advised the public to remain vigilant against scam syndicates tricking individuals into opening companies as part of tactics related to mule accounts. She highlighted that opening an account online, particularly with digital banks, is subject to the electronic Know Your Customer (e-KYC) process to verify the applicant's identity using identification documents and facial recognition. Hasjun emphasized that this process is designed to ensure strict verification of the account opener's identity.

Hasjun also advised individuals who find that a bank account has been opened without their consent to lodge a complaint with the concerned bank to enable an investigation into the account opening process. She mentioned that every bank and insurance company has a dedicated complaints unit to handle unresolved cases. If there is no satisfactory response from the bank after 14 days, individuals can approach Bank Negara for further assistance.