Phishing Attacks in Malaysia 2026: Trends, Examples and How to Stop Them

Phishing attacks in Malaysia are more sophisticated, more targeted, and more costly than at any point in the country’s digital history. In 2024, the Malaysian Communications and Multimedia Commission (MCMC) recorded over 5,000 phishing-related cybercrime reports, with financial losses across all scam categories surpassing RM 1 billion. In 2026, threat actors are no longer sending poorly-written mass emails — they are conducting patient, intelligence-led campaigns against Malaysian finance teams, C-suites, and government suppliers. This guide covers the current phishing threat landscape in Malaysia, real-world attack examples, the five red flags every employee must know, and the technical controls your organisation needs in place today.
The evolving phishing threat landscape in Malaysia
Malaysia’s rapid digitisation — driven by the MyDigital blueprint and the expansion of digital banking — has created a larger, more lucrative attack surface for phishing actors. The National Cyber Security Agency (NACSA) classifies phishing as one of the top three threats to Malaysian critical information infrastructure, alongside ransomware and supply chain attacks. Three attack variants dominate the 2026 landscape.
Spear-phishing: targeted, patient, and convincing
Unlike bulk phishing, spear-phishing targets a named individual using personalised context harvested from LinkedIn, company websites, and previous data breaches. A finance manager at a Malaysian logistics firm might receive an email appearing to come from their CEO, referencing an active tender — with a request to settle an “urgent supplier invoice” via a new bank account. The MITRE ATT&CK framework catalogues spear-phishing as technique T1566.001 and notes it as the most common initial access vector used by advanced persistent threat (APT) groups active in Southeast Asia.
QR code phishing (quishing): bypassing email gateways
QR code phishing — known as quishing — embeds malicious URLs inside QR code images rather than clickable text links. Because most enterprise email security gateways scan hyperlinks, not image content, quishing campaigns frequently bypass perimeter filters entirely. In 2025 and into 2026, Malaysian threat actors have deployed quishing via WhatsApp Business accounts, SMS, and physical printed materials placed at co-working spaces and bank branches. Victims who scan the code are directed to convincing replica login pages for Maybank2u, CIMB Clicks, or Office 365, where credentials are harvested in real time.
Business Email Compromise: the costliest variant
Business Email Compromise (BEC) is the highest-value phishing variant targeting Malaysia’s corporate sector. Attackers either compromise a legitimate email account through credential theft or spoof a trusted domain to send fraudulent payment instructions. A common BEC pattern observed in Malaysia involves a threat actor monitoring a supplier email thread for two to three weeks, identifying an upcoming invoice, then impersonating the supplier’s finance team with updated banking details days before payment is due. The FBI’s Internet Crime Complaint Center (IC3) estimates global BEC losses exceeded USD 2.9 billion in its most recent reporting year — and Malaysian businesses are an increasingly deliberate target given the volume of cross-border trade with Singapore, China, and the Middle East.
WhatsApp scams and the blurring of phishing channels
Malaysia has one of the highest WhatsApp penetration rates in Southeast Asia, which has made the platform a primary phishing delivery channel. Threat actors impersonate bank officers, LHDN (Inland Revenue Board) officials, PDRM, and even employer HR departments to deliver malicious links and request OTP codes. In 2025, MCMC issued multiple public advisories warning of WhatsApp accounts impersonating CIMB and Public Bank customer service lines, directing victims to credential-harvesting sites. The Personal Data Protection Act 2010 (PDPA) imposes obligations on organisations when customer data is compromised via such attacks — making staff awareness training a compliance requirement as well as a security one.
Organisations with customer-facing digital channels should consider brand protection services that monitor for impersonation of your domain, brand name, and executive identities across email, social media, and messaging platforms.
Five red flags every employee must know
Technical controls alone cannot stop phishing. Every employee — from the receptionist to the CFO — is a potential target. Train your team to pause and verify whenever any of the following five signals appear.
1. Urgency and pressure
Legitimate organisations do not demand immediate wire transfers, OTP submissions, or password resets within minutes. Any email or message creating artificial urgency — “Act now or your account will be suspended”, “Transfer must be completed by 3pm today” — should be treated as a phishing indicator. Verify through a separate, known communication channel before acting.
2. Mismatched sender domain
Hover over the sender’s email address and compare it carefully with the organisation’s real domain. Attackers register lookalike domains such as simplydata.com.my.support-portal.net or replace letters with visually similar characters (rn instead of m, 0 instead of o). One character difference is enough to fool a distracted reader.
3. Unexpected QR codes or shortened URLs
A QR code in an unsolicited email asking you to “verify your account” or “confirm a delivery” is a strong phishing signal in 2026. Use a URL preview tool or QR scanner that displays the destination link before opening it. Shortened URLs (bit.ly, tinyurl) in business emails are equally suspicious unless the sender is known and the context expected.
4. Requests for credentials or financial data
No legitimate bank, government agency, or IT department will ask you to submit your username, password, OTP, or banking credentials via email, WhatsApp, or SMS. NACSA, Bank Negara Malaysia, and MCMC have all published public statements to this effect. If an email requests this information, it is a phishing attempt.
5. Unusual attachment types or unexpected invoice changes
Be suspicious of attachments with double extensions (invoice.pdf.exe), macro-enabled Office documents from unknown senders, and any last-minute supplier request to change payment account details. BEC actors specifically time these requests to coincide with genuine invoice cycles — the change feels routine because the surrounding context is legitimate.
Technical controls: what your organisation must deploy
Employee awareness reduces risk but cannot eliminate it. A layered technical defence is essential for Malaysian organisations, particularly those subject to Bank Negara Malaysia’s Risk Management in Technology (RMiT) policy document.
Email authentication: SPF, DKIM, and DMARC
SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance) are the foundational technical controls for email phishing defence. SPF specifies which mail servers are authorised to send email on behalf of your domain. DKIM adds a cryptographic signature that receiving servers use to verify message integrity. DMARC instructs receiving servers what to do when SPF or DKIM checks fail — and critically, it delivers reports back to your security team showing who is attempting to spoof your domain. Organisations that have not set DMARC to p=reject are actively inviting domain spoofing. RMiT paragraph 11.17 expects financial institutions to implement email authentication as a baseline control.
Multi-Factor Authentication (MFA)
MFA remains the single most effective control for limiting the damage of a successful credential phish. Even when an attacker captures a valid username and password, MFA-protected accounts cannot be accessed without the second factor. Organisations should enforce MFA across all email accounts, VPN access, cloud applications, and administrative portals. Phishing-resistant MFA methods — FIDO2 hardware security keys and passkeys — are preferred over SMS OTP, which is itself vulnerable to SIM swap attacks that are increasingly common in Malaysia.
Email security gateway
A dedicated email security gateway (Microsoft Defender for Office 365, Proofpoint, or equivalent) provides anti-phishing heuristics, sandboxing of attachments, URL rewriting and time-of-click protection, and impersonation detection. Cloud-native gateways can now inspect QR code images to extract and scan the embedded URL — closing the quishing gap that basic filters miss. Integration with a managed Security Operations Centre (SOC) ensures that phishing alerts are triaged and responded to within minutes rather than days.
Phishing simulation and awareness training
Technical controls catch the majority of attacks — but not all. Controlled phishing simulation programmes send realistic (but harmless) phishing emails to employees, measure click rates, and feed results into targeted training. Organisations that run quarterly phishing simulations consistently demonstrate 60-70% reductions in employee click-through rates within 12 months. BNM RMiT and NACSA’s Cybersecurity Framework both reference security awareness training as a required control for regulated entities. Running a simulation before an attacker does is the most cost-effective risk reduction available to a Malaysian organisation today.
BNM RMiT expectations for financial institutions
Financial institutions regulated by Bank Negara Malaysia face the most prescriptive phishing-related obligations in Malaysia. RMiT requires boards and senior management to maintain oversight of technology risk, including phishing and social engineering threats. Specific expectations include documented evidence of periodic phishing simulation exercises, staff awareness training records, incident response procedures for email compromise events, and DMARC enforcement on all customer-facing domains. NACSA’s sector-specific advisories for banking, energy, and telecommunications also reference phishing simulation as a recommended practice under the National Cybersecurity Policy. Organisations that cannot demonstrate these controls face regulatory scrutiny during Bank Negara examinations and cybersecurity assessments.
For organisations building or reviewing their phishing defence posture, Simply Data offers phishing email simulation services designed specifically for the Malaysian regulatory environment — covering RMiT-aligned reporting, multilingual training content (English and Bahasa Malaysia), and integration with existing security awareness programmes.
Protect your organisation with Simply Data
Phishing attacks in Malaysia are not slowing down — they are becoming more targeted, more patient, and more financially damaging with every passing quarter. Waiting for an incident before investing in defence is no longer a viable strategy for Malaysian businesses operating under PDPA, RMiT, or NACSA’s national cybersecurity framework.
Simply Data works with Malaysian organisations across banking, healthcare, energy, and professional services to design and deliver phishing defence programmes that combine technical controls, employee simulation, and continuous threat monitoring. Our team holds international certifications in penetration testing, SOC operations, and cybersecurity risk management — and every engagement is grounded in the Malaysian regulatory landscape.
Start with a phishing email simulation to benchmark your organisation’s current exposure — and speak to our team about how managed detection through our Security Operations Centre can ensure every phishing attempt that slips past your filters is caught and contained before it becomes a breach.
Contact Simply Data today for a no-obligation consultation on phishing defence for your Malaysian organisation.
Frequently Asked Questions
What are the most common phishing attacks targeting Malaysian businesses in 2026?
The most common phishing attacks in Malaysia in 2026 include spear-phishing emails impersonating bank officers and government agencies, QR code phishing (quishing) delivered via WhatsApp and SMS, and Business Email Compromise (BEC) fraud targeting finance teams. MCMC reported over 5,000 phishing-related cybercrime cases in Malaysia in 2024, with losses exceeding RM 1 billion across all scam categories.
How does Business Email Compromise (BEC) work?
Business Email Compromise (BEC) is a sophisticated scam where attackers compromise or impersonate a legitimate business email account — typically a CEO, CFO, or trusted supplier — to trick employees into transferring funds or sharing sensitive data. Attackers often monitor email threads for weeks before striking, making the fraud convincing. Malaysian SMEs and corporates are increasingly targeted, with BEC now classified as a priority threat by NACSA.
What technical controls stop phishing emails from reaching employees?
The three foundational email security controls are SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance). Together they verify that inbound emails genuinely originate from the claimed domain. Layering an email security gateway (such as Proofpoint or Microsoft Defender for Office 365) and enforcing Multi-Factor Authentication (MFA) on all mailboxes significantly reduces phishing success rates.
Does BNM RMiT require banks to implement anti-phishing controls?
Yes. Bank Negara Malaysia Risk Management in Technology (RMiT) requires financial institutions to implement robust email authentication, security awareness training, and incident response procedures. Paragraph 11 of RMiT specifically addresses technology risk management, and regulators expect documented evidence of phishing simulation exercises, MFA deployment, and email filtering as part of annual technology risk assessments.
What is QR code phishing and how do I spot it?
QR code phishing, also called quishing, embeds a malicious URL inside a QR code image rather than a hyperlink. Because most email security gateways scan text links — not images — quishing bypasses traditional filters. Signs to watch for include unexpected QR codes in emails requesting urgent action, QR codes redirecting to non-official domains, and messages pressuring you to scan quickly. Always preview the URL before entering any credentials.
What should employees do if they receive a suspicious email?
Employees should not click any links, download attachments, or scan QR codes in suspicious emails. They should report the email immediately to their IT or security team using a designated phishing report button or email address. The email should be preserved as evidence and not forwarded. If credentials were entered on a suspected phishing site, passwords must be changed immediately and the IT team alerted so they can check for account compromise.


