Phishing links in Malaysia often imitate banks, LHDN, JPJ, PDRM, Pos Malaysia, Shopee and Touch 'n Go.
Warning signs
- The link arrives by SMS, WhatsApp or Telegram from an unknown number and creates urgency ("account suspended", "claim refund today").
- Short links (bit.ly, s.id, cutt.ly) hide the destination.
- The domain contains a brand but is not the official one, e.g.
maybank2u-secure.xyzinstead ofmaybank2u.com.my. - The page asks for your IC number, online-banking password, TAC / OTP or card CVV. Banks never ask for these by message.
Check it
- Copy the link (long-press → copy). Do not open it.
- Paste it into the Scam Checker or the URL Analyzer. Our server visits it for you and shows the full redirect chain, the domain age, the hosting country and a risk score.
- Look up the domain owner and abuse contact with the Domain / IP Lookup.
Report
- National Scam Response Centre: 997 (immediately, if money was transferred).
- Check bank accounts and phone numbers on PDRM Semak Mule.
- Report phishing sites to the bank concerned and to MCMC.