Malaysia
Phishing simulation for Malaysia’s
bank, courier and e-wallet lures.
In Malaysia, many scams start with an SMS: a bank alert about a new device, a courier asking for a handling fee, or an e-wallet reward about to expire, followed by a phone call or WhatsApp chat.
- Regulators & frameworks
- BNM RMiT (November 2025), Cyber Security Act 2024, PDPA as amended in 2024
- Channels to rehearse
- SMS, WhatsApp, voice calls, email and Teams
- Local lure patterns
- Bank device alerts, courier handling fees, e-wallet rewards
- KeenSec evidence
- Simulation results, reporter logs, certificates, policy acknowledgements
Simulated Malaysian lures
Banks, parcels and e-wallets:
the pretexts to rehearse.
Simulated examples of the bank, courier and e-wallet texts Malaysians see every week, rewritten with generic senders.
Courier desk
Parcel on hold
Your parcel could not be delivered. Pay the handling fee to reschedule: redeliver-now.example
- Small fee, card details
- Parcel you didn’t order
“E-wallet support” · unknown number
Reward expiring tonight
You have unclaimed e-wallet credit expiring at midnight. Log in here to claim it: ewallet-rewards.example
- Free money deadline
- Wallet login by link
Regulators and frameworks
The Malaysian frameworks
your evidence supports.
| Framework | Applies to | KeenSec evidence |
|---|---|---|
| BNM RMiT (28 November 2025) | Financial institutions regulated by Bank Negara Malaysia | S 15.1: awareness education at least annually, with measured effectiveness; S 11.16: annual cyber drill, for example social engineering |
| PDPA 2010, as amended in 2024 | Organisations processing personal data in commercial transactions | Breach notification to the Commissioner within 72 hours since 1 June 2025; data-handling training and policy acknowledgements |
| Cyber Security Act 2024 (Act 854) | National critical information infrastructure entities | Incident notice within 6 hours; sector codes of practice set awareness duties |
| ISO/IEC 27001:2022 | Organisations certified or certifying | Evidence for the awareness, education and training control |
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
Questions buyers ask
Frequently asked questions.
Which Malaysian frameworks does KeenSec help with?
KeenSec helps produce awareness evidence for BNM RMiT, the Cyber Security Act 2024, the amended PDPA and ISO/IEC 27001:2022. Your auditor decides compliance.
Can we simulate bank and courier SMS scams?
Yes. KeenSec runs bank-alert and courier-fee SMS scenarios with generic senders and .example links, each followed by a just-in-time lesson.
Can we include e-wallet lures?
Yes. AI Studio drafts e-wallet reward and account-verification scenarios for review, for SMS, WhatsApp or email.
Let’s connect the dots
Rehearse Malaysia’s real lures.
Keep the proof.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo