Malaysia

Phishing simulation for Malaysia’s
bank, courier and e-wallet lures.

In Malaysia, many scams start with an SMS: a bank alert about a new device, a courier asking for a handling fee, or an e-wallet reward about to expire, followed by a phone call or WhatsApp chat.

Regulators & frameworks
BNM RMiT (November 2025), Cyber Security Act 2024, PDPA as amended in 2024
Channels to rehearse
SMS, WhatsApp, voice calls, email and Teams
Local lure patterns
Bank device alerts, courier handling fees, e-wallet rewards
KeenSec evidence
Simulation results, reporter logs, certificates, policy acknowledgements

Simulated Malaysian lures

Banks, parcels and e-wallets:
the pretexts to rehearse.

Simulated examples of the bank, courier and e-wallet texts Malaysians see every week, rewritten with generic senders.

Simulated example
SMS

Courier desk

Parcel on hold

Your parcel could not be delivered. Pay the handling fee to reschedule: redeliver-now.example

  • Small fee, card details
  • Parcel you didn’t order
Simulated example
WhatsApp

“E-wallet support” · unknown number

Reward expiring tonight

You have unclaimed e-wallet credit expiring at midnight. Log in here to claim it: ewallet-rewards.example

  • Free money deadline
  • Wallet login by link

Regulators and frameworks

The Malaysian frameworks
your evidence supports.

FrameworkApplies toKeenSec evidence
BNM RMiT (28 November 2025)Financial institutions regulated by Bank Negara MalaysiaS 15.1: awareness education at least annually, with measured effectiveness; S 11.16: annual cyber drill, for example social engineering
PDPA 2010, as amended in 2024Organisations processing personal data in commercial transactionsBreach notification to the Commissioner within 72 hours since 1 June 2025; data-handling training and policy acknowledgements
Cyber Security Act 2024 (Act 854)National critical information infrastructure entitiesIncident notice within 6 hours; sector codes of practice set awareness duties
ISO/IEC 27001:2022Organisations certified or certifyingEvidence for the awareness, education and training control

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

Questions buyers ask

Frequently asked questions.

Which Malaysian frameworks does KeenSec help with?

KeenSec helps produce awareness evidence for BNM RMiT, the Cyber Security Act 2024, the amended PDPA and ISO/IEC 27001:2022. Your auditor decides compliance.

Can we simulate bank and courier SMS scams?

Yes. KeenSec runs bank-alert and courier-fee SMS scenarios with generic senders and .example links, each followed by a just-in-time lesson.

Can we include e-wallet lures?

Yes. AI Studio drafts e-wallet reward and account-verification scenarios for review, for SMS, WhatsApp or email.

Let’s connect the dots

Rehearse Malaysia’s real lures.
Keep the proof.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo