Cyber999 Advisories

1 December 2024     Alert

MA-1212.122024: MyCERT Alert - Resurface of Scam Calls Impersonating CyberSecurity Malaysia and Several Malaysia Law Enforcement Agencies


1.0 Introduction
Lately, the Cyber999 Incident Response Centre of CyberSecurity Malaysia has been observing rising of several calls to users' mobile numbers, purportedly from CyberSecurity Malaysia or Cyber999 and other agencies, such as Kementerian Komunikasi, Malaysian Communications and Multimedia Commissions (MCMC), National Scam Response Center (NSRC), Ibu Pejabat Polis Daerah (IPD) Penang or Perlis and Kementerian Komunikasi (KKD) saying that they are going to terminate users’ phone number due to receive several cases from different state that involving illegal activities. 

2.0 Impact
Personal information obtained from individuals could be misused by perpetrators for various malicious activities, for instance, impersonation via telephone calls, purportedly from government officials or the Law Enforcement Agency (LEA). The modus operandi of the scam call is to create panic among potential victims and force victims to follow the order of the scammer to obtain/harvest personal details.

3.0 Modus Operandi
The calls were received from personal mobile numbers, not toll-free numbers or from businesses/organisations. The caller claimed to be from a Law Enforcement Officer (LEO) and accused the user’s mobile number of engaging in illegal activities, such as promoting online gambling, participating in illegal investments, or being involved in scams.

Users are pressured to lodge a police report within an unreasonably short time frame, often as little as two hours. They are directed to a distance police station, making it practically impossible for the victim to comply. Users may be offered assistance or encouraged to use the scammer's system to facilitate the reporting process, adding an additional layer of deceit. We assume that the system or link or application from the scammer could be malicious and harmful to users if they click on it. Users are being threatened with legal consequences, such as being arrested or having their phone number blocked, to scare them into doing what they are told to do.

The true intention behind these calls remains uncertain at present. However, there is a risk of irresponsible individuals exploiting user’s personal information for misuse. This may involve seeking out sensitive details like Identification Card (NRIC) numbers or other personal details, with the potential for malicious intent. Based on our observation, this scam is most likely operated by a group of people with various mobile numbers. 

4.0 Recommendations
Protecting sensitive data is required not only for legal or ethical reasons but for issues related to personal privacy. Hence, as mentioned above, it is important for individuals to be alert and vigilant when facing such threats. 

We suggest the below best practices as preventive measures:

  1. Do not click on any links, applications or attachments sent over social media, email, SMS, Whatsapp or any online messengers before verifying they are safe and not malicious.
  2. Do not disclose any personal information, including NRIC numbers, telephone numbers, bank account numbers, ATM cards, or credit card numbers.
  3. Always check with the organisation implicated using their official telephone numbers, and do not call back any number given by the perpetrators during the call.
  4. Do not panic and simply follow the instructions given by the perpetrators. Users are advised to remain calm and disconnect such calls immediately. 
  5. Lodge a report to the Royal Malaysia Police (PDRM) at a nearby police station.
  6. The public can also contact the PDRM via the CCID Infoline at 013-211 1222 or the CCID Scam Response Centre at 03-2610 1559 or 03-2610 1599.

For further enquiries about this Security Alert or to report a security incident, please contact us through the following channels:

E-mail: cyber999[at]cybersecurity.my 
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting) 
Business Hours: Mon - Fri 08:30 -17:30 MYT 
Web:  https://www.mycert.org.my  

5.0 References

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed