22.6k unique visitors in the last 3 days

Malaysian Regulator Stops SMS Blaster Bypassing Telco Filters

MCMC found a 23 year old man driving around Johor Bahru with an SMS blaster that sent scam links. This was its fifth special operation against the devices during 2026.

The Malaysian Communications and Multimedia Commission (MCMC) found a 23 year old local man driving a car equipped with an SMS blaster around Johor Bahru, a Malaysian city bordering Singapore, on July 24. The device transmitted a radio signal that impersonated a mobile provider and sent fraudulent messages containing web links directly to nearby phones.

Initial investigations indicated the syndicate targeted busy public areas during peak hours to maximize the number of messages sent. MCMC did not disclose how many messages had been transmitted or whether any recipients lost money.

The device bypassed a safeguard intended to stop fraudulent links. MCMC requires Malaysian telcos to block SMS messages containing URLs, a measure Commsrisk covered when it was introduced in 2023. The SMS blaster avoided those filters because it delivered messages directly to nearby phones without passing through a legitimate mobile network.

The latest operation brought MCMC’s tally to five special operations against SMS blasters during 2026, comprising two in Johor and three in Genting Highlands. Across the five operations, four GSM modules were seized and four individuals gave statements to investigators. Commsrisk previously reported on SMS blasters found around Genting Highlands and Johor Bahru in January and February.

MCMC did not explain how it located the latest vehicle. Dr Silke Holtmanns and Eleanor Holtmanns describe methods that telcos and regulators can use to identify these devices in their article about detecting SMS blasters.

MCMC did not announce an arrest, although its photographs show the suspect giving a statement at Sentral Police Station in Johor Bahru. The investigation is being conducted under Section 239(1)(a) of Malaysia’s Communications and Multimedia Act 1998 and Regulation 16(1)(b) of the Communications and Multimedia (Technical Standards) Regulations 2000. The first offence carries a maximum fine of MYR1mn (USD244,000), imprisonment for up to ten years, or both. The second carries a maximum fine of MYR300,000 (USD73,000), imprisonment for up to three years, or both.

The latest incident has been added to the SMS blaster map on the Commsrisk Global Fraud Dashboard. The facts and photographs were published in the original Malay-language MCMC press release.

Look below for photographs of the suspect giving a statement at Sentral Police Station in Johor Bahru, the vehicle, and the equipment seized.

Photographs: MCMC

James Greenley
James Greenley
James is responsible for developing the software for the Commsrisk Global Fraud Dashboard and maintaining the IT for Commsrisk. He originally joined the Commsrisk team as Producer of Commsrisk TV but has since become the spearhead for all the technological aspects of Commsrisk.

Related Articles

The Commsrisk Global Fraud Dashboard


Our Global Fraud Dashboard uses AI-powered search to collate, update and visualize data about scams and other network abuses from around the world. New charts are added each month. See it here.

Get Our Weekly Newsletter by Email