JagaShieldBahasa Malaysia

Phishing/smishing, including fake bank TAC/OTP messages

Last verified: 20 Aug 2026

Fake messages impersonate your bank via SMS, email or WhatsApp, with a link to a fake login page to steal your credentials, or a direct request to share a TAC/OTP just sent to you. A message that simply tells you your OTP ("do not share this with anyone") is normal and safe — the danger is only when a message asks you to hand the code over.

How this scam typically works

Smishing (SMS phishing) and phishing (email or web) both impersonate a bank, e-wallet, courier, or government agency to get you to hand over information you'd never normally give a stranger. There are two common versions.

The first sends you a link — by SMS, email, or WhatsApp — to a fake page made to look exactly like your bank's login screen. You type in your username and password (and sometimes your card number), and that information goes straight to the scammer, who then logs into your real account.

The second skips the fake page entirely and just asks directly: a message or a caller claiming to be your bank tells you a one-time password (TAC/OTP) has been or will be sent to you, and asks you to read it out, reply with it, or forward it "to verify your identity" or "to cancel a transaction." Whoever has that code can complete a transaction on your account in real time.

The distinction that matters most

Your bank will send you real OTP messages all the time — for logins, transfers, and card payments. A message that only tells you the code, such as "Your OTP is 123456. Do not share this with anyone," is completely normal and not a threat by itself.

The scam is not the code being sent to you — it's someone asking you to give the code to them. No bank, government agency, or legitimate service will ever call, message, or email you asking you to read out, type into a form, or forward a TAC/OTP. If a message or caller asks you to hand over a code rather than just informing you of one, that is the scam.

Warning signs

If you're being targeted right now

Don't click the link, and don't share, read out, or forward any TAC/OTP to anyone, no matter who they claim to be. If you're unsure whether a message is real, go to your bank's app or official website directly — never through the link in the message — or call your bank using the number on your card or their official website, not a number given in the message.

If you've already shared a TAC/OTP

See I gave my TAC/OTP to someone — what now for the exact steps to take next — this page covers how to recognise and avoid the pattern, not the recovery procedure itself.

If you've already lost money

See Scammed in Malaysia? The first 24 hours for what to do next — who to contact, in what order, and what to preserve as evidence.

FAQ

My bank sent me an OTP I didn't ask for — does that mean I'm already being scammed?

Not by itself. An unsolicited OTP can mean someone else has your password and is trying to log in or transact using it, which is worth taking seriously — but the OTP message itself is just your bank doing its job. The danger step is if you then share that code with anyone. If you didn't request it, don't share it, and consider changing your banking password as a precaution.

The link looked exactly like my bank's real website — how do I tell the difference?

Check the exact domain in the address bar character by character rather than trusting how the page looks, since a fake page can be a pixel-perfect copy. When in doubt, don't click the link at all — open your banking app directly or type your bank's known web address in yourself.

Is a phone call asking for my OTP different from a text message asking for it?

No — the request itself is the red flag regardless of channel. Whether it arrives as a call, SMS, WhatsApp message, or email, no genuine bank or agency needs you to say, type, or forward a TAC/OTP to them.

Checklist

  • Message asks you to click a link and log in to "verify" or "unlock" your bank account
  • Message asks you to reply with, read out, or forward a TAC/OTP to anyone, including someone claiming to be from your bank
  • Sender number, email address, or link domain is slightly altered from your bank's real one
  • Urgent framing — "your account will be suspended," "unusual activity detected" — pushing you to act within minutes