How this scam typically works
Smishing (SMS phishing) and phishing (email or web) both impersonate a bank, e-wallet, courier, or government agency to get you to hand over information you'd never normally give a stranger. There are two common versions.
The first sends you a link — by SMS, email, or WhatsApp — to a fake page made to look exactly like your bank's login screen. You type in your username and password (and sometimes your card number), and that information goes straight to the scammer, who then logs into your real account.
The second skips the fake page entirely and just asks directly: a message or a caller claiming to be your bank tells you a one-time password (TAC/OTP) has been or will be sent to you, and asks you to read it out, reply with it, or forward it "to verify your identity" or "to cancel a transaction." Whoever has that code can complete a transaction on your account in real time.
The distinction that matters most
Your bank will send you real OTP messages all the time — for logins, transfers, and card payments. A message that only tells you the code, such as "Your OTP is 123456. Do not share this with anyone," is completely normal and not a threat by itself.
The scam is not the code being sent to you — it's someone asking you to give the code to them. No bank, government agency, or legitimate service will ever call, message, or email you asking you to read out, type into a form, or forward a TAC/OTP. If a message or caller asks you to hand over a code rather than just informing you of one, that is the scam.
Warning signs
- A link asking you to log in to "verify," "unlock," or "reactivate" your account
- Any request — by call, SMS, WhatsApp, or email — to share, read out, or forward a TAC/OTP
- A sender ID, email domain, or link URL that's almost but not quite your bank's real one
- Urgency and threats: account suspension, legal action, or "final notice" language designed to make you act before you think
If you're being targeted right now
Don't click the link, and don't share, read out, or forward any TAC/OTP to anyone, no matter who they claim to be. If you're unsure whether a message is real, go to your bank's app or official website directly — never through the link in the message — or call your bank using the number on your card or their official website, not a number given in the message.
If you've already shared a TAC/OTP
See I gave my TAC/OTP to someone — what now for the exact steps to take next — this page covers how to recognise and avoid the pattern, not the recovery procedure itself.
If you've already lost money
See Scammed in Malaysia? The first 24 hours for what to do next — who to contact, in what order, and what to preserve as evidence.
FAQ
My bank sent me an OTP I didn't ask for — does that mean I'm already being scammed?
Not by itself. An unsolicited OTP can mean someone else has your password and is trying to log in or transact using it, which is worth taking seriously — but the OTP message itself is just your bank doing its job. The danger step is if you then share that code with anyone. If you didn't request it, don't share it, and consider changing your banking password as a precaution.
The link looked exactly like my bank's real website — how do I tell the difference?
Check the exact domain in the address bar character by character rather than trusting how the page looks, since a fake page can be a pixel-perfect copy. When in doubt, don't click the link at all — open your banking app directly or type your bank's known web address in yourself.
Is a phone call asking for my OTP different from a text message asking for it?
No — the request itself is the red flag regardless of channel. Whether it arrives as a call, SMS, WhatsApp message, or email, no genuine bank or agency needs you to say, type, or forward a TAC/OTP to them.