Callstrike
Compliance

Voice phishing simulations in Malaysia

Phone numbers in MalaysiaSelf-provisioned after approval

Malaysia is the country where this portal's standing advice does not travel. There is no legitimate interests basis in Malaysian data protection law at all, so a voice phishing simulation here is built on the employment contract or on a legal obligation that comes from outside it, which is why the banking regulator's red team requirement carries more weight here than a sector rule usually does. Recording is the open question, and Malaysian law does not use the framing everyone reaches for.

Phone numbers

Supplied by Callstrike

Local numbers in Malaysia, after a one-time approval.

Running a simulation

Permitted, on two grounds only

No balancing test exists. The ground is the contract, or an obligation from outside it.

Consent

The default, and not the route

Agreement plus a closed list of six, and agreement from your own staff is not usable.

Getting a phone number in Malaysia

One approval per country, completed in the console.

Self-provisioned after approval

Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Malaysia is one of the countries where your own team rents the number once the filing clears, rather than waiting for one to be assigned, so the approval is the only step between you and open inventory. What the console asks for is the lightest set in the region: your business name, evidenced by a business registration, and your business address, which will take the business registration showing a local address, a utility bill, a tax notice, a rent receipt or a title deed. The requirements the form applies are the ones attached to local numbers, and they are the two lines in the table below.

The address is the line to plan around, and the reason is in the numbering plan rather than in the carrier's checklist. It has to fall inside the locality covered by the number's own prefix, and a post office box is not accepted where a local address is required. There is a genuine locality rule behind that: geographic subscriber numbers may be used only in relation to a service that terminates a call within the area code they belong to, so a number from one area cannot be operated from another. Choose the area code and the address you can evidence at the same time.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03Search the inventory and rent your numberYour team
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business nameBusiness registration
Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Business registration showing local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Malaysia?

The position in short, before your counsel reads the detail below.

Yes, and Malaysia needs its own analysis rather than a European one, because the difference is structural. The Personal Data Protection Act is built on agreement plus a closed list: processing without agreement is permitted only where necessary for the performance of a contract to which the person is a party, for pre-contractual steps at their request, for compliance with a legal obligation other than one imposed by a contract, to protect their vital interests, for the administration of justice, or for the exercise of functions conferred by law. That list is exhaustive, there is no legitimate interests entry, and the 2024 amendment did not add one. So there is no balancing assessment to write here and no Malaysian impact assessment duty either, which is an absence rather than a licence.

The two grounds a workforce programme can realistically build on are the employment contract and compliance with a legal obligation that comes from outside the contract, and the qualifier in the second matters more than it looks: an obligation you imposed on yourself by policy is not a legal obligation for this purpose. That is why the sector position is load-bearing in Malaysia in a way it is not elsewhere. The central bank's technology risk policy requires a realistic red team simulation exercise at least once every three years, and separately requires annual awareness education together with a duty to measure its effectiveness, which is precisely what an unannounced test does and a training module does not.

One scope question sits underneath all of that and nobody has settled it. The Act applies to personal data processed in respect of commercial transactions, and whether the employment relationship is one is not answered by any regulator text we could find. The arguments run both ways on the face of the statute and no guidance on employee data exists. Do not build a programme on the argument that the Act does not reach employees: assume it does, comply on that footing, and treat the contrary view as a position to be defended rather than a foundation. Note too that biometric data was added to the definition of sensitive personal data with effect from April 2025, so handling a voice can move processing into the narrower regime.

Recording is the hardest question on this page and it is genuinely open. The communications statute makes it an offence to intercept any communications without lawful authority, and defines intercept as the aural or other acquisition of the contents through any equipment, which on its face is wide enough to cover a party recording. There is no words-of-one-party exception, no party-to-the-communication exception and no agreement defence anywhere in the section; the only express carve-out is for network and service provider staff acting in the normal course of employment. So Malaysia is neither cleanly one party nor cleanly all party, because the statute does not use that framing at all. Design so the programme works without audio, and take the question to Malaysian counsel before recording anything.

What your company needs to do

8 items, in the order you will need them.

  • Record which of the two grounds you are onMalaysia-specificThe employment contract, or a legal obligation from outside it. Write it down and do not import a balancing assessment from a European programme, because there is no ground here for one to support. Anyone handing you a template that says otherwise has not read the Act.
  • If you rely on an external legal obligation, name the instrumentMalaysia-specificThe ground is compliance with a legal obligation other than one imposed by a contract, so a policy you wrote yourself does not qualify. For a financial institution the technology risk policy is the instrument to name, and it is the clearest hook in this region for justifying the programme internally as well as legally.
  • Assume the Act reaches your employee dataMalaysia-specificThe commercial transactions scope gate is unresolved and no regulator text answers it. Comply on the footing that the Act applies. A programme built on the argument that it does not is a programme with no fallback if the argument goes the other way.
  • Decide whether you record, and design so you do not have toMalaysia-specificThe interception offence has no party exception and no agreement defence, and no regulator guidance or gazetted instrument resolves whether someone on the call intercepts it. Build the programme so its outputs survive an answer coming back badly, and take the point to Malaysian counsel before any audio is captured.
  • Scope voice handling against the sensitive data regimeMalaysia-specificBiometric data joined the definition of sensitive personal data in April 2025, and a voice recording is the obvious candidate. That narrows what you may do with it and is a second, independent reason to keep the audio out of the design if you can.
  • Keep the authorisation and the rules of engagement, because they are the defenceThe general offence that does apply is intent-based, covering a false communication made and transmitted with intent to annoy, abuse, threaten, harass or defraud, and a communication initiated with or without disclosing identity with the same intent. Your whole protection sits in that element, so documented authorisation, scope and purpose are not paperwork here.
  • Do not go looking for a works councilMalaysia has none, no co-determination instrument and no statutory duty to consult employees or a union before introducing monitoring. The employment statute creates no information and consultation machinery, and the industrial relations statute runs the other way by excluding managerial matters from union proposals.
  • Do not expect the choice of voice to change the analysisThe rules here turn on purpose and intent rather than on how the audio is produced, so an autonomous voice and a live operator engage exactly the same provisions. That changes the operational fit and nothing legal, which is worth knowing before anyone proposes a human caller as a compliance measure.

The controls that do the work

How Callstrike is configured, and which provision in Malaysia each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Malaysia has no acquisition-by-deception offence for this to dispose of, so the honest account of what it does here is narrower and more useful. The provision that actually reaches the exercise is intent-based, covering a false communication transmitted with intent to annoy, abuse, threaten, harass or defraud, and the whole of your protection sits in that element. Intent is evidenced by what the system does as well as by what the authorisation says, and a call engineered to stop before anything is handed over is the strongest available evidence that no gain was ever the purpose. It also keeps a credential out of the sensitive data regime voice handling can already put you in.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

There is no works council here to negotiate acceptance with and no consultation step to earn goodwill in, so whatever tolerance the programme has has to be created inside the call itself. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is also the most direct evidence available against the intent element the offence turns on, because an exercise that teaches immediately is a poor fit for a charge of intending to annoy or harass.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Agreement is the statutory default in Malaysia and it is exactly the thing you cannot build on, so the ground has to be the contract or an external obligation and this produces the dated record of which. Where it does more than that is the second ground: the central bank's technology risk policy requires annual awareness education and a duty to measure its effectiveness, and a signed, timestamped record of what staff were told and when is what turns an assertion that you complied into evidence the regulator's own duty was discharged.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The route is worth having in Malaysia for the pretext rather than for the recording, and saying so is the honest version. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens themselves after working through the module, and the intent-based offence is written about a communication initiated to annoy, abuse, threaten or harass, which a session someone chose to start is not. The interception definition is about the aural acquisition of contents by equipment and says nothing about telephony, so the open recording question is unchanged by the delivery and still has to be designed around.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

No legitimate interests, a closed list, and an unsettled scope gate

Every other page in this cluster tells you to use legitimate interests and not consent. Malaysia is the country where that advice would be wrong, and the difference is structural rather than a matter of degree.

The Personal Data Protection Act 2010, the PDPA, is built on consent plus a closed list. Its general principle provides that a data controller shall not process personal data unless the data subject has given consent, and then permits processing without consent only where it is necessary for the performance of a contract to which the data subject is a party, for pre-contractual steps at their request, for compliance with a legal obligation other than one imposed by a contract, to protect their vital interests, for the administration of justice, or for the exercise of functions conferred by law. That list is exhaustive. There is no paragraph for legitimate interests, and the 2024 amendment did not add one: we read the amending Act in full and the general principle is untouched.

So there is no legitimate interest assessment to write in Malaysia and no European style balancing test to run, and anyone handing you a template that says otherwise has not read the Act. The two grounds a workforce programme can realistically build on are the employment contract, and compliance with a legal obligation that comes from outside the contract, which is why the sector rules further down this page matter more here than they do elsewhere. Note the qualifier in the third ground carefully: an obligation you imposed on yourself by policy is not a legal obligation for this purpose.

There is also no data protection impact assessment in Malaysian law. That is an absence rather than a licence, and doing one anyway remains good practice, but do not describe it as a statutory requirement here.

Now the scope question, which is the single most important thing on this page and which nobody has settled. The Act applies to personal data processed in respect of commercial transactions, and its definition of personal data repeats that gate. A commercial transaction means any transaction of a commercial nature, whether contractual or not, including matters relating to the supply or exchange of goods or services, agency, investments, financing, banking and insurance. Whether the employment relationship is one is not answered by any regulator text we could find. The arguments run both ways on the face of the statute, and the data protection department has published no guidance on employee data. Do not build a programme on the argument that the Act does not reach employees. Assume it does, comply on that footing, and treat any contrary view as a position to be defended rather than a foundation.

One thing that did change in 2024 and matters directly to an AI voice: biometric data was added to the definition of sensitive personal data with effect from April 2025. Voice handling can move processing out of the general principle and into the narrower regime for sensitive data, so scope your programme with that in mind.

On consultation there is nothing, and that is a finding rather than a gap. Malaysia has no works council, no co-determination instrument and no statutory duty to consult employees or a union before introducing monitoring. The employment statute creates no information and consultation machinery at all, and the industrial relations statute runs the other way, excluding a list of managerial matters from union proposals rather than creating duties. A reader arriving from our German, Italian or Swedish page should not go looking for the Malaysian equivalent.

The interception offence, and what it conspicuously does not say

This is the hardest question on the Malaysian page and we are going to leave it open, because closing it would mean inventing a rule.

The Communications and Multimedia Act makes it an offence to intercept, or attempt or procure the interception of, any communications without lawful authority under that Act or any other written law, and equally to disclose or use the contents knowing they were so obtained. Intercept is defined as the aural or other acquisition of the contents of any communications through the use of any electronic, mechanical or other equipment, device or apparatus.

Read those two together. The definition is wide enough on its face to catch a party to the call recording it, because a recorder is equipment and recording is aural acquisition of the contents. And here is the part that matters: there is no words of one party exception, no party to the communication exception and no consent defence anywhere in the section. The only express carve-out is for officers, employees and agents of network and service providers acting in the normal course of employment, which is about carriers rather than callers. The only other door is the phrase without lawful authority under this Act or any other written law, which requires you to point at an actual enabling law, and consent under the data protection statute is not obviously one.

So Malaysia is neither cleanly one party nor cleanly all party. The statute does not use that framing at all, and describing it in those terms would be the single most dangerous sentence we could put on this page. We found no regulator guidance and no gazetted instrument resolving whether a participant recording their own call intercepts it. Take it to Malaysian counsel before you record anything, and design the programme so that it works without the audio if the answer comes back badly.

One trap that will catch anyone checking this themselves. Every copy of the Act available online, including the reprints on the government portals, stops at amendments made around twenty years ago and carries no banner saying so. The penalty under this section was raised substantially by a 2025 amending Act. If you look up the fine and find a modest one, you are reading a superseded text that looks entirely current.

No dialler rule, and one offence that turns entirely on intent

Malaysia has no automated dialler rule and no artificial voice rule. The two provisions people reach for are both scoped away from this activity, and the one that does apply is not about technology at all.

The data protection statute gives a right to require a controller to stop processing for the purposes of direct marketing, and defines direct marketing as the communication by whatever means of any advertising or marketing material directed to particular individuals. An authorised security test communicates no advertising or marketing material, so that right is not engaged. A newer communications provision on unsolicited commercial electronic messages is scoped to commercial messages and is in any event a shell that bites only through regulations. We could not obtain its commencement instrument from a primary source, so we are telling you its text and scope and not whether it is in force.

The provision that actually applies is general and intent-based, and it deserves more attention than any dialler rule would. It is an offence to knowingly make and transmit, over a network or applications service, a communication that is false or grossly offensive in character with intent to annoy, abuse, threaten, harass or commit an offence involving fraud or dishonesty against any person, and separately to initiate a communication with or without disclosing one's identity with intent to annoy, abuse, threaten or harass. The penalty is a fine of up to five hundred thousand ringgit or two years, with a daily amount after conviction.

Read what that describes. A vishing simulation is by design a false communication initiated over an applications service, often with a concealed or assumed identity. The whole of your protection sits in the intent element: the exercise is run to train, under the employer's authority, and not with intent to annoy, abuse, threaten, harass or defraud. That is a defensible position and it is also a fragile one, because it rests entirely on documented authorisation, scope and purpose. In Malaysia more than anywhere else in this cluster, the written authorisation and the rules of engagement are not paperwork. They are the defence.

Because the rules here turn on purpose and intent rather than on how the audio is produced, choosing an autonomous voice or a live operator does not change which provisions apply. It changes the operational fit and nothing legal.

Caller ID, a locality rule, and a regulation that binds your carrier

The current caller identification rule sits in the national numbering plan as substituted by an amendment notice effective January 2024, made under the communications statute's numbering power. The important structural point is who it binds: the obligation falls on the assignment holder, which is the carrier, rather than on the end user directly. So when your provider tells you what you may present, it is discharging its own obligation.

There is a genuine locality rule for geographic numbers: subscriber numbers may be used only in relation to a service that terminates a call within the area code they belong to, so a number from one area cannot be operated from another. Toll free numbers carry no equivalent restriction, which is worth knowing when you are choosing what to present.

One thing to keep straight, because our own records have not always been precise about it. A regulation existing for a class of number does not mean inventory exists for it. What is actually purchasable is a commercial fact and the panel below carries it, generated from the same matrix the platform enforces, rather than being described in prose that would go stale.

What the country matrix holds for Malaysia

Number types:
Local, Toll free
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

What the regulator requires of you, which is nothing

We read the numbering plan looking for a requirement that the holder of a Malaysian number be a registered Malaysian company or hold a local address, and there is none published. The obligations in the plan run to the assignment holder, which is your carrier.

So the onboarding checks you will encounter are carrier checks. That does not make them optional, because your carrier has its own obligations to discharge and will not proceed without satisfying them. It does mean that if you are told a regulator requires a particular document, it is worth asking which instrument says so, because we could not find one.

We are stating that as a negative finding rather than as reassurance. If a Malaysian requirement exists in an instrument we did not reach, this section is where it would belong, and its absence here means we did not find it rather than that it cannot exist.

The one regulator in this tranche that mandates adversarial simulation

If you are a Malaysian financial institution, this section is the reason your programme exists, and it is the most direct requirement in the whole of this cluster.

The central bank's technology risk policy document, issued in November 2025 and binding through the financial services legislation, requires a realistic red team simulation exercise at least once every three years, and separately requires annual awareness education together with a duty to measure the effectiveness of it. Measuring effectiveness is precisely what an unannounced test does and a training module does not, which makes this the clearest regulatory hook available to anyone justifying this work internally.

The national cybersecurity statute is a genuine differentiator too, but be precise about what it says. It requires entities designated as national critical information infrastructure to conduct risk assessment and to undergo audit by an approved auditor. It does not on its face mandate social engineering testing; that detail is pushed into a code of practice we could not obtain. So cite the statute for the audit and assessment duty and do not overstate it.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in MALAYSIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The programme is authorised in writing by the system owner.

Verify or correct each proposition below against primary Malaysian sources, and tell me which ground to record:

1. ⚠ PDPA 2010 s 6(1) requires consent and s 6(2) is a CLOSED list of six with NO legitimate-interests paragraph. Confirm Act A1727 (2024) did not add one.
2. ⚠ Is the employment relationship a «commercial transaction» within s 2 at all? No JPDP guidance on employee data was located. We assume it applies: confirm or correct.
3. Biometric data entered the sensitive personal data definition with effect from April 2025. Does a voice recording of an employee fall inside it?
4. ⚠⚠ CMA s 234 has NO party-consent exception, NO one-party exception and NO consent defence on its face, and s 6 defines «intercept» as aural or other acquisition of contents by equipment. Is there ANY gazetted instrument, regulator guidance or reported decision resolving whether a participant recording their own call intercepts it?
5. ⚠ EVERY online copy of Act 588 is roughly twenty years stale WITH NO BANNER. Act A1743 (2025) raised the s 234(3) penalty from RM50,000 / 1 year to RM500,000 / 5 years. Confirm the current penalty.
6. CMA s 233's intent element (annoy, abuse, threaten, harass, or fraud or dishonesty) is the whole of our protection. What documentation best evidences its absence?
7. Malaysia has no works council, no co-determination instrument and no statutory consultation duty before introducing monitoring (Act 265 and Act 177 s 13(3)). Confirm.
8. BNM's RMiT policy document (28 November 2025) requires a realistic red team simulation at least every three years plus annual awareness education with a duty to MEASURE effectiveness. Confirm, and advise whether it is a «legal obligation» for s 6(2) purposes.

⚠ Cyber Security Act 2024 s 22 requires risk assessment and audit but does not on its face mandate social engineering testing; the detail sits in a code of practice we could not obtain. Flag anything that has changed since September 2026.

Common questions

Can we use legitimate interests as the basis in Malaysia?
No. Malaysian data protection law requires consent and permits processing without it only on a closed list of six grounds, none of which is legitimate interests. The 2024 amendment did not add one. Build on the employment contract or an external legal obligation instead, and expect no impact assessment requirement.
Does the Act even apply to employee data?
Unsettled. The Act reaches personal data processed in respect of commercial transactions, and whether employment is one has not been answered by any regulator text we could find. Assume it applies and comply on that footing rather than building a programme on the contrary argument.
Can we record simulated calls in Malaysia?
Take it to counsel first. The interception offence has no party exception, no consent defence and a definition wide enough to catch a participant recording their own call. Malaysia is neither one party nor all party; the statute does not use that framing. Design so the programme works without audio.
Does any Malaysian regulator actually require this testing?
The central bank does. Its technology risk policy requires a realistic red team simulation at least every three years for the institutions it covers, plus annual awareness education and a duty to measure its effectiveness. The cybersecurity statute requires assessment and audit but does not name social engineering.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.