Voice phishing simulations in Malaysia
Malaysia is the country where this portal's standing advice does not travel. There is no legitimate interests basis in Malaysian data protection law at all, so a voice phishing simulation here is built on the employment contract or on a legal obligation that comes from outside it, which is why the banking regulator's red team requirement carries more weight here than a sector rule usually does. Recording is the open question, and Malaysian law does not use the framing everyone reaches for.
Phone numbers
Supplied by Callstrike
Local numbers in Malaysia, after a one-time approval.
Running a simulation
Permitted, on two grounds only
No balancing test exists. The ground is the contract, or an obligation from outside it.
Consent
The default, and not the route
Agreement plus a closed list of six, and agreement from your own staff is not usable.
Getting a phone number in Malaysia
One approval per country, completed in the console.
Self-provisioned after approval
Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Malaysia is one of the countries where your own team rents the number once the filing clears, rather than waiting for one to be assigned, so the approval is the only step between you and open inventory. What the console asks for is the lightest set in the region: your business name, evidenced by a business registration, and your business address, which will take the business registration showing a local address, a utility bill, a tax notice, a rent receipt or a title deed. The requirements the form applies are the ones attached to local numbers, and they are the two lines in the table below.
The address is the line to plan around, and the reason is in the numbering plan rather than in the carrier's checklist. It has to fall inside the locality covered by the number's own prefix, and a post office box is not accepted where a local address is required. There is a genuine locality rule behind that: geographic subscriber numbers may be used only in relation to a service that terminates a call within the area code they belong to, so a number from one area cannot be operated from another. Choose the area code and the address you can evidence at the same time.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03Search the inventory and rent your numberYour team
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business name | Business registration |
| Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required. | Business registration showing local address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Malaysia?
The position in short, before your counsel reads the detail below.
Yes, and Malaysia needs its own analysis rather than a European one, because the difference is structural. The Personal Data Protection Act is built on agreement plus a closed list: processing without agreement is permitted only where necessary for the performance of a contract to which the person is a party, for pre-contractual steps at their request, for compliance with a legal obligation other than one imposed by a contract, to protect their vital interests, for the administration of justice, or for the exercise of functions conferred by law. That list is exhaustive, there is no legitimate interests entry, and the 2024 amendment did not add one. So there is no balancing assessment to write here and no Malaysian impact assessment duty either, which is an absence rather than a licence.
The two grounds a workforce programme can realistically build on are the employment contract and compliance with a legal obligation that comes from outside the contract, and the qualifier in the second matters more than it looks: an obligation you imposed on yourself by policy is not a legal obligation for this purpose. That is why the sector position is load-bearing in Malaysia in a way it is not elsewhere. The central bank's technology risk policy requires a realistic red team simulation exercise at least once every three years, and separately requires annual awareness education together with a duty to measure its effectiveness, which is precisely what an unannounced test does and a training module does not.
One scope question sits underneath all of that and nobody has settled it. The Act applies to personal data processed in respect of commercial transactions, and whether the employment relationship is one is not answered by any regulator text we could find. The arguments run both ways on the face of the statute and no guidance on employee data exists. Do not build a programme on the argument that the Act does not reach employees: assume it does, comply on that footing, and treat the contrary view as a position to be defended rather than a foundation. Note too that biometric data was added to the definition of sensitive personal data with effect from April 2025, so handling a voice can move processing into the narrower regime.
Recording is the hardest question on this page and it is genuinely open. The communications statute makes it an offence to intercept any communications without lawful authority, and defines intercept as the aural or other acquisition of the contents through any equipment, which on its face is wide enough to cover a party recording. There is no words-of-one-party exception, no party-to-the-communication exception and no agreement defence anywhere in the section; the only express carve-out is for network and service provider staff acting in the normal course of employment. So Malaysia is neither cleanly one party nor cleanly all party, because the statute does not use that framing at all. Design so the programme works without audio, and take the question to Malaysian counsel before recording anything.
What your company needs to do
8 items, in the order you will need them.
- Record which of the two grounds you are onMalaysia-specificThe employment contract, or a legal obligation from outside it. Write it down and do not import a balancing assessment from a European programme, because there is no ground here for one to support. Anyone handing you a template that says otherwise has not read the Act.
- If you rely on an external legal obligation, name the instrumentMalaysia-specificThe ground is compliance with a legal obligation other than one imposed by a contract, so a policy you wrote yourself does not qualify. For a financial institution the technology risk policy is the instrument to name, and it is the clearest hook in this region for justifying the programme internally as well as legally.
- Assume the Act reaches your employee dataMalaysia-specificThe commercial transactions scope gate is unresolved and no regulator text answers it. Comply on the footing that the Act applies. A programme built on the argument that it does not is a programme with no fallback if the argument goes the other way.
- Decide whether you record, and design so you do not have toMalaysia-specificThe interception offence has no party exception and no agreement defence, and no regulator guidance or gazetted instrument resolves whether someone on the call intercepts it. Build the programme so its outputs survive an answer coming back badly, and take the point to Malaysian counsel before any audio is captured.
- Scope voice handling against the sensitive data regimeMalaysia-specificBiometric data joined the definition of sensitive personal data in April 2025, and a voice recording is the obvious candidate. That narrows what you may do with it and is a second, independent reason to keep the audio out of the design if you can.
- Keep the authorisation and the rules of engagement, because they are the defenceThe general offence that does apply is intent-based, covering a false communication made and transmitted with intent to annoy, abuse, threaten, harass or defraud, and a communication initiated with or without disclosing identity with the same intent. Your whole protection sits in that element, so documented authorisation, scope and purpose are not paperwork here.
- Do not go looking for a works councilMalaysia has none, no co-determination instrument and no statutory duty to consult employees or a union before introducing monitoring. The employment statute creates no information and consultation machinery, and the industrial relations statute runs the other way by excluding managerial matters from union proposals.
- Do not expect the choice of voice to change the analysisThe rules here turn on purpose and intent rather than on how the audio is produced, so an autonomous voice and a live operator engage exactly the same provisions. That changes the operational fit and nothing legal, which is worth knowing before anyone proposes a human caller as a compliance measure.
The controls that do the work
How Callstrike is configured, and which provision in Malaysia each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Malaysia has no acquisition-by-deception offence for this to dispose of, so the honest account of what it does here is narrower and more useful. The provision that actually reaches the exercise is intent-based, covering a false communication transmitted with intent to annoy, abuse, threaten, harass or defraud, and the whole of your protection sits in that element. Intent is evidenced by what the system does as well as by what the authorisation says, and a call engineered to stop before anything is handed over is the strongest available evidence that no gain was ever the purpose. It also keeps a credential out of the sensitive data regime voice handling can already put you in.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
There is no works council here to negotiate acceptance with and no consultation step to earn goodwill in, so whatever tolerance the programme has has to be created inside the call itself. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is also the most direct evidence available against the intent element the offence turns on, because an exercise that teaches immediately is a poor fit for a charge of intending to annoy or harass.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Agreement is the statutory default in Malaysia and it is exactly the thing you cannot build on, so the ground has to be the contract or an external obligation and this produces the dated record of which. Where it does more than that is the second ground: the central bank's technology risk policy requires annual awareness education and a duty to measure its effectiveness, and a signed, timestamped record of what staff were told and when is what turns an assertion that you complied into evidence the regulator's own duty was discharged.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
The route is worth having in Malaysia for the pretext rather than for the recording, and saying so is the honest version. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens themselves after working through the module, and the intent-based offence is written about a communication initiated to annoy, abuse, threaten or harass, which a session someone chose to start is not. The interception definition is about the aural acquisition of contents by equipment and says nothing about telephony, so the open recording question is unchanged by the delivery and still has to be designed around.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.