Voice phishing simulations in Malta
Malta is the one country in this portal whose telecoms regulator has already written about this exact product, and it drew the line in your favour: manipulating the identity you present is not spoofing where there is no malicious intent. A voice phishing simulation runs here on unusually clear ground, and what Malta asks of you is documentary rather than procedural.
Phone numbers
Supplied by Callstrike
Local numbers in Malta, after a one-time approval.
Running a simulation
Permitted, on the regulator's own reasoning
The communications authority addressed the caller identity question directly and carved out honest use.
Consent
Rarely free, always evidenced
The regulator says employees are seldom able to agree freely, so this is your record of notice.
Getting a phone number in Malta
One approval per country, with no documentation to gather.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.
Malta is one of the few countries where the carrier publishes no documentation requirement at all, so the evidence-gathering that dominates most of this portal has no counterpart here. What you are waiting on is the country being enabled against your workspace rather than a regulator reading a submission, and the planning that does matter is about your provider rather than about a form.
The Maltese constraint runs through the operator, and it is worth knowing before you design around a display number. Where a Maltese number is presented as the calling identity on a call placed through an overseas or decoupled platform, the undertaking must validate the subscriber and be able to show that only validated end users holding the right of use for that number are using it, with technical verification such as a one-time password delivered in a call to the number itself and revalidation every quarter. Since November 2024 operators of international network interfaces must block all incoming calls over those interfaces carrying a Maltese calling number from the main national ranges. So this is a procurement conversation with your provider rather than a policy one, and the answer is that you present a number you genuinely hold.
- 01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Malta is assigned to youCallstrike
- 04Build and launch the campaignYour team
No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.
Is it lawful to run a simulation in Malta?
The position in short, before your counsel reads the detail below.
Yes, and Malta is the country where the answer needs the least construction. The Maltese transposition of the European rule on unsolicited communications is scoped by purpose on every limb: no publicly available service may be used to make an unsolicited communication for the purpose of direct marketing by automatic calling machine, fax or electronic mail without prior written agreement, and a further paragraph applies the same gate to any other means used for direct marketing. An authorised internal test markets nothing, so the regulation does not reach it, and nothing turns on whether the caller is a person or a synthetic voice. The honest limit is that direct marketing is defined nowhere in the instrument or its parent act, so the boundary of the scoping is undefined even though the scoping is clear.
Recording is easier here than almost anywhere in this cluster, and the reason is structural rather than interpretive. Maltese criminal law contains no general eavesdropping offence at all; the only interception offence sits inside the computer misuse provisions and turns on whether the person was duly authorised by someone entitled to control the activity, not on who was on the call. The confidentiality rule in the communications instrument then excepts you by its opening words, which bind any person other than the user.
That comfort comes with a documentation requirement attached, and it is the most operationally important line on the Maltese page. The Criminal Code says it is not for the prosecution to negative any authorisation, that the burden of proving it lies on whoever alleges it, and that the burden is not discharged by the uncorroborated testimony of the person charged. Read that plainly: in Malta the written, signed, corroborated authorisation for the programme is not governance hygiene. It is the evidence you would have to produce, and your own account of it would not be enough. Get the sign-off in writing, from someone entitled to give it, before the first call rather than after a complaint.
The paperwork is where Malta actually bites. The regulator's published list catches an exercise like this on four independent limbs and only one is needed: systematic monitoring, the use of innovative technologies, employees named expressly as vulnerable data subjects, and an employee-monitoring limb covering processing that evaluates performance or increases the power imbalance, particularly where employees may be unable easily to agree to or oppose it. Deception is exactly the condition that last limb describes. One helpful counterpart: the regulator says in terms that assessments are not subject to its authorisation, so this is a document you produce and keep rather than a submission you wait on.
What your company needs to do
6 items, in the order you will need them.
- Get the authorisation in writing, signed, and corroboratedMalta-specificThe burden of proving authorisation lands on whoever alleges it, and the Code says an uncorroborated account from the person charged does not discharge it. Name who authorised the programme, what it covers, and who else can attest to it. This is the single most useful hour anyone spends on a Maltese campaign.
- Write the impact assessment and keep itMalta-specificThe regulator's list catches this on four separate limbs, so whether one is owed is not a judgement call. It also says assessments need no authorisation from it, which means nothing here is waiting on the regulator: produce the document, keep it current, and be able to hand it over.
- Settle the display number with your provider, not with a policyMalta-specificEvery decision here is addressed to undertakings rather than to you, so you are bound through your provider's validation gate. Expect right-of-use verification and quarterly revalidation, and expect a Maltese number presented from outside the country over an international interface to be blocked.
- Give the notice at the start of the processing, not after it beginsThe regulator says employees should not be informed once monitoring has already started, and that the required information belongs at the commencement phase. Programme-level notice given in advance is our reading of what satisfies that for an exercise of this kind, and we are labelling it as a reading: the regulator has published nothing on simulations.
- Use an invented persona, never a named real colleagueMalta-specificThe aggravated tier of the computer misuse offences reaches misuse of another person's personal data to gain a third party's trust, causing prejudice to the rightful identity owner, which describes impersonating a named employee. A generic help desk is not a person. This is a scenario-design decision rather than a paperwork one.
- Inform and consult where you employ fifty or moreThe regime is real, carries no veto, and is priced unusually: the sanction is a fine calculated for every employee of the undertaking rather than per breach, so the exposure scales with headcount. Below fifty the regulations never commenced at all. Check your own collective agreement separately, because those are private and can go further than the law.
The controls that do the work
How Callstrike is configured, and which provision in Malta each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The regulator's assessment list reaches processing that evaluates an employee's performance or increases the power imbalance, particularly where employees cannot easily oppose it, and it tells you to consider the least invasive measure available. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system and never stored, and the least-invasive answer is a design choice you can evidence rather than a claim you make in the assessment.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Malta's 2025 addition creates an offence for using an address or domain likely to deceive the recipient as to the sender's identity, or otherwise using an electronic communications network for those purposes, and its gate is knowing intent to cause harm. A call that ends with a second voice breaking character and vishing training in writing the same day is the clearest evidence of the opposite intent, produced by the exercise itself rather than asserted about it.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
The regulator's position is that employees are rarely able to agree genuinely and freely because of the imbalance, so other than exceptionally the ground has to be a different one. Where this earns its place in Malta is evidential: a dated, signed and timestamped record of what staff were told, or a hashed copy of the policy or handbook clause you rely on with an attestation of its scope, is corroboration of exactly the kind the Criminal Code says your own testimony cannot supply.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
The Maltese telephone route is unusually comfortable, so this earns its place for reach rather than for risk. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a browser call presents no calling number at all, so the validation and blocking machinery your provider operates has nothing to check.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.