Malaysia's communications regulator has uncovered a substantial volume of fraudulent content circulating across social media platforms, with over 127,000 deceptive posts identified and flagged for removal since the start of the year. Communications Minister Datuk Seri Fahmi Fadzil revealed the figures during a press conference following a Cabinet meeting in Putrajaya on Monday, highlighting the escalating challenge posed by organised scam operations exploiting digital platforms to defraud unsuspecting users.

The breakdown of platform-specific violations reveals a clear concentration of fraudulent activity on two dominant social networks. Facebook emerges as the primary vector for scam content, accounting for 53 percent of all identified posts, while TikTok follows closely with 39 percent of detected cases. These two platforms alone represent the overwhelming majority of scam-related removal requests processed by the Malaysian Communications and Multimedia Commission (MCMC), underscore the vulnerability of mass-market social media services to coordinated fraud schemes. The remaining eight percent of cases involve various other platforms, though the minister did not specify which services fell into this category.

The scale of the problem becomes clearer when contextualised against the MCMC's total removal request workload. The 127,000 scam contents represent approximately 27 percent of all content removal requests initiated by the regulatory body during the same period. This proportion suggests that fraudulent material constitutes the single largest category of harmful content requiring intervention, surpassing other classifications such as hate speech, violent material, and misinformation. The prevalence of scam-related takedown requests reflects the operational strategy employed by fraudsters, who rely heavily on fake accounts and coordinated posting patterns to maximise reach and evade detection.

The administrative burden associated with processing these removal requests has prompted the MCMC to underscore the resource constraints facing the regulator. According to Fahmi, each content removal request demands substantial investment of time and personnel resources. The commission's staff must dedicate between 30 and 45 minutes per post to complete the necessary documentation and submit formal takedown requests to the respective social media platforms. When aggregated across thousands of weekly submissions, this requirement translates into significant operational costs and processing delays that may extend the period during which fraudulent material remains visible to potential victims.

To combat the proliferation of online fraud, Malaysian authorities have invoked newly established regulatory frameworks designed to hold social media platforms accountable for harmful content on their services. The Online Safety Act 2025 (Act 866) introduced two specific codes targeting different categories of digital harm: the Child Protection Code (CPC) and the Risk Mitigation Code (RMC). Both codes came into effect on June 1, establishing mandatory compliance obligations for identified social media platforms operating within Malaysia's regulatory jurisdiction. These frameworks represent a departure from earlier approaches that relied primarily on voluntary cooperation and post-hoc removal requests.

The government has adopted a measured implementation strategy, granting social media platforms a grace period spanning several months to achieve full compliance with the new codes. This timeline reflects recognition of the scale and complexity involved in redesigning platform systems to detect and prevent harmful content proactively rather than reactively. Officials indicated that the compliance period allows platforms to coordinate their responses and implement systemic changes necessary to prevent harmful material from being distributed in the first place, rather than merely removing content after it has achieved wider circulation among users.

The distinction between the two codes reflects the government's targeted approach to different categories of digital harm. The Child Protection Code specifically addresses content that poses risks to minors, encompassing material ranging from sexual exploitation imagery to predatory contact and grooming behaviour. The Risk Mitigation Code casts a broader net, targeting any content that threatens users' physical safety or economic security, a category clearly encompassing the scam materials that dominate MCMC removal requests. By establishing these frameworks in legislation rather than relying on administrative guidance, Malaysian regulators have signalled their intention to enforce compliance through legal mechanisms.

Minister Fahmi emphasised the government's commitment to educating the public about identifying and avoiding fraudulent content, recognising that regulatory action alone cannot eliminate the risk posed by scams. The MCMC has promoted the use of Sebenarnya.my and MyCheck as official verification portals where Malaysians can fact-check suspicious claims and alert authorities to fraudulent material. Fahmi also recommended that citizens prioritise information from mainstream media outlets as more reliable sources compared to unverified social media posts. This public education component acknowledges that fraud prevention requires shared responsibility between regulators, platforms, and individual users exercising critical evaluation of content encountered online.

The concentration of scam activity on Facebook and TikTok presents specific challenges given these platforms' scale and algorithmic design. Both services employ recommendation systems intended to maximise user engagement, creating incentives that fraudsters exploit to amplify the reach of misleading content. Facebook's mature user base and established payment integration features make it particularly attractive for financial fraud schemes, while TikTok's predominantly younger demographic and algorithm-driven content distribution present different opportunities for manipulation. The high proportion of cases on these two platforms suggests that generic removal request processes may be insufficient to address the systemic vulnerabilities enabling fraud at scale.

For Malaysian consumers and businesses, the prevalence of online scams represents a persistent threat to financial security and personal data safety. The estimated 127,000 fraudulent posts detected since January likely represent only a fraction of total scam attempts, given that not all malicious content receives regulatory attention and some schemes may successfully complete their objective before detection. The variety of scam typologies deployed—from investment fraud and impersonation schemes to fake product sales and credential harvesting—means that vigilance requires sustained effort and awareness from individual users. Regulatory action, platform accountability mechanisms, and public education initiatives must operate in concert to reduce the vulnerability of Malaysia's growing digital population to organised fraud operations.

The ongoing regulatory effort reflects broader regional trends across Southeast Asia, where governments are increasingly asserting authority over social media platforms through legislative frameworks. Malaysia's approach combining specific codes addressing distinct harms with extended compliance periods represents a middle path between light-touch regulation and restrictive censorship regimes. As the implementation of the Online Safety Act 2025 proceeds and platforms adapt their systems to meet new requirements, the effectiveness of this regulatory model in reducing scam content circulation will provide important lessons for other countries in the region grappling with similar challenges of balancing platform accountability with operational feasibility and user protection.