Case Library / Vishing (Voice Phishing) / Johor Baru Retired Bank Manager Macau Scam (RM936,000)

Johor Baru Retired Bank Manager Macau Scam (RM936,000)

A retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively as an insurance agent, a police officer, and a deputy public prosecutor convinced her to open a new bank account, transfer her savings into it, and hand over her online banking credentials "for investigation," only for the funds to be drained before she discovered the theft on 15 May 2026.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In Johor Baru, Malaysia, a 60-year-old retired bank manager lost RM936,000 to a "Macau scam" vishing syndicate over a roughly six-week period beginning 1 April 2026. She received a call from a man posing as an insurance agent who claimed a fraudulent medical insurance claim had been filed in her name at a Kuala Lumpur hospital; the call was handed off to a second man posing as a police officer who told her she was under investigation for money laundering and had her file an online police report; a third caller, posing as a deputy public prosecutor, then instructed her to open a new bank account "for investigation purposes." On 6 April 2026 she opened the account, transferred all her savings into it, and also gave the scammers her online banking login credentials. On 15 May 2026 she discovered the money had been withdrawn and filed a police report. Johor Baru (South) police chief Assistant Commissioner Raub Selamat detailed the case in a public statement on 20 May 2026, confirming the case is being investigated under Section 420 of the Penal Code (cheating) and warning the public never to disclose banking details or transfer funds to unknown callers, even those claiming to be law enforcement.

How the Attack Worked

The syndicate ran a three-stage relay/handoff vishing script typical of Malaysia's "Macau scam": (1) an initial caller posing as a medical insurance agent told the victim a fraudulent claim had been filed in her name at a Kuala Lumpur hospital, creating a plausible, personally-relevant hook and establishing that "someone is using your identity"; (2) the call was transferred live to a second caller posing as a police officer, who escalated the fear by accusing her of being under investigation for money laundering and instructing her to file an online police report (a step that both looks like due diligence and locks the victim into the fictitious legal narrative); (3) a third caller, posing as a deputy public prosecutor and invoking a real, authoritative government legal office, instructed her to open a brand-new bank account "for investigation purposes," ostensibly to protect/quarantine her funds from the fraud being investigated. She opened the account on 6 April 2026, transferred her entire savings into it, and, still following "investigative" instructions, handed over her online banking login credentials to the callers. The scammers then drained the account; she did not discover the loss until 15 May 2026, more than five weeks after the funds were moved, when she checked the account. The chain worked because each caller escalated authority (agent -> police -> prosecutor) while keeping the victim on a single continuous, uninterrupted call/handoff, denying her time to consult family, her bank, or real authorities, and because the final instruction (moving money into a "safe" account under legal orders) mimics real asset-freeze procedures victims may have heard about.

The Lure & the Tell

Lure: a call from a purported insurance agent alleging a fraudulent medical claim filed in the victim's name, followed by escalating handoffs to a "police officer" alleging a money-laundering investigation and finally a "deputy public prosecutor" directing her to open a new account and surrender banking credentials "for investigation purposes." Tell (in hindsight): no genuine Malaysian police officer, prosecutor, or insurer conducts an investigation by directing a private citizen to open a new bank account, transfer savings into it, or disclose online banking passwords over an unsolicited phone call; legitimate authorities communicate via official written notices/summons and never ask for credentials or fund transfers by phone.

Outcome

Total loss of RM936,000; the victim's funds were withdrawn by the syndicate before she discovered the theft on 15 May 2026 and filed a police report. Johor Baru (South) police confirmed the case is being investigated under Section 420 of the Malaysian Penal Code (cheating). As of the police statement on 20 May 2026, no arrests, asset recovery, or prosecution outcomes had been reported.

Why It Matters

The case is a textbook illustration of Malaysia's prevalent "Macau scam" vishing pattern (relay/handoff calls escalating from a plausible commercial pretext to impersonated police and prosecutorial authority) and is notable for its irony: the victim was herself a retired bank manager, demonstrating that financial-industry expertise and seniority offer no inherent immunity against sustained, escalating social-engineering pressure that exploits fear of legal jeopardy rather than financial naivety. It also underscores a durable core vulnerability: no legitimate government investigation ever requires a citizen to open a new account, move savings into it, or surrender online banking credentials by phone, yet these specific asks remain effective when wrapped in successive authority impersonation.

Defenses

Royal Malaysia Police (Johor Baru South chief ACP Raub Selamat) issued a public statement/warning after the fact, reminding the public never to disclose banking information or transfer money to unknown parties even when callers claim to be from enforcement/prosecution agencies, and to independently verify any claim of a criminal investigation via official channels rather than acting on instructions received over an unsolicited call. No technical control stopped this attack; the case was only caught after the money was already withdrawn, when the victim checked her account balance and then filed a police report. Broader Malaysian public-awareness efforts (e.g., MCPF Penang's republication of the case) aim to pre-empt similar "Macau scam" calls by educating the public that police and prosecutors never conduct investigations by asking victims to open new bank accounts or transfer savings by phone.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target list acquisition: Malaysian "Macau scam" call centres are documented by police and consumer-protection advisories as typically working from bulk phone-number lists, sourced from data broker leaks, prior breach dumps, or straightforward sequential/random dialing, rather than individually profiling each victim beforehand; large volumes of speculative calls are placed and the syndicate invests further effort only in whoever stays on the line and engages.
Countering Stage 1: Bulk/random-dialing target lists are largely outside an individual's or a single bank's control; the nearest realistic control is telecom- and regulator-level scam-call filtering and caller-ID/anti-spoofing measures (the kind of national anti-scam call-blocking efforts Malaysian authorities have pushed) that reduce how many such calls reach subscribers in the first place.
2
Initial pretext call posing as an insurance agent: A first caller told the victim a fraudulent medical insurance claim had been filed in her name at a Kuala Lumpur hospital, a personally alarming, plausible hook that established the premise "someone is using your identity" and got her talking instead of hanging up.
Countering Stage 2: Public-awareness messaging, including the same police advisory issued after this case, that trains people to independently verify any claim of a fraudulent insurance claim or investigation by calling the institution back on an official number, rather than continuing to engage with an unsolicited caller.
3
Live handoff to a fake police officer: The call was transferred, without a break that would let her think or hang up, to a second impersonator claiming to be a police officer, who escalated the accusation to money laundering and directed her to file an online police report, a step that both looks like due diligence and locks the victim into the fictitious legal narrative.
Countering Stage 3: Normalizing hanging up on any call that pressures a continuous, uninterrupted handoff between "officials," and calling the police back through a verified official number instead of staying on a suspect-controlled line, directly breaks this stage.
4
Live handoff to a fake deputy public prosecutor: A third caller, impersonating a senior legal authority, instructed her to open a new bank account "for investigation purposes," borrowing the credibility of a real government office to make an otherwise absurd request sound procedural.
Countering Stage 4: Clear, repeated public messaging (as Johor Baru police issued after the fact) that no genuine Malaysian police officer or deputy public prosecutor ever directs a citizen to open a new bank account for "investigation purposes" removes the pretext's legitimacy before it can work.
5
Account opening and fund transfer: On 6 April 2026, following the instructions, she opened a new bank account and transferred her entire life savings into it, believing the funds were being safeguarded pending investigation.
Countering Stage 5: Bank-side friction at account opening and unusually large same-day transfers, such as a teller or app prompt asking whether the customer is acting on instructions received by phone, gives a moment to interrupt the fraud before the money moves.
6
Credential harvesting: The syndicate directed her to hand over her online banking login credentials "for investigation," giving them direct account access on top of the funds already moved.
Countering Stage 6: Never disclosing online banking credentials or one-time passcodes to anyone by phone is the single highest-leverage control; banks reinforcing this with persistent, hard-to-dismiss warnings and login methods that can't be verbally handed over close this gap.
7
Cash-out and payout: Using the transferred funds and harvested credentials, the syndicate withdrew all the money from the account before the victim checked her balance; she discovered the loss on 15 May 2026, more than five weeks after the initial transfer, completing the syndicate's objective of full extraction with no reported recovery.
Countering Stage 7: Bank transaction-monitoring for mule-account patterns, a brand-new account receiving a large inbound transfer followed quickly by full withdrawal, is a well-documented red flag that could trigger a hold or manual review before the funds are fully cashed out; in this case no such control caught it in time.
Quick Facts
Victim
60-year-old retired bank manager (woman), Johor Baru, Malaysia
Location
Johor Baru, Johor, Malaysia
Date
2026-04-01 (scam initiated) to 2026-05-15 (loss discovered); police statement issued 2026-05-20
Impact
RM936,000 (~USD 200,000) in total losses; entire life savings of the victim transferred into a scammer-directed account and then withdrawn by the syndicate. No recovery or restitution reported at time of the police statement.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public
Threat Actor
Organized Crime
Related

Related Cases

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →

Naresh Gujral WhatsApp CEO-Impersonation Fraud (2026)

Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…

Incident 2026Read →