AUG 7 — For months, I had been receiving calls from several unknown numbers which I then ignored.

The phone would ring every so often, followed by a message on WhatsApp demanding payment for an outstanding mobile phone bill. 

I have not been a Maxis user since 2012, so I naturally assumed it was a scam call. 

After all, Malaysians are constantly reminded to be wary of unsolicited calls, particularly those demanding money. 

But one day, out of annoyance, I called the number that was in one of those WhatsApp messages. 

Everything about the conversation reinforced my suspicion, especially when the caller refused to reveal the phone number or any other information linked to the alleged account. 

When I insisted on the mobile phone number, the person on the other end mentioned my current Celcom postpaid number — a number that has never been ported to Maxis. 

He  brushed off my questions, directing me instead to visit a Maxis Centre. 

The calls kept coming after that but I continued to ignore them 

It was only when I was preparing to travel overseas that I finally decided to investigate the matter further. 

Although I had checked that I was not barred from leaving the country, I was unsettled by messages from the outsourced debt collection agency warning that if I did not settle the outstanding amount, I would be “disenaraikan hitam di CTOS” (blacklisted under CTOS). 

While I had some understanding of what CTOS is, I could not ignore the possibility that my identity had somehow become linked to someone else’s debt. 

To clear my conscience, I even obtained my own CTOS credit report to confirm that everything was clear.

For many Malaysians, CTOS is often mistaken for a blacklist. 

Originally, CTOS stands for “credit tip-off service”; today it provides credit reporting and risk management services, compiling information from publicly available sources such as court records, bankruptcy notices, company information and information submitted by its members. 

In reality, it is a credit reporting agency that compiles credit-related information to help banks and financial institutions assess a person’s creditworthiness. 

It is however important to distinguish CTOS from CCRIS (Central Credit Reference Information System). 

Having a CTOS report does not automatically mean someone has been “blacklisted”, but unresolved debts and adverse records can influence future applications for loans, credit cards and financing.

That distinction matters. Phrases such as “disenaraikan hitam di CTOS” can easily create fear among consumers who may not understand how the credit reporting system works.

When I eventually visited a Maxis Centre, the staff checked their system, and confirmed there was indeed an account registered under my identification card.

I still had email correspondence from my genuine Maxis account dating back to 2012, as proof that the “new” account did not belong to me.

Ironically, the staff could not even locate that old account anymore, they only had a record of the disputed account.

To pursue the matter further, I had to lodge a police report before Maxis could formally open an investigation into what happened and how it happened.
To pursue the matter further, I had to lodge a police report before Maxis could formally open an investigation into what happened and how it happened.

To pursue the matter further, I had to lodge a police report before Maxis could formally open an investigation into what happened and how it happened.

That was the moment I realised this was no longer simply about an outstanding bill. It had become a question of identity security.

As I went through the process, I remembered that a friend had experienced something similar last year.

She was checking her eligibility to purchase a new mobile phone from CelcomDigi — she is a CelcomDigi user — only to be told she could not proceed because her identification card had been blacklisted by Maxis.

After making enquiries, she discovered that someone had allegedly used her identification card to register a Maxis broadband service without her knowledge.

She had stopped using Maxis more than a decade ago, in her case since 2010.

I recalled that the police officer attending to her report at the time said cases involving the misuse of identification cards for telco services were “common”.

If that is the case, it should concern all of us.

Our identification card is one of the most important pieces of personal information we possess, used to verify our identity, access financial services and conduct countless official transactions. 

It should not be possible for someone else to gain access to its information.  

In this case, it raises serious questions about whether existing identity verification measures are adequate. 

For consumers, the consequences can extend far beyond an unpaid bill, requiring them to prove they never opened the account in the first place.

Several other questions also surfaced from this experience —  how was an account opened using my identification card? What identity verification process was followed? What safeguards are in place today to prevent someone from impersonating another person?

This experience has also changed how I view suspicious calls.

In an era where scam calls have become commonplace, many people would instinctively dismissed such calls as fraudulent. I certainly did. 

Yet in this case, what appeared to be a scam call turned out to be the only warning that identity fraud may already have occurred.

Neither my friend nor I discovered the misuse of our identification cards because of proactive safeguards. 

We found out by coincidence and that should not be how identity fraud is discovered.

Ultimately, this is about safety and security.

Telecommunications companies hold some of the most sensitive personal information Malaysians possess. 

Identification card details are not ordinary data, therefore deserve the highest level of protection.

While I appreciate that Maxis has opened an investigation into my case following my police report, my experience nevertheless raises broader questions about whether existing identity verification processes and security measures are sufficient to prevent cases like mine.

If cases involving the misuse of identification cards are indeed common, then they should not be treated as an inevitable part of doing business. 

Every incident should prompt a closer examination of whether existing safeguards remain fit for purpose.

Consumers should not have to discover that their identification cards have allegedly been misused only after debt collectors begin calling or applications for new services are rejected.

Identity fraud should be prevented before an account is approved — not when bills are piled up to an extent that it requires harsh action.

* This is the personal opinion of the writer or publication and does not necessarily represent the views of Malay Mail.