Massive Data Breach Of Personal Information Reported In Malaysia

Malaysian citizens have been affected by a massive data breach including more than 46 million mobile phone numbers as well as more than 80,000 medical records, according to local reports.

While large data breaches are becoming increasingly common, the incident remains unusual in its scale, with Malaysia having a population estimated at only about 31.2 million.

Lowyat.net, a Malaysian news site that also operates online forums, said earlier this month it had found an individual attempting to use one of its forums to sell the data.

Late on Monday the site said it had confirmed the data was authentic, although it didn’t specify how the authentication had been carried out.

Data had already changed hands

The site said the files appeared to date from 2014 and to have already changed hands several times.

It wasn’t clear how the data had been obtained, with the variety of sources suggesting it may have been compiled from several distinct leaks. Time stamps on the telco data indicated it was last updated between May and July 2014, Lowyat.net said.

Malaysian mobile operators contacted by local news outlet The Star said they were cooperating with investigators, but none commented on whether they had been hacked.

The telecoms data included 46.2 million mobile phone numbers, including both postpaid and prepaid numbers, along with customer details, addresses and SIM card information such as IMEI and IMSI numbers.

The figure is larger than Malaysia’s entire estimated population, but many mobile users have multiple numbers, and the data could also include numbers no longer in active use.

While the data isn’t sufficient to clone users’ SIM cards, it could expose them to scams. Lowyat.net said since it originally reported the breach earlier in October telcos have taken no action to protect those affected by the breach, such as replacing the affected SIM cards.

Medical records

Also in the cache were three databases from the Malaysian Medical Council (MMC), the Malaysian Medical Association (MMA) and the Malaysian Dental Association (MDA), 81,309 records in all.

The information they include is more sensitive, with individuals’ identity card numbers (called MyKad), along with mobile, work and home phone numbers and work and residential addresses.

The MMA said it had filed a police report earlier this month, following Lowyat.net’s original report, and said it was planning a security upgrade for its systems.

Lowyat.net said it had handed over its information to the Malaysian Communications and Multimedia Commission (MCMC), which is working with police to investigate.

How well do you know the cloud? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Electric Vehicle Turned Away From Hospital Car Park

Liverpool's Alder Hey children's hospital turns away electric car from car park due to 'fire…

16 mins ago

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

3 days ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

3 days ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

3 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

4 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

4 days ago