Personal data of nearly 4 million Malaysian citizens allegedly put on sale for 0.2 Bitcoin

It appears that there’s a potential data breach at the National Registration Department (JPN) as a database containing close to 4 million Malaysian citizens has been put on sale through an online forum. According to the seller, the data was freshly obtained from Jabatan Pendaftaran Negara and hasil.gov.my (Inland Revenue Board) through the MyIdentity API.

The database consists of 19 files in JSON/CSV format with a total size of 31.8GB. The person alleged that the current list contains details of individuals born between 1979 to 1998. The list includes personal details such as name, email, mobile number, permanent address, gender, IC number, race, religion, and even photos stored in base64 string.

The seller is asking for 0.2 Bitcoin (BTC) for the full list which is about RM35,000. Some interested buyers were asking for data narrowed down to selected cities but the seller prefer to sell the list in bulk.

At the time of writing, the MyIdentity portal is currently inaccessible. Launched in 2012, the platform was meant to make it easier for citizens and permanent residents to access and update their personal information when dealing with government agencies online. A total of 10 agencies were involved in the pilot project which includes National Registration Department, Malaysian Immigration Department, Road Transportation Department, Inland Revenue Board, Election Commission, Education Service Commission, Social Welfare Department, Labour Department of Peninsular Malaysia, National Higher Education Fund Corporation, and Royal Malaysian Police.

When another user asked for proof of authenticity, the seller shared personal details of a popular local celebrity based in Kuala Lumpur. The database appears to be legit as the image matches the actual person.

This potential data breach raises concerns about the security of the government’s online platforms especially when it involves the National Registration Department. Not only it exposes important details of Malaysians but the data can be misused for potential scams and phishing attack.

Under the MyDigital initiative, Malaysia aims to move 80% of public data to hybrid cloud systems by the end of 2022. In order to build trust, it is important for the government to strengthen cybersecurity for its platforms and to ensure resilience towards potential cyber-attacks.

[ SOURCE, IMAGE SOURCE ]

Recent Posts

Huawei Mate 80 Pro is coming to Malaysia on 12 March, early-bird customers get free Huawei MatePad 11.5 Standard

The candy bar Huawei Mate series smartphone is making a comeback on the global stage.…

3 hours ago

Maybank and TNB Electron launch EV charging pilot at Bangi, exploring rollout at selected branches

Maybank has partnered with Tenaga Nasional Berhad (TNB) through its EV charging arm TNB Electron,…

23 hours ago

Samsung Galaxy Buds 4 & Buds 4 Pro Malaysia: New looks, improved sound & battery life, head gestures, priced from RM699

In addition to the Galaxy S26, Samsung has also launched its latest true wireless earbuds,…

1 day ago

Leapmotor C10+: Upgraded 295hp motor, bigger battery with up to 510km range and faster 180kW DC Charging

Stellantis Malaysia has introduced its new Leapmotor C10 PLUS (C10+) for our local market. This…

1 day ago

Samsung Galaxy S26 Ultra: Privacy Display, overclocked Snapdragon 8 Elite Gen 5, brighter cameras, faster charging

The Samsung Galaxy S26 Ultra might have brought the biggest change to Samsung's flagship series…

2 days ago

Samsung Galaxy S26 & S26+: Minor spec tweaks, new AI call screening, agentic AI features

Samsung's latest flagship Galaxy S26 series is now official. The Galaxy S26 Ultra might get…

2 days ago

This website uses cookies.