Personal data of over a million Malaysians might’ve been exposed online by MITI

When Malaysia first began rolling out the COVID-19 vaccines to the public, one of the protocols included the Ministry of International Trade and Industry (MITI) getting some companies in the manufacturing industry to register their employees via the Public-Private COVID-19 Industrial Immunisation Programme or PIKAS for short. However, a new report now claims that its website may be inadvertently exposing the details of over two thousand Malaysians who signed up for PIKAS.

According to a report from CodeBlue, who in turn got the information from a Dr Suresh Ramasamy on LinkedIn, a server under MITI’s PIKAS website at pikas.miti.gov.my seemingly had a directory that stored over two thousand files. These files are apparently the same files that companies had to upload onto the PIKAS website last year when PIKAS began in June 2021. Each file had the details of the company’s staff, which included their name, IC number, employee ID, age, gender and contact details.

It’s quite appalling that all this data is left in the open web, and that anyone can simply find their way to it. At time of writing though, the PIKAS website appears to be down and cannot be accessed. Dr Suresh asserts that there’s over a million records of personal information available to any bad actors in the PIKAS servers via these Excel files that anyone could’ve accessed. He also goes on to say that the entire PIKAS programs seemed to have been relying on this one directory for their information.

As Dr Suresh mentions in this post, the storage directory was left open along with many others, so it could’ve been left open intentionally. He notes that there was another directory called logs with files in it called ‘laravel’. These refer to laravel logs that were left open as according to Dr Suresh, the vendor may have needed access to troubleshoot the system. As for why the Excel files were left out in the open though, Dr Suresh says it could’ve been their IT department leaving it open to that they can work on it remotely, or needing to transfer files around the servers. Bad actors within could’ve also left it open.

Nevertheless, we’ll need to wait for MITI to release a statement to get a better idea of what happened, especially considering that the PIKAS website is now unavailable. CyberSecurity Malaysia meanwhile seemed to have known about this potential data leak already, with CodeBlue noting that they had told Dr Suresh that they’ve taken action to ‘notify and advice the respective party accordingly’. An email from CyberSecurity Malaysia dated 27 May then closed the case on Dr Suresh’s complaint that he had filed with them on 22 May.

This makes it just the latest data leak in Malaysia in the last couple of weeks. Back in May, a JPN database containing the personal details of approximately 22.5 million Malaysians were found for sale online. The seller for that one even provided the personal data of Home Affairs Minister Dato Seri Hamzah bin Zainudin for evidence. You can read more about that here.

[ SOURCE 2 ]

Recent Posts

Realme 16 and 16T Malaysia: Slim 7,000mAh and 8,000mAh battery smartphones, now available from RM1,299

Realme Malaysia has officially launched the Realme 16 and Realme 16T which focuses on long…

17 hours ago

JomCharge offers 50% discount for Solaris Mont Kiara EV chargers for this weekend only

JomCharge and DBKL officially announce their EV charger #21 located at Solaris Mont Kiara. The…

1 day ago

Malaysia EV registrations rise 21% in May 2026 despite overall car market decline of 11%

Malaysia's electric vehicle (EV) market continues to show growth in May 2026, with registrations growing…

1 day ago

Hyundai Ioniq 5 N and Ioniq 6 N launched in Malaysia with up to 641hp, from RM443,888

Hyundai Motor Malaysia has officially launched the Hyundai Ioniq 5 N and Hyundai Ioniq 6…

2 days ago

Proton e.MAS 7 Premium Plus delivers up to 450km WLTP, priced from RM119k

Pro-Net has officially unveiled the 3rd variant for Proton e.MAS 7 family at the ongoing…

2 days ago

Zeekr 009 Grand and Zeekr 9X now open for booking in Malaysia, priced from RM600,000

Zeekr Malaysia has revealed its two flagship models at KLIMS 2026, with the Zeekr 9X…

2 days ago

This website uses cookies.