Malaysian payment gateway platform iPay88 suffers data leak, card data may be compromised

If you typically use contactless payment methods, chances are that you’ve used iPay88 even without realising it. iPay88 is one of Malaysia’s biggest payment gateway platforms, providing point-of-sale solutions for plenty of merchants throughout Malaysia and the region.

As such, it’s understandably quite worrying to know then that iPay88 has suffered a cybersecurity breach, and that customer card data may have been compromised. They then state that, once they had found out about the issue on 31 May, they began investigating it and got cybersecurity experts to deal with the matter. iPay88 also stated that there’s been no further suspicious activity since 20 July, and that there’s new measures in place to prevent further incidents. On top of that, they’re already working together with the authorities over the issue too.

Among the major companies listed as iPay88 merchants include Shopee, KK Mart, Senheng, SenQ, Nandos, Machines, and more.

Here’s their statement in full:

“iPay88 would like to report that there was a cybersecurity incident where card data may have been potentially compromised.

Upon discovery of the issue, we immediately initiated an investigation on 31 May 2022 and brought in cybersecurity experts to contain the issue. The containment process was successfully completed and no further suspicious activity has been detected since 20 July 2022.

To ensure the continued safety of the card data, we have implemented various new measures and controls to strengthen the system’s security against any further incidents. The investigation is currently ongoing and we are working closely with the authorities and relevant parties on this matter. More updates and detailed findings will be shared in due course.

All financial institution partners have been informed and kept up to date. We will continue to monitor the situation closely and ensure the safety of the cardholder data,” – iPay88 statement

However, their statement has raised more questions than answers. For starters, iPay88’s statement did not reveal just how many customers and merchants were affected by this data breach. Furthermore, Lembah Pantai MP Fahmi Fadzil also wants to know why, despite having known of the breach back in May, did it take iPay88 this long to make the matter public. Furthermore, despite knowing of a data breach happening at least some time in May and lasting till July, they were still organising events, campaigns and promotions, such as partnering with Atome and taking part at the PJ Startup Festival 2022 while customers remained in the dark.

iPay88 was first founded back in 2000 in Malaysia by Chan Kok Long, Lim Kok Hing and Chong Lee Kean. They have a presence in seven countries across the continent, and would be acquired by NTT Data, a Japanese system integration company, in 2015.

Recent Posts

The Single-Stock Trap: Why True Tech Investing Means Moving Beyond a Few Famous Tickers

This post is brought to you by Eastspring Investments. If you are a regular reader…

6 hours ago

BYD will deploy Flash Charging stations in Malaysia. 10%-70% charge in 5 min, up to 1500kW

BYD will be bringing its latest EV charging technology to Malaysia which allows users to…

7 hours ago

Inokom assembled over 31,800 vehicles in 2025, exported 24,500 units across ASEAN from 2021-2025

Inokom Corporation Sdn Bhd (Inokom) has grown into one of Malaysia's established automotive contract assemblers…

2 days ago

Astro offers Disney+, Prime Video and Viu bundles from RM15/month

Astro has announced several new streaming bundles that combine popular streaming services such as Disney+,…

2 days ago

Lenovo Tab Plus Gen 2: 9-speaker JBL audio and 12.1-inch 2.5K display from RM2,099

Lenovo Malaysia has announced the new Tab Plus Gen 2 tablet, which offers a large…

2 days ago

Samsung unveils UFS 5.0 storage with 10.8GB/s speeds, built for next-gen AI smartphones

As smartphone makers continue to push more on-device AI features, there's a crucial need to…

2 days ago

This website uses cookies.