• 中文版
  • BM
  • News
  • Deals
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Tech
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • Tune Talk
    • U Mobile
    • Unifi
    • Yes
  • Cars
  • Contribute
  • Jobs
Menu
  • 中文版
  • BM
  • News
  • Deals
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Tech
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • Tune Talk
    • U Mobile
    • Unifi
    • Yes
  • Cars
  • Contribute
  • Jobs
Search
  • Tech
    • News
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • U Mobile
    • Unifi
    • Yes
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Buyer’s Guide
  • Opinions
  • Digital Life
  • Video
  • Deals
  • How-To
  • Cars
  • Bahasa Melayu
  • EV
  • Contribute
  • Advertise
Menu
  • Tech
    • News
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • U Mobile
    • Unifi
    • Yes
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Buyer’s Guide
  • Opinions
  • Digital Life
  • Video
  • Deals
  • How-To
  • Cars
  • Bahasa Melayu
  • EV
  • Contribute
  • Advertise
Search
Close
Home Digital Life

PADU: Critical password flaw found within hours of launch

  • BY Chief Chapree
  • 3 January 2024
  • 11:46 am
  • Comment
PADU Login Page
Share on FacebookShare on Twitter

Pangkalan Data Utama (PADU) made its official debut yesterday after a grand launch event in Putrajaya. However, several flaws were discovered inside the government’s latest signature digital project within just hours of its public rollout.

This critical flaw revolves around the user’s password  

While the most talked about flaw was the MyKad-related issue which was raised by the former Deputy Minister of International Trade and Industry, Ong Kian Ming, there was another issue with the centralized database that is even more critical. According to developer and X user @drmsr_dev, the user password for PADU account can be changed easily just by using one’s IC number.

Guess what.

I only need your IC number to override and change your PADU login password.@farhanhelmycode @rafiziramli @Dr_Uzir @lamkanahraf pic.twitter.com/m1K2mR3wP2

— useState('drmsr') (@drmsr_dev) January 2, 2024

In a set of screenshots that were shared through the popular social media platform, drmsr_dev demonstrated that this flaw can be taken advantage of easily through API calls by someone savvy enough. He has since published an in-depth analysis of the security flaw through his Hashnode blog.

The Ministry of Economy acknowledged the security issue

A few hours after this issue was exposed to the public, drmsr_dev noted in a follow-up tweet that the team behind PADU had changed the API to fix the flaw. In addition to that, the Ministry of Economy has since acknowledged the flaw through a tweet earlier today.

https://twitter.com/EkonomiMalaysia/status/1742340318828413162

Aside from saying that the agency is constantly monitoring feedback from the public, the tweet also noted that improvements are currently being implemented as we speak. Furthermore, the ministry deemed the discovery of the flaw and subsequent feedback as a “positive criticism”.

This may affect the public’s opinion of PADU

Since it deals with personal data that belongs to millions of Malaysians, security has always been a lingering concern for PADU. The discovery of this critical flaw certainly doesn’t help its reputation.

In many ways, it may shake the public’s confidence in the new centralized database which is supposed to help improve government policies and subsidy distribution. Let’s not forget that there have been so many data leak incidents involving government agencies such as SOCSO, JPN, and MCMC.

PADU
Despite all these cybersecurity policies, why does the password flaw still happen?

PADU can only meet its objective properly if it can obtain up-to-date details from the majority of the population. If the Rakyat is not confident of the government’s capability to keep their data safe and refuses to submit their details, what will then happen to the project which costs millions of Ringgit?

Many have begun to wonder if PADU has gone through enough testing or proper security audits before it went live yesterday.  Even though credit must be given to the PADU’s administrator who swiftly fixed the flaw despite being discovered after working hours, it is something that should not happened in the first place.

Tags: Central Database Hubpadupadu databasepangkalan data utama
Chief Chapree

Chief Chapree

POPULAR

PADU Login Page

PADU: Critical password flaw found within hours of launch

January 3, 2024
BYD Tech Discovery KL

MITI’s CBU EV ruling will wipe out current EV lineup from BYD, iCaur, Mini, Smart, Toyota, and more

May 7, 2026
Proton EV Plant, Tanjung Malim

MITI says EVs won’t become more expensive, but can Malaysia’s CKD industry fill the gap?

May 10, 2026

Maxis Home Solar now offers outright purchase option, with up to 80% electricity bill savings

May 11, 2026

The Best Camera is the One You Have with You; The OPPO Find X9 Ultra Wants to be Your Only One

May 6, 2026
Rear view of the OPPO Find X9 Ultra in Tundra Umber standing vertically on a stone surface with a lush green bokeh background. The device features an eco-friendly vegan leather back with a classic stitching design , vertically oriented Hasselblad and OPPO logos , and a large circular Master Lens camera module with a bronze-toned knurled ring.

Clearing Every Expectation: How the OPPO Find X9 Ultra Redefines the Modern Flagship Experience

April 16, 2026

Copyright © 2025 · SoyaCincau.com
Mind Blow Sdn Bhd (1076827-P)

  • ADVERTISE
  • DISCLAIMER

Copyright © 2026 · SoyaCincau.com – Mind Blow Sdn Bhd (1076827-P)

  • ADVERTISE
  • DISCLAIMER