Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

> M’sia sees biggest mobile data breach News

views
     
TSsmallbug
post Oct 31 2017, 10:04 AM, updated 9y ago

Enthusiast
*****
Senior Member
874 posts

Joined: Nov 2005


https://www.thestar.com.my/news/nation/2017...cam-attacks-an/

PETALING JAYA: The personal details of some 46.2 million mobile number subscribers in Malaysia are at stake in what is believed to be one of the largest data breaches ever seen in the country.

From home addresses and MyKad numbers to SIM card information, the private details of almost the entire population may have fallen into the wrong hands.

Malaysia’s population is only around 32 million, but many have several mobile numbers. The list is also believed to include inactive numbers and temporary ones bought by visiting foreigners.

With this leak, Malaysians may be vulnerable to social engineering attacks and in a worst-case scenario, phones may be cloned.

It is also said that 81,309 records from the Malaysian Medical Council, Malaysian Medical Association (MMA) and Malaysian Dental Association were also leaked.

The leak of the mobile data was reported earlier this month on online forum and news site lowyat.net, which reported that it was thought to originate from a massive data breach in 2014.

Yesterday, the site “confirmed” that 46.2 million mobile numbers were leaked online.

Lowyat.net founder Vijandren Ramadass told The Star that all information it received on the matter was handed over to the Malaysian Communications and Multimedia Commission (MCMC).

Asked what sort of action would be needed, he said: “Telcos need to admit that this breach actually happened and should inform all their customers what should be done.”

It is believed that the MCMC and police are collaborating on the investigation.

Network and security strategist Gavin Chow said the most common social engineering attack examples were phone and messaging scams.

“Scammers pretend to be someone calling or texting from the telco since they can prove they have the target’s personal details,” said Chow, who is with cybersecurity and malware protection company Fortinet.

He added that the scammers would then try to trick the victim in various ways.

These include transferring funds into their accounts and installing “telco applications” containing malware or spyware, which will be used to exploit the target in future.

“The devices would likely not be hacked directly, but anyone with the data dump information and a little creativity may convince unsuspecting victims to install malware on their devices.

“Users need to be alert when receiving calls and messages from strangers. Do not get tricked into sharing more personal details, transferring funds or installing apps,” he said.

Technology strategist Dinesh Nair said there was not much that consumers could do, but they should change their SIM card, for starters.

“Your name, address, phone number, the IMSI (international mobile subscriber identity) and the IMEI (international Mobile Equipment Identity), which are tied to your device are all out there.

“I’m sure my data is there as well. People with really good technical skills will be able to clone someone’s phone and that’s the worst-case scenario,” he said.

Dinesh added that while no one knew where the breach occurred, the fact that the details were out there pointed to a leak of some sort.

“How it happened, we can’t tell but with so much released from different telcos at the same time, it must come from a single source,” he added.

Bar Council cyber law and information technology committee co-chairman Foong Cheng Leong said assuming that the leak was after the enforcement of the Personal Data Protection Act 2010, there might have been a breach of the Act’s Security Principle by the data users.

“The Security Principle requires data users to process personal data securely, but there is not much customers can do other than file a complaint with the Personal Data Protection Commissioner,” he said.

Digi said in a statement that it prioritised the privacy of its customer data.

“The authorities are looking into the matter and we’ll continue to support them,” the statement read.

Celcom Axiata Bhd said it was “collaborating closely with the authorities to assist in the investigation”, a sentiment echoed by Maxis Bhd, which also said it “fully supports the investigation”.

Representatives from U Mobile declined to speak about the leak, while representatives of TuneTalk could not be contacted for comments at press time.

MMA president Dr Ravindran R. Naidu said a police report was lodged more than a week ago when news of the leak surfaced.

“Of course, no system is unhackable. Even the US Department of Defence has been hacked.

“However, we have been in the process of upgrading our IT system for the last year or so and the new servers will be more secure.

“We will also be upgrading our operational security measures and introducing a new SOP for our staff to minimise the risk of a repeat of this episode,” he said.


Baconateer
post Oct 31 2017, 10:05 AM

Meh..... (TM)
*******
Senior Member
5,088 posts

Joined: Jun 2013
From: Blue Planet


SELOW
HeartR0bber
post Oct 31 2017, 10:09 AM

Getting Started
**
Junior Member
141 posts

Joined: Feb 2015
its not the biggest, its like a whole nation issue
s@ni
post Oct 31 2017, 10:09 AM

Gambar Di Lesen Kereta Saya
*******
Senior Member
2,842 posts

Joined: Jun 2005
From: Seasaw



with this news, IT security supplier/consultant will flourish.

se7en thank you

p/s: im not related in any way within the IT security industry
DarkAeon
post Oct 31 2017, 10:11 AM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
"boss, macam mana skrg? apa kita nak buat"

"tenang dulu, lepas minum pagi kita pi tangkap whistleblower"

"ohhh....pandainya tuan"
SUSeksk
post Oct 31 2017, 10:15 AM

On my way
****
Junior Member
586 posts

Joined: Oct 2004
why post news in forum when it has been posted in the front page of lowyat.net...
Efalex
post Oct 31 2017, 10:18 AM

Casual
***
Junior Member
361 posts

Joined: Jun 2007
Got PM and Big Mama data in the list?
alien3d
post Oct 31 2017, 10:19 AM

Look at all my stars!!
*******
Senior Member
3,740 posts

Joined: Mar 2009
hehee.. i hope seven is alive.
SinzChan
post Oct 31 2017, 10:20 AM

Getting Started
**
Junior Member
127 posts

Joined: Oct 2011
this is a national security issue d...
SUScrash123
post Oct 31 2017, 10:21 AM

Getting Started
**
Junior Member
271 posts

Joined: Aug 2011
Seven in trouble
RobUlstan
post Oct 31 2017, 10:22 AM

Getting Started
**
Junior Member
101 posts

Joined: Dec 2010
Yaayy Malaysia no 1 again.
WutDePhuc
post Oct 31 2017, 10:22 AM

New Member
*
Junior Member
21 posts

Joined: Apr 2015
got demand, got money, got hack
MR_alien
post Oct 31 2017, 10:25 AM

Mr.Alien on the loss
*******
Senior Member
3,581 posts

Joined: Oct 2007
From: everywhere in sabah



FAKE NEWS
DENY
what else?
blueblueoutofblue
post Oct 31 2017, 10:26 AM

Regular
******
Senior Member
1,683 posts

Joined: Dec 2011
It's frightening someone call you and say he know you and where you stay...
Wolgie
post Oct 31 2017, 10:28 AM

Look at all my stars!!
*******
Senior Member
2,640 posts

Joined: Jun 2009
QUOTE(blueblueoutofblue @ Oct 31 2017, 10:26 AM)
It's frightening someone call you and say he know you and where you stay...
*
Vey easy know where u stay. We got FB
blueblueoutofblue
post Oct 31 2017, 10:29 AM

Regular
******
Senior Member
1,683 posts

Joined: Dec 2011
QUOTE(Wolgie @ Oct 31 2017, 10:28 AM)
Vey easy know where u stay. We got FB
*
Fb can be fake and use vpn tongue.gif
darkluxus313
post Oct 31 2017, 10:31 AM

New Member
*
Newbie
4 posts

Joined: Jul 2013
Population 32 mil

Data breaches 46 mil

Dayum
2387581
post Oct 31 2017, 11:33 AM

Enthusiast
*****
Senior Member
756 posts

Joined: Dec 2016
How much are the telcos making for selling the data?
WinkyJr
post Oct 31 2017, 11:40 AM

Casual
***
Junior Member
432 posts

Joined: Jul 2010

QUOTE(DarkAeon @ Oct 31 2017, 10:11 AM)
"boss, macam mana skrg? apa kita nak buat"

"tenang dulu, lepas minum pagi kita pi tangkap whistleblower"

"ohhh....pandainya tuan"
*
plot twist, the boss is the whistleblower
haroldz123
post Oct 31 2017, 12:32 PM

Regular
******
Senior Member
1,062 posts

Joined: May 2008
National security issue but mass media gags order


dadurtyz
post Oct 31 2017, 12:34 PM

On my way
****
Senior Member
658 posts

Joined: May 2006
From: Melaka



QUOTE(blueblueoutofblue @ Oct 31 2017, 10:29 AM)
Fb can be fake and use vpn tongue.gif
*
U thinks thise typical girl/awek/amoi know this things? Last time instagram even worse! The apps give location where the people upload it, now i dont see that option anymore

Bump Topic Add ReplyOptions New Topic
 

Change to:
| Lo-Fi Version
0.0158sec    0.49    5 queries    GZIP Disabled
Time is now: 12th December 2025 - 06:36 AM