QUOTE(tkyong1 @ Apr 26 2023, 09:44 PM)
AKPK customer portal still down?
Received an email earlier this morning...
AKPK: Cybersecurity Breach
Dear Customer,
We are writing to let you know that Agensi Kaunseling & Pengurusan Kredit (AKPK) recently detected a breach of one of its IT systems and has determined that some data exfiltrated by the cybercriminals was published on the dark web today.
While our investigation with third-party cybersecurity experts is continuing, it appears that approximately 20 customers have had their names and National Registration Identity Card (NRIC) numbers published.
What Actions Have We Taken?
Following the malicious and criminal breach of our IT system, we notified the authorities, took measures to secure our server, and began an investigation with leading third-party cybersecurity experts. AKPK received and rejected a ransom request, a response relevant authorities and experts agreed with.
As a result of the breach, we decided to take some of our operational systems offline temporarily to prevent further risks. We are gradually bringing our systems back online and can confirm that the process is almost completed. In the meantime, we continue to have relevant arrangements in place to maintain our services to our customers with as little disruption as possible.
What Can You Do?
While it is not yet clear exactly what customer data has been accessed and whose, we are encouraging all customers to take a number of steps to safeguard themselves. We would recommend that customers consider taking the following precautionary actions for themselves:
Monitor accounts that use personal data;
Change the login credentials for online accounts, including but not limited to those used to access AKPK services;
Use strong passwords and change them regularly. Try to keep password at least eight characters long and use numbers, upper case, lower case and symbols;
Enable two-factor authentication on all your online services where possible;
Be suspicious if anyone contacts you by email, phone call or text message asking you to confirm your personal details. Never give out personal details unless you’re sure who you’re speaking or writing to; and
Check your bank and credit card statements regularly for any unusual payments that you don’t recognise.
For general personal safety and identity protection online customers can refer to the CyberSecurity Malaysia guidelines:
https://www.cybersecurity.my/data/content_files/11/763.pdf We understand this situation is very concerning and we sincerely apologise. AKPK will continue to do everything we can to mitigate the impact of this breach, and will provide further updates when we are in a position to do so.
We are addressing customer concerns and questions through our dedicated call center and website. AKPK customers can contact AKPK’s dedicated call centre at 03 2616 7766 or click
https://www.akpk.org.my/branches to find the nearest AKPK branches.
We will take additional actions as needed based on investigations underway and in cooperation with the authorities.
We thank you for your ongoing support and understanding during this trying time.
Yours Sincerely,
Mansor Ali
General Manager, Operations and Business Development Division
26 April 2023