Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious OutperformanceFind Stocks Now

Malaysia investigating reported leak of 46 million mobile users data

Published 11/01/2017, 07:00 AM
Updated 11/01/2017, 07:00 AM
© Reuters. FILE PHOTO: An illustration picture shows a network cable next to a pack of smartphones in Berlin

By Rozanna Latiff and Jeremy Wagstaff

KUALA LUMPUR/SINGAPORE (Reuters) - Malaysia is investigating an alleged attempt to sell the data of more than 46 million mobile phone subscribers online, in what appears to be one of the largest leaks of customer data in Asia.

The massive data breach, believed to affect almost the entire population of Malaysia, was first reported last month by Lowyat.net, a local technology news website. The website said it had received a tip-off that someone was trying to sell huge databases of personal information on its forums.

The country's internet regulator, the Malaysian Communications and Multimedia Commission (MCMC), was looking into the matter with the police, Communications and Multimedia Minister Salleh Said Keruak said on Wednesday.

"We have identified several potential sources of the leak and we should be able to complete the probe soon," Salleh told reporters at parliament.

The leaked data included lists of mobile phone numbers, identification card numbers, home addresses, and SIM card data of 46.2 million customers from at least 12 Malaysian mobile phone and mobile virtual network operators (MVNO).

LIKE EQUIFAX

Cybersecurity researchers said the leaked data was extensive enough to allow criminals to create fraudulent identities to make online purchases.

Justin Lie, CEO of Cashshield, a Singapore-based anti-fraud company, compared the Malaysian case in its "degree of complexity" to the cyber attack on U.S. credit-scoring agency Equifax Inc (NYSE:EFX), which said in September that cyber criminals had stolen sensitive information from 145.5 million people.

"Now these hackers have more quality information such as birth dates, IC numbers, mobile numbers, email address and passwords," Lie said about the Malaysian attack.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Customers of Malaysia's biggest mobile service providers, including Maxis (KL:MXSC), Axiata Group's Celcom (KL:AXIA) and DiGi (KL:DSOM), among others, were affected.

MCMC's chief operating officer Mazlan Ismail said on Tuesday the regulator had met with local telecommunications companies to seek their cooperation in the probe, according to state news agency Bernama.

Celcom and Maxis said in separate statements they were cooperating with authorities on the investigation. DiGi did not respond to requests for comment.

"ALMOST EVERY MALAYSIAN"

According to a Singapore-based cybersecurity researcher, the leaked database was initially being sold on several underground forums for 1 bitcoin, which was trading on Wednesday at around $6,500. At least one other user was posting a link for anyone to download for free.

The researcher, who declined to be named, said he had seen at least 10 people on an online forum in the "dark web" download the data before it was taken offline.

"Discussion in the dark web shows a huge interest," he said.

Time stamps indicate the leaked data was last updated between May and July 2014, Lowyat.net said.

"We are urging the telco and MVNO companies mentioned above to alert, and start immediately replacing the SIM cards, of all affected customers, especially those who have not updated their SIM cards since 2014," Lowyat.net said in a post.

Malaysia's population is just around 32 million, but many have several mobile numbers. The lists are also believed to include inactive numbers and temporary ones bought by visiting foreigners, The Star newspaper reported.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Bryce Boland, FireEye's chief technology officer in Asia Pacific, said if the data was widely available as suspected, it could be used for identity fraud and scams.

"This stolen data may ultimately impact almost every Malaysian," he said.

The data also includes private information of more than 80,000 individuals leaked from the records of the Malaysian Medical Council, the Malaysian Medical Association, and the Malaysian Dental Association, Lowyat.net said.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.