Enhanced safeguards introduced following disruption to services across multiple local councils
A CYBERATTACK on June 29 halted parking payments, compound settlements and enforcement functions on the Flexi Parking platform, affecting public-sector and privately operated sites from Peninsular Malaysia to Sabah.
Instead of restoring services on the compromised network, Flexi Parking developer Leading Innovative Technologies & Systems Sdn Bhd (LITS) opted to rebuild its entire system.
ALSO READ: Compensation in spotlight after parking system outage
LITS chief executive officer Lai Thiam Sin said the company could have cleaned the affected servers and restored services within hours.
“However, we did not know what the intruder knew, and decided it was safer to shut everything down and rebuild,” he told StarMetro.

LITS built new virtual servers, migrated its code, reconstructed the supporting network, moved operations to a new virtual private network (VPN) and reset passwords and security keys.
“We did not want them to know where the rest of the servers were, so we shut everything down and moved to a new VPN,” Lai explained.
ALSO READ: ‘Need for sustained defences to battle threats’
“The compromised servers were isolated, decommissioned and imaged for forensic examination,” he said.
CyberSecurity Malaysia (CSM) was carrying out a post-mortem on the incident, he added.
When contacted, a CSM spokesperson declined to comment on matters concerning the LITS Flexi Parking cyber incident as it fell within the company’s purview.
What transpired
Lai said the breach occurred while LITS was migrating ageing virtual servers and software to newer cloud infrastructure on June 28.
He said some folder permissions were inadvertently left open during the time.
He likened the migration to moving house and leaving the gate open.
The attacker gained access to a legacy server at about 9am the following day, he said.
“During migration, you open up a lot of things. That is where the intruders came in.
“We left our credentials inside the servers to transfer files. Some older codes were removed and we were attacked through those codes,” said Lai.
A security key left on the server for file transfers had probably enabled the intrusion, he said, although access was confined to that machine.
“Once we disconnected it from the rest of the network, the attacker could not reach the other servers,” he added.
The attackers used backend administrative tools to send unauthorised app notifications and deface a local council enforcement page, said Lai.
Initially believing it to be a website defacement, LITS removed unfamiliar files from its servers.
However, monitoring alerts later showed databases were being deleted.
“Our monitoring bots alerted us that databases were disappearing.
“We immediately shut everything down to stop it from spreading.
“Our priority was to protect users’ information and the other servers,” Lai said.
He said preliminary checks on database logs found no evidence that attackers had viewed or downloaded users’ data.
“The logs showed they were trying to delete databases and tables rather than download them,” he said.
Lai said the findings remained preliminary, pending CSM’s post-mortem.
He also disputed the attacker’s claim of accessing data belonging to seven million users.
LITS has 5.7 million registered users across Flexi Parking, Smart Selangor Parking and Sabah Smart Parking.
Lai said the figure cited by the attacker likely came from a login table containing about 6.5 million to 6.7 million entries because users appeared multiple times if they were using the apps in different local council jurisdictions.
The table contained login timestamps and user identification numbers, but not names, email addresses, identity card numbers or passwords, he added.
Lai said a screenshot shared by the attacker appeared to show root access to an older server.
Beefing up security
Following the incident, LITS changed its migration and backup procedures, so backup systems now retrieve data from cloud servers instead of relying on credentials stored on them.
The company has also strengthened
server monitoring, enhanced detection of suspicious Internet protocol addresses and unusual server activity.
LITS has also reviewed its login systems, coding practices, backup procedures, software deployment processes and legacy files, Lai said.
“Penetration testing was done before the rebuilt platform was brought back online.
“When we started building Flexi Parking and expanded council by council, some older codes remained,” he said.
The company also plans to brief local authorities’ information technology personnel on lessons from the attack
and security measures that could strengthen connected systems.
“There are many lessons from this incident.
“Some of the security measures we introduced could also benefit the local councils,” Lai said.
Shah Alam City Council (MBSA), in a statement responding to StarMetro’s questions, said it took note of LITS’ explanation concerning the recovery and security improvements introduced after the outage.
MBSA said it would continue monitoring the measures and ensure the service provider complied with security requirements and contractual terms.
StarMetro also contacted Subang Jaya City Council and Kajang Municipal Council for comments on revenue losses, compounds issued during the outage and possible compensation from LITS, but both had yet to respond at press time.

