Your personal data on sale – cheap


PETALING JAYA: The country’s cybersecurity is again under the spotlight as Malaysians’ personal data has been allegedly sold openly on the Internet for a few ringgit.

The existence of the website, highlighted by Twitter user @Radz1112, allowed a person to be searched by name, address, phone number, MyKad or military ID or date of birth.

Searching for someone via a MyKad number, for instance, would reveal the person’s full name, date of birth, gender and house address, claimed @Radz1112, who wanted to stay anonymous.

More detailed information, including MySejahtera vaccination info, loans and credit card applications, was hidden behind a paywall.

“OSINT (open source intelligence) tools are common and they display easily accessible information like a person’s social media, but this is one of the few instances where I am seeing country-specific database leaks being compiled in a single spot,” @Radz1112 said.

He said the website was found via a Google search and that the data might end up in the hands of those who could exploit it for financial gain or nefarious purposes.

“Granted that some of the information is paywalled, you can still do some harm if you have access to the right information,” he said.

Checks on the website found that apart from common data such as identification numbers and addresses, users could also get information based on car number plate and Companies Commission of Malaysia (SSM), among others.

It also contained information believed to be of agencies such as Election Commission, which could be acquired for just about RM20.

Those who wished to have their data removed from the database would have to pay RM436.

The Malaysian Personal Data Protection Department (PDPD) said it had requested for the website to be blocked.

“The website is no longer accessible,” a spokesperson said when contacted yesterday evening.

The Malaysian Communications and Multimedia Commission (MCMC) said they were providing technical assistance upon receiving requests from PDPD.

Chairman of cybersecurity firm LGMS Bhd and cybersecurity consultant Fong Choong Fook, who analysed the website, said it was likely created by Malaysians or people who were familiar with the local market.

“The data is specific to Malaysia and there is a page to inform users how to buy bitcoin locally to gain access to more information,” he said.

He said the website was likely created just this month, charging as little as 50 cents (RM2.20) for a person’s mobile number.

It also has three other plans offering various levels of access.

“Though the website is labelled as an OSINT tool, in reality, it is actually a pirate site which was put together using stolen information,” he said.

Prior to this, the same domain was used to host another website.

Intrusion analyst Adnan Mohd Shukor believed that the data might have been sourced from publicly available information, third party APIs (application programming interfaces) and possibly from previous data leaks.

He said his peers in the cybersecurity field found it troubling as the website had correlated the data and put it all under one website, allowing bad actors to easily acquire personal information of others.

Get 20% OFF The Star Digital Access

Monthly Plan

RM 13.90/month

RM 11.12/month

Billed as RM 11.12 for the 1st month, RM 13.90 thereafter.

Best Value

Annual Plan

RM 12.33/month

RM 9.87/month

Billed as RM 118.40 for the 1st year, RM 148 thereafter.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!
cybersecurity , personal data ,

Next In Nation

Synthetic drug abuse surges in Malaysia, youths account for over 84% of cases
Jais raids premises linked to Shiite teachings in Petaling Jaya
Marine police seize liqour, white cigarettes worth over RM3mil
Setiu enters MBOR with longest battered dish
RM1 durian draws crowd, 3,000kg sold out in five minutes
Nadi becomes model for other countries, says Fahmi
Govt urged to provide annual funding to support stray animal care
World's first anti-bullying tribunal: Madani govt's stand against bully culture, says Azalina
MetMalaysia warns of thunderstorms in six states until 8pm (June 27)
Johor polls: From 23 to 73, young blood and veterans join the fray

Others Also Read