EXEPERTAI LAB
EXEPERT / DIRECTORY
← Blog

Recycled Records, an Insider Lookup and a Claimed Sale: Malaysia's Personal-Data Incidents, June to September 2026

A follow-up to our lookup-site report. Three Malaysian incidents in four months show three failure modes: pre-2022 breach data still circulating, an unauthorised lookup of one telco customer's account, and a claimed sale of a delivery platform's database. What is established, what is claimed, and what helps.

Akmal Alif · 9 October 2026 MYT

Three panels in a row: faded paper records drifting out of an old archive box, a single customer card lit up under a desk lamp beside an access log, and a delivery map pinned with location dots next to a padlock that hangs open.
Three panels in a row: faded paper records drifting out of an old archive box, a single customer card lit up under a desk lamp beside an access log, and a delivery map pinned with location dots next to a padlock that hangs open.
Three failure modes in four months: old breaches that keep circulating, an insider lookup, and a platform holding identity, money and location together.

Editorial and privacy note

This report covers public posts, news reports and official statements about three personal-data incidents in Malaysia. EXEPERT did not access, buy or download any leaked data, and none is reproduced here. That includes the personal details mentioned in news coverage of the second case.

Some embeds load only when you choose. The Facebook post shows a screenshot of a threat-intelligence account's summary of a claimed sale; we checked that it lists categories and counts, not records. The Threads embed may show media from the original post. The news sites do not allow framing, so they appear as link cards.

Why a follow-up

Our September report on the personal-data lookup case examined a June 2026 Threads post about a site displaying Malaysians' personal information, and what the official record does and does not establish. Since June, two more cases have shown different ways personal data escapes. Read together, the three describe distinct failure modes, each with a different fix.

June: records that never stop circulating

On 19 June 2026 a public Threads post by @belumsetel renewed attention on a searchable site that appeared to show Malaysians' personal information (belumsetel, 2026).

On 21 June the National Security Council, through the National Cyber Security Agency (NACSA), said the information was believed to come from intrusions into various systems before 2022. It was being redistributed online without authorisation and was not linked to any current platform (Malay Mail, 2026a). The council said the following:

  • Using such services is an offence. Providing, disseminating or granting access to unlawfully obtained information is an offence under Malaysian law, even if the service is hosted abroad.

  • Takedowns are under way. NACSA, MyNIC and the Personal Data Protection Department (JPDP) were working with foreign providers to remove and block the sites.

  • Police are investigating. The police were conducting a digital-forensic investigation.

  • New law is coming. It pointed to the Cyber Crime Bill, which would cover unauthorised access and identity theft.

  • MyDigital ID is not a data store. The council said the national digital identity is an identity-verification platform, not a store of personal data.

Our earlier report covers this case and its history in detail.

The failure mode: breached data does not expire. Old records are recombined, repackaged and resold, so every past breach keeps creating risk long after the headlines end.

July: an insider lookup at a telco

In July the case was not an old dump but a single account. A Threads user publicly claimed to know details of the phone bill of entrepreneur and content creator Khairul Aming. Khairul Aming then asked Maxis how that information had been obtained (Malay Mail, 2026b; New Straits Times, 2026).

Maxis's statement, as reported (New Straits Times, 2026):

  • The individual is identified. Maxis said it had identified the individual linked to the incident and was taking action, including legal action.

  • An apology. It apologised.

  • An isolated case. Its investigation found an isolated case of unauthorised access to one customer's account details.

  • Access is logged. It said all access to customer accounts is recorded and monitored.

Maxis did not publicly say who the individual was or what role they held.

The regulators responded:

  • JPDP opened an investigation. It acted under the Personal Data Protection Principles and Section 130 of the Personal Data Protection Act 2010, which covers the unlawful collection or disclosure of personal data. Penalties would follow if the company were found not to have complied (Malay Mail, 2026b).

  • The minister ordered a report. Communications Minister Fahmi Fadzil directed the Malaysian Communications and Multimedia Commission (MCMC) to obtain a full report. Fahmi said the allegations suggested people without authorisation could see data in the telco's internal systems, and urged other victims to report to MCMC (Malay Mail, 2026b).

Khairul Aming said on Threads that a lawyer had sent Maxis a letter of demand. Reports had also been made to MCMC, to the police at the Dang Wangi district headquarters, and to JPDP. Khairul Aming described the exposed information in general terms: phone details, payment history, subscriptions and an identity-card number that could be used with other services. Khairul Aming said it felt "sad and scared" that privacy could be lost so easily (Halim, 2026).

We found no public report of the outcome of the JPDP or MCMC processes.

The failure mode: authorised access, misused. Logging helped Maxis identify the person afterwards, but it did not stop the lookup. Customer-record systems need least-privilege access, a reason recorded for each lookup and alerts on unusual access, not just an audit trail.

September: a claimed database sale

On 8 September 2026 a threat-intelligence account on X relayed a seller's claim to be offering a database belonging to Misi Rakyat, a Malaysian platform in the Misi delivery ecosystem. The Facebook page OMG Hackers shared a screenshot of that summary, and the post spread widely (OMG Hackers, 2026). As reported, the seller claimed the data was current to 7 September and included (Kosmo!, 2026):

  • about 300,000 customer records with names, contact details, addresses and location coordinates;

  • about 22,500 delivery-rider records with identity details including identity-card numbers, vehicle and licence information, and location;

  • about 28,500 vendor records including bank details;

  • around 1.88 million e-wallet transactions.

These are the seller's claims. The original summary itself noted that size, freshness and provenance had not been independently verified.

Misi's founder, Nur Ahmad Faiz, said the company's cyber-security team had begun an internal investigation to verify the claim and determine whether any unauthorised access occurred. The company was working with the authorities under the PDPA. Nur Ahmad Faiz also warned users to be wary of calls, emails or messages claiming to come from Misi, and not to share personal information or passwords (Kosmo!, 2026). A separate incident affecting the Misi Rakyat website was investigated by JPDP in 2023 (Business Today, 2023). We found no public finding on the September 2026 claim.

The failure mode: a platform that holds identity, money and live location together. If even part of the claim is true, that combination matters. Location data adds physical risk, and rider records carry identity-card numbers that can be used for impersonation.

What the three cases have in common

They are different problems: legacy breaches recirculating, an insider looking up an account, and a third-party platform's alleged database. Each sits under the same law, which changed in 2025.

Amendments to the Personal Data Protection Act that came into force on 1 June 2025 require organisations to notify the Personal Data Protection Commissioner of personal-data breaches. Where significant harm is likely, they must also notify the affected people. Our earlier report lists that commencement in its timeline.

What readers can do:

  • Do not use lookup services. NACSA has said obtaining or using services that offer unlawfully acquired data is itself an offence.

  • Expect targeted scams. After any of these incidents, expect phishing that uses real details to sound credible. Verify through official channels, and never share one-time passwords.

  • Report. Use the channels the authorities named: the police, MCMC and, for personal-data complaints, JPDP.

  • Ask the right questions. Ask platforms you use how customer records are accessed, logged and reviewed, and how they would tell you about a breach.

For organisations, the July case is the instructive one. The question is not only whether an intruder can get in, but whether someone already inside can look up a customer without a reason, and how quickly you would know.

References

belumsetel. (2026, June 19). [Post about a site displaying Malaysians' personal information] [Threads post]. Threads. https://www.threads.com/@belumsetel/post/DZwoGhZE5a3

Business Today. (2023, July 14). PDP investigating allegation of personal data leakage incident of Misi Rakyat website. https://www.businesstoday.com.my/2023/07/14/pdp-investigating-allegation-of-personal-data-leakage-incident-of-misi-rakyat-website/

Halim, U. (2026, July 22). Kes kebocoran data peribadi, peguam Khairul Aming hantar LOD kepada syarikat telco – "Saya rasa sedih, seram…" [Personal data leak case: Khairul Aming's lawyer sends letter of demand to telco – "I feel sad, scared…"]. Gempak. https://gempak.com/hiburan/kes-kebocoran-data-peribadi-peguam-khairul-aming-hantar-lod-kepada-syarikat-telco-saya-rasa-sedih

Kosmo!. (2026, September 8). Misi siasat dakwaan kebocoran data lebih 300,000 pelanggan [Misi investigates alleged data leak involving more than 300,000 customers]. Kosmo! Online. https://www.kosmo.com.my/2026/09/08/misi-siasat-dakwaan-kebocoran-data-lebih-300000-pelanggan/

Malay Mail. (2026a, June 21). Viral data-leak claims stem from pre-2022 intrusions, unrelated to current systems, says National Security Council. https://www.malaymail.com/news/malaysia/2026/06/21/viral-dataleak-claims-stem-from-pre2022-intrusions-unrelated-to-current-systems-says-national-security-council/224650

Malay Mail. (2026b, July 22). Personal Data Protection Department investigates Maxis over Khairul Aming data leak. https://www.malaymail.com/news/malaysia/2026/07/22/personal-data-protection-department-investigates-maxis-over-khairul-aming-data-leak/228568

New Straits Times. (2026, July 21). Maxis identifies individual behind Khairul Aming data leak, apologises for breach. https://www.nst.com.my/news/nation/2026/07/1494201/maxis-identifies-individual-behind-khairul-aming-data-leak-apologises

OMG Hackers. (2026, September). Data Misi Rakyat didakwa dijual di pasaran gelap [Misi Rakyat data allegedly sold on the dark market] [Image attached] [Status update]. Facebook. https://www.facebook.com/photo/?fbid=122222728406550925&set=a.122093944358550925