CSIDB logo
Incident

Ifmal

Incident posture

Attack window
Feb 2021
Location
Malaysia
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
Ifmal
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A seller advertised a database allegedly containing personal details of 200,000 Malaysians, including names, addresses, phone numbers, and national identification numbers, claiming it originated from a local e-commerce platform. The platform denied involvement, asserting it never collected identification numbers and maintained a smaller customer base than the dataset suggested. Independent verification confirmed the platform's registration process did not request such sensitive information, casting doubt on the legitimacy of the seller's attribution. Despite unresolved questions regarding the data's true source, the incident highlighted potential exposure of citizens' personal information, prompting calls for official scrutiny.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around February 6, 2021, an online seller listed a database purportedly containing personal details of 200,000 Malaysians for sale on an underground marketplace. The seller claimed the data originated from Ifmal, a local e-commerce platform, and included sensitive information such as full names, physical addresses, phone numbers, and national identification card (IC) numbers. This listing appeared on the same platform that had recently featured the alleged E-Pay Malaysia database leak, suggesting a pattern of similar malicious activity. Ifmal swiftly denied any involvement or ownership of the leaked database through an official statement on its Facebook page. The company asserted its customer database was significantly smaller than 200,000 records and emphasized it had never collected IC numbers during user registration or transactions.

Independent verification by Lowyat.NET confirmed inconsistencies between the leaked dataset's characteristics and Ifmal's actual data collection practices. Examination of Ifmal's registration process revealed the platform only requested standard e-commerce details like names, addresses, and phone numbers, with no IC number field present. This discrepancy raised critical questions about the database's true origin and authenticity, though the seller maintained their attribution to Ifmal. Despite unresolved questions regarding the data's provenance, the incident highlighted potential risks to Malaysian citizens' privacy, prompting calls for authorities to investigate the listing's legitimacy. The lack of corroborating evidence linking the data to Ifmal left the breach's scope, attack vector, and responsible parties unconfirmed, with no public disclosure of containment measures or forensic findings by the implicated platform.

Sources

Sources available to members: 1 source.

CSIDB