• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Over 10 million Malaysian citizenship information was leaked due to SQLi bug
  • Data Leak

Over 10 million Malaysian citizenship information was leaked due to SQLi bug

Ddos June 11, 2018 3 minutes read
10 million Malaysian citizenship information

According to Malaysian media, Malay Mail reports, the School Examination Analysis System (SAPS), launched by the Malaysian Ministry of Education, was forced to go offline after finding a security breach that could expose more than 10 million citizens’ personal information.

The report pointed out that an anonymous reader said to Malay Mail on Friday evening that the Ministry of Education had previously ignored his warnings and forced him to seek help from the media.

After consulting with technical blogger Keith Rozario and Khairil Yusof, co-founder of the local technology advocacy organization Sinar Project, Malay Mail alerted to the Malaysian Computer Emergency Response Team (MyCERT). MyCERT responded to Malay Mail on Saturday at noon and the system was also offline the same day later.

SAPS is an entry for test scores. Students or parents can access student test scores online by entering the student’s MyKad number. Of course, these data can also be retrieved by the regional education offices, national registration authorities and the Ministry of Education.

“Great system, but the backend is a total failure They store millions of records of students’ detail, but they never hide this information. Some very personal details can be accessed without permission, and they are just ignoring it. The system has been flawed since day one,” the anonymous reader replied.

SAPS was launched in 2011. The reader told Malay Mail that this vulnerability was discovered only recently by the Ministry of Education after updating the SAPS interface.

The anonymous reader claimed that he could download more than 4.9 million (4,940,203) students’ data from the server because each parent’s personal information was associated with their child’s individual, so there may be a total of more than 10.3 million Malaysian Citizens are affected.

According to statistics released by the Department of Statistics Malaysia in the first quarter of this year, there are currently 28.7 million citizens in Malaysia, which means that data leakage may have affected more than one-third of the total number of Malaysian citizens.

Malay Mail has determined that this anonymous reader downloaded nearly 1GB of data from the server, but has not been able to verify its authenticity. The reader has now deleted his copy of the data, but it may have been disclosed to other media.

Rozario, who had contacted some of the data, said that although the number of affected people is less than expected, the type of data affected is more extensive.

Rozario said: “It’s quite easy to piece together who a child’s classmates are, and who the parents of the classmates are as well, creating a very rich data set of a child’s schooling friend and family.”

“The exploit was an SQL injection, which could be performed by a child. Just take a lesson and around five hours, and they can get all the database from the server,” he said.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Some third-party mail app allow employees to read user mails
  2. Microsoft workers uploaded sensitive login credentials to Microsoft’s own systems to GitHub
  3. Exposed security cameras in Israel and Palestine pose major risk
  4. AnyDesk Breach 2024: Dark Web Sale of 18,317 Credentials
  5. 10 Million Users Compromised in Z-Library Phishing Site Hack
Tags: 10 million Malaysian citizenship information

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.