Cyber Security News

INDOHAXSEC Hacker Group Allegedly Breaches Malaysia’s National Tuberculosis Registry

The Indonesian hacker group “INDOHAXSEC” has allegedly breached the National Tuberculosis Registry (NTBR) of Malaysia, managed by the Ministry of Health.

The group announced their claim via a post on a hacking forum, stirring fears over the safety of sensitive health data in the country.

The cyberattack came to light after INDOHAXSEC boasted about the breach on social media and hacking platforms.

The NTBR contains highly sensitive information, including personal health records of individuals diagnosed with tuberculosis, a disease still prevalent in Malaysia.

If the hacking group’s claims are verified, this breach could have significant repercussions for patient privacy, public health efforts, and national security.

The Alleged Breach

Reports indicate that INDOHAXSEC has provided no concrete proof of the extent of the breach, but the group claims to have accessed a significant amount of confidential data.

The hackers allege that the stolen information includes names, identification numbers, medical records, and treatment details of patients registered in the NTBR.

This incident, if confirmed, would represent a serious lapse in cybersecurity, raising questions about the vulnerability of Malaysia’s public databases.

Cyber experts have pointed out that national health registries are typically high-value targets for hackers due to the sensitivity of the data they store.

INDOHAXSEC, a relatively new but increasingly notorious hacking group in Southeast Asia, has a track record of targeting government systems and databases.

Their motivations, however, remain unclear, as they have yet to disclose whether the attack was politically or financially driven.

Malaysia’s Ministry of Health has not officially confirmed the breach. Authorities have stated that they are conducting an investigation into the matter and working with cybersecurity agencies to assess the situation.

An official spokesperson urged the public to remain calm while the claims are verified. Cybersecurity experts have warned that if the data is leaked or sold on the dark web, it could lead to identity theft, stigmatization of patients, and disruption of critical public health programs.

This alleged breach underscores the urgent need for stronger cybersecurity frameworks within government agencies.

With cyberattacks becoming increasingly sophisticated, robust safeguards, regular audits, and rapid response protocols are crucial to protect sensitive data.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN Sandox -> Start Now for Free.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

FortiOS & FortiProxy Vulnerability Allows Attackers Firewall Hijacks to Gain Super Admin Access

A critical vulnerability in Fortinet's FortiOS and FortiProxy products has been identified, enabling attackers to…

20 minutes ago

Fortinet’s FortiOS Vulnerabilities Allow Attackers Trigger RCE and Launch DoS Attack

Fortinet’s FortiOS, the operating system powering its VPN and firewall appliances, has been found vulnerable…

22 minutes ago

0-Day Vulnerability in Windows Storage Allow Hackers to Delete the Target Files Remotely

A newly discovered 0-day vulnerability in Windows Storage has sent shockwaves through the cybersecurity community.…

1 hour ago

Ratatouille Malware Bypass UAC Control & Exploits I2P Network to Launch Cyber Attacks

A newly discovered malware, dubbed "Ratatouille" (or I2PRAT), is raising alarms in the cybersecurity community…

2 hours ago

Sandworm APT Hackers Weaponize Microsoft KMS Activation Tools To Compromise Windows

In a sophisticated cyber-espionage operation, the Russian state-sponsored hacking group Sandworm (APT44), linked to the…

2 hours ago

Hackers Can Exploit “Wormable” Windows LDAP RCE Vulnerability for Remote Attacks

A critical new vulnerability in Microsoft’s Windows Lightweight Directory Access Protocol (LDAP), tagged as CVE-2025-21376,…

3 hours ago