Experts urge stronger safeguards after alleged Khairul Aming data exposure
PETALING JAYA: The alleged unauthorised disclosure of the personal account details belonging to social media influencer Khairul Amin Kamarulzaman (Khairul Aming) has raised fresh concerns over whether companies are equipped to detect and stop suspicious access to customer records before sensitive information is exposed to the public.
Universiti Malaya Centre of Research for Cybersecurity and Network professor Dr Ainuddin Wahid Abdul Wahab said organisations should not rely solely on audit trails that identify who accessed customer records after an incident but also have monitoring systems capable of detecting and responding to suspicious activity before confidential information is disclosed.
READ MORE: JPDP probes alleged Maxis customer data leak
READ MORE: Khairul Aming takes legal action after alleged personal data breach
He added that the issue was not simply whether someone possessed valid system credentials, but also whether there was a legitimate operational reason to access a customer’s records.
“It is like a bank employee who only needs to verify a customer’s name but is nevertheless given access to the person’s account balance and entire transaction history,” he told theSun.
“Automatic alerts should be triggered whenever certain accounts are accessed, especially those belonging to prominent individuals or celebrities.
“Regular audits should also be carried out to detect unusual access before it escalates into a public issue.”
He also said companies should adopt the principles of least privilege and segregation of duties, ensuring employees could only access information necessary to perform their roles, while automated alerts should flag access to sensitive or high-profile customer accounts for immediate review.
“Security teams should be able to verify immediately whether an account had been accessed for a genuine customer service matter or an authorised work assignment.
“This is particularly important for accounts belonging to VIPs or celebrities, while regular audits should be conducted to identify unusual access before it becomes a public issue.”
Meanwhile, Universiti Tun Hussein Onn Malaysia Centre for Cybersecurity and Data Intelligence senior researcher Assoc Prof Dr Zubaile Abdullah said it was still too early to conclude that all the information shared had originated directly from the telecommunications company’s systems.
He said investigators must establish the provenance, or original source, of each piece of data and determine whether it was obtained directly, supplied by someone with legitimate access or compiled from other exposed sources.
“A match with customer records alone does not prove the source of the entire dataset.“
Zubaile also cautioned against assuming that the individual who published the information was the one who originally obtained it.
“The exposure of a celebrity’s data should not be the reason we suddenly recognise the seriousness of the problem.
“If similar incidents have affected ordinary individuals, they deserve the same level of attention and protection.
“The real issue is not who the victim is, but whether personal data is being adequately protected.”
He added that the attention generated by Khairul’s case should not overshadow similar incidents involving ordinary customers. On July 20, a Threads user publicly shared information allegedly linked to Khairul’s Maxis account.
The influencer, known for his cooking content, has amassed a large following across Instagram, TikTok and other social media platforms.
The information shared allegedly included details of his outstanding telephone bill and other customer information.
The same user also published information relating to Khairul Aming’s MySara status, although it has yet to be established whether both sets of information originated from the same source.
Maxis later confirmed that an unauthorised action had taken place, saying the individual linked to the incident had been identified and describing it as an “isolated” case.
However, the company has not disclosed whether the individual was an employee, contractor, dealer, agent or affiliated with a third-party service provider.
Khairul subsequently announced on July 22 that his lawyers had issued a Letter of Demand to Maxis and that reports had been lodged with the police, the Malaysian Communications and Multimedia Commission and the Personal Data Protection Department.









