the sun malaysia ipaper logo 150x150
Monday, July 27, 2026
30.9 C
Kuala Lumpur
the sun malaysia ipaper logo 150x150

Social media fame is fuelling misuse of confidential customer records – Cyber expert

When employees become the biggest cybersecurity risk

PETALING JAYA: The alleged misuse of customer data in the telco leak highlights a growing cybersecurity risk, in which employees with legitimate system access may exploit confidential information for social media attention, a cybersecurity expert warned.

Universiti Malaysia Pahang Al-Sultan Abdullah Computer Network and Cyber Security Department head Dr Syifak Izhar Hisham said the rise of “clout culture” had led some individuals to prioritise online popularity over legal and ethical responsibilities, turning protected customer information into sensationalised content.

READ MORE: Khairul Aming data leak raises questions over companies’ ability to detect insider access

“Sometimes, the incidents happen because of the trend of clout culture. Influencers or social media users seek likes and followers by revealing information that attracts public attention.

“It becomes content over everything. They forget that disclosing this type of information can constitute a crime,“ she told theSun.

Syifak said the pattern observed in the Khairul Aming case appeared more consistent with an insider threat involving the misuse of authorised system access than a cyber attack by an external actor.

She added that the information disclosed was highly specific to a single individual, rather than a large collection of records typically targeted by cybercriminals for resale or broader exploitation.

The fact that the telco was able to identify the person involved also suggests that the activity came through a traceable internal account or system, she said.

“An outsider would normally target an entire database because a larger volume of information has greater value for sale.“

She also said organisations handling sensitive customer records should implement data masking to conceal confidential information from unauthorised personnel, ensuring details such as MyKad numbers were not displayed in plain text to employees who did not require full access.

Syifak said access to customer records should only be granted in response to legitimate customer requests, while role-based access controls should restrict sensitive information to a limited number of authorised personnel.

“If an employee could easily access and capture private MyKad information without adequate logging, role-based restrictions or data masking, it would indicate that the necessary safeguards were not properly in place.”

She added that to determine whether other customers had been affected, the telco should conduct a comprehensive audit trail of every search made using the employee’s user ID from the date access was first granted.

“This would show whose accounts were previously searched or viewed by the individual throughout the period of employment.“

She also said endpoint forensic examinations should also be carried out on the employee’s work computer or device to determine whether personal data had been stored locally, shared through messaging applications or transferred to external storage devices.

However, Syifak said the company’s liability would depend partly on whether adequate technical and administrative safeguards had been implemented and consistently enforced.

“If all the appropriate controls were in place and the incident still occurred, then it may ultimately involve an employee who was dishonest and failed to understand the duty of confidentiality.“

Syifak said Section 9 of the Personal Data Protection Act 2010 requires data controllers to implement sufficient technical and organisational measures to protect personal information from unauthorised access, disclosure and misuse.

STAY AHEAD OF THE CURVE

Join our community for instant updates and exclusive content.

Join Telegram Channel

Related


spot_img

Latest News

Most Viewed

spot_img
WC26

World Cup 2026

Updates, Fixtures, Results & Standings