Monday, December 29, 2025
  • Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Security

MoH Insists MySejahtera Is Not Experiencing Any Data Leak

The unsolicited OTP SMS and spam e-mails were purely due to API manipulation, says the agency.

by Chief Chapree
October 20, 2021
MySejahtera app Ministry of Health MOH monkeypox COVID-19
Share on FacebookShare on Twitter

Following reports of unsolicited OTP SMS and spam e-mails that were triggered using MySejahtera’s backend system, the Ministry of Health (MoH) has issued a statement to address both issues. For starters, the agency denies that both incidents were caused by database leaks.

Instead, MoH insists that they were triggered through API manipulation. Specifically, the API is related to the MySejahtera Check-In feature that allows the public to generate MySejahtera’s QR code for them to display at their premises.

The web-based MySejahtera Check-In feature.

Random phone numbers and e-mail addresses were used as the target recipients for the unsolicited OTP SMS and e-mail. In addition to that, MoH noted that the unknown party has also taken advantage of the Need Help feature within MySejahtera’s website to send random spam e-mails.

The agency further added that the level of security for both MySejahtera’s app and website has since been increased. However, the media statement didn’t provide any details on what exactly that the MySejahtera team has done in order to accomplish that.

A sample of the spam e-mail, as shared by Phakorn Kiong in his Medium article.

While the statement did not make any direct reference to them, the API manipulation seemed to be related to the vulnerabilities that were discovered recently by full stack engineer Phakorn Kiong. Given what has transpired for the past few days, MoH and National Security Council may want to consider conducting a thorough audit on MySejahtera to ensure that the platform is secure and reliable enough to continue serving the Rakyat as the national COVID-19 app.

(Source: KKM / Twitter.)

Filed Under mysejahtera
Updated 10:05 am, Thu, 21 October 21
http://lowy.at/LrAYO
Share1Tweet1SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Banking

    Bank Negara Monitors Agrobank After Reported Loss Of Up To RM165.75 Million

  2. 2
    Automotive

    Perodua Rumoured Of Possible RM500 Million Acquisition Of TCMA Assembly Plant

  3. 3
    Banking

    Downtime, No Answers: The Chronic Silence Of Banks And Telcos In Malaysia

  4. 4
    Storage

    Redditor Orders Two Samsung 9100 Pro SSDs, Receives RM24,200 Worth Of SSDs Instead

  5. 5
    Smartwatches

    Xiaomi Watch 5 Officially Debuts In China With EMG Sensor

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.