• Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Security

MoH Insists MySejahtera Is Not Experiencing Any Data Leak

The unsolicited OTP SMS and spam e-mails were purely due to API manipulation, says the agency.

by Chief Chapree
October 20, 2021
MySejahtera app Ministry of Health MOH monkeypox COVID-19
Share on FacebookShare on Twitter

Following reports of unsolicited OTP SMS and spam e-mails that were triggered using MySejahtera’s backend system, the Ministry of Health (MoH) has issued a statement to address both issues. For starters, the agency denies that both incidents were caused by database leaks.

Instead, MoH insists that they were triggered through API manipulation. Specifically, the API is related to the MySejahtera Check-In feature that allows the public to generate MySejahtera’s QR code for them to display at their premises.

The web-based MySejahtera Check-In feature.

Random phone numbers and e-mail addresses were used as the target recipients for the unsolicited OTP SMS and e-mail. In addition to that, MoH noted that the unknown party has also taken advantage of the Need Help feature within MySejahtera’s website to send random spam e-mails.

The agency further added that the level of security for both MySejahtera’s app and website has since been increased. However, the media statement didn’t provide any details on what exactly that the MySejahtera team has done in order to accomplish that.

A sample of the spam e-mail, as shared by Phakorn Kiong in his Medium article.

While the statement did not make any direct reference to them, the API manipulation seemed to be related to the vulnerabilities that were discovered recently by full stack engineer Phakorn Kiong. Given what has transpired for the past few days, MoH and National Security Council may want to consider conducting a thorough audit on MySejahtera to ensure that the platform is secure and reliable enough to continue serving the Rakyat as the national COVID-19 app.

(Source: KKM / Twitter.)

Filed Under mysejahtera
Updated 10:05 am, Thu, 21 October 21
http://lowy.at/LrAYO
Share2Tweet1SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Mobile Phones

    Tecno Camon 50 Ultra Debuts At MWC 2026 With Dimensity 7400 Ultimate, 6,500mAh Battery

  2. 2
    Mobile Phones

    Infinix Note 60 Pro Now Official In Malaysia From RM1,199

  3. 3
    Apps

    MyJPJ’s MyDigital ID Implementation Postponed Yet Again; Now Set For 1 May 2026

  4. 4
    Banking

    Account Lockouts: Maybank Says Challenge Questions Triggered By Fraud Monitoring

  5. 5
    Hands On

    Huawei Mate 80 Pro Hands On: The Return Of the Mate Series

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Wanista
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.