Malaysia probes telecoms giant Maxis over Khairul Aming privacy leak

A social media post over an unpaid phone bill has triggered a data-protection investigation in Malaysia, after one of the country’s most recognisable influencers questioned how a stranger obtained details from his telecoms account. The episode involving Khairul Amin Kamarulzaman, better known as Khairul Aming, has raised uncomfortable questions for telcos about how tightly they manage customer account information and how quickly private details can be exposed when those controls fail. Khairul...

AI Privacy PanicAI Privacy Panic$AIPP
No data available
Trade

A social media post over an unpaid phone bill has triggered a data-protection investigation in Malaysia, after one of the country’s most recognisable influencers questioned how a stranger obtained details from his telecoms account. The episode involving Khairul Amin Kamarulzaman, better known as Khairul Aming, has raised uncomfortable questions for telcos about how tightly they manage customer account information and how quickly private details can be exposed when those controls fail. Khairul posted screenshots on social media on Monday showing another user claiming that the influencer had an overdue Maxis bill of 498 ringgit (US$122), that his line could soon be barred and that digital purchases had pushed up his charges despite an advance payment of 2,000 ringgit. The same account had allegedly revealed details linked to Khairul’s MySara government aid account before the post disappeared from social media. Maxis has not publicly identified the person or said whether the individual was an employee, contractor or another authorised user of its systems. “The amount is not the issue. That is my personal matter,” Khairul wrote in response. “What’s frightening is how you could know my phone bill details and then post them publicly.” Maxis said on Tuesday that all access to customer accounts was logged and monitored and that its investigation had found “an isolated incident involving an unauthorised action”, with no indication that other customers were affected. “We have identified the individual linked to this incident and are taking immediate action, including legal action,” the company said, apologising to Khairul and pledging to protect customer data. Communications Minister Fahmi Fadzil described the case as “quite worrying”, saying the complaint gave the impression that an individual had gained access to private information and a telco’s internal system. He met company representatives and ordered the Malaysian Communications and Multimedia Commission (MCMC) to obtain a full report. Malaysia’s Personal Data Protection Department has opened a separate investigation under the law’s data-protection principles and Section 130, which covers unlawful collection or disclosure of personal data. The department said enforcement action would follow if investigators established non-compliance. Khairul said on Wednesday that his lawyers had sent Maxis a letter of demand and lodged reports with the police, MCMC and the Personal Data Protection Commissioner. “Honestly, I feel sad and frightened that privacy can be lost so easily,” he said, adding that information covering his phone account, payment history, subscriptions and MySara access had been exposed. The episode quickly became a national talking point because Khairul is a popular social media celebrity in Malaysia. The former engineer has built a large following through his annual “30 Days, 30 Recipes” Ramadan series and used the exposure to expand into a food business selling products such as spicy sambal. In February, a 12-hour TikTok Shop broadcast featuring the 33-year-old generated 2.3 million ringgit in sales, then described as the highest one-day live stream total recorded on the platform in Malaysia. Behind the firewall The case has shifted scrutiny away from the familiar image of hackers forcing their way into corporate networks and towards the risks posed by people who have legitimate access to customer records. Samantha Khoo, a cyber and technology policy researcher at the Institute of Strategic and International Studies Malaysia, said telcos faced “concentration risks” because they held different categories of information which, when combined, revealed far more about a customer than any isolated data set. “As digital services become increasingly interconnected, companies are no longer protecting isolated data sets but an individual’s broader digital footprint,” she said. Such cases could damage confidence beyond a single company because customers had to trust the people authorised to handle their data, as well as the technology protecting it, Khoo added. Murugason R Thangaratnam, a cybersecurity practitioner, said insider misuse was difficult to detect because an individual might already possess valid credentials, understand internal procedures and operate in ways resembling routine customer-service work. An employee could open billing records without triggering defences designed to detect external attacks, he said, meaning telcos needed to scrutinise customer-service platforms, billing systems, contractors and outsourced call centres as closely as their core security operations. Access should be restricted according to an employee’s role and the purpose of a specific task, while higher-risk searches should require a recorded business justification or additional approval, Murugason said. Real-time systems could also flag searches involving prominent customers, repeated lookups of one account, access outside working hours, bulk exports or queries made without an active customer-support ticket, he added. In neighbouring Singapore, a worker at Singtel’s Malaysia call centre was jailed in 2020 for using legitimate system access to retrieve customer billing records without authorisation and sell the information to third parties. Malaysia’s Personal Data Protection Department says companies must take practical steps to prevent misuse and unauthorised access to customer data. Under guidelines introduced in 2025, notifiable breaches likely to cause significant harm generally must be reported to the commissioner within 72 hours, with affected people informed within seven days of that notification. Section 130 makes it an offence for a person to knowingly or recklessly collect or disclose personal data held by an organisation without consent, subject to limited exceptions. A conviction can carry a fine of up to 500,000 ringgit (US$122,000), jail of up to three years, or both. “The issue isn’t whether employees should have access,” Khoo said. “It is whether that access is governed appropriately through oversight, monitoring and accountability.”

Comments

Y
Loading...