Malaysia

What’s going on, MySejahtera?

Several users report a few disturbing problems such as prank emails

Updated 4 years ago · Published on 20 Oct 2021 11:50AM

What’s going on, MySejahtera?
A number of MySejahtera users have expressed concern that their profile on the application may have been compromised. – The Vibes file pic, October 20, 2021

by Amar Shah Mohsen

KUALA LUMPUR – Not for the first time, MySejahtera users are facing issues with the government-developed mobile app.

This time, scores of users are receiving unsolicited one-time password (OTP) messages for check-in QR registrations, raising security and data breach concerns within the app.

Some have also received prank emails claiming they have tested positive for Covid-19.

The issue surrounding the OTP messages supposedly first surfaced on Monday, after several users posted on social media about receiving the SMS at odd hours.

A user by the name of “Darkripper” also posted on a Lowyat.net forum highlighting how the OTP can be pushed by anyone to random phone numbers.

“You can instruct MySejahtera to spam OTP to others at will. Just run the following code at (the) terminal of choice and change (the) contact number,” the user wrote in his post with an accompanying code.

On Twitter, a number of users have expressed concern that their profile on the app may have been compromised.

“Hi @KhairyKJ @my_sejahtera, I received an OTP number for check-in registration at 3.52am whereas I did not request any action at that moment. I was sleeping. Can you help? I’m afraid someone will use my identity for their needs,” @nazirulatic posted.

Meanwhile, @chewmeiling said: “Hey, I got an OTP too at 2.11am this morning! I think maybe some people are trying to access others’ MySejahtera accounts.”

“Why did I get an OTP for MySejahtera at 12am? Is someone trying to steal my ID?” posted another user @pawtanbunn. A simple search on Twitter will find many more such cases.

In response to media enquiries, MySejahtera’s team said it has investigated the issue and found that the check-in feature meant for business premises has been misused by some malicious scripts to send the OTPs to random numbers.

“Since then, these application programming interface end points have been blocked and a fix to enhance security will be moved tonight.

“We want to reassure all our users that no user data was accessed by these scripts, but random phone numbers were spammed to verify their numbers. We apologise for this inconvenience,” it said.

Today, another issue surfaced with multiple users claiming to have received an email from MySejahtera, jokingly informing them that they are Covid-19-positive.

“You’ve tested positive for covid nahhh, joking. Plenty of exploits to show,” the email read.

The email was signed off by “CPRC MOH” (Crisis Preparedness and Response Centre, Health Ministry) and delivered from [email protected].

Twitter user @kavitamaheendra, who was among those to have received the unsolicited email, questioned if the app is truly safe and asked if this was a kind of joke.

The Health Ministry has yet to officially respond to this issue. – The Vibes, October 20, 2021

Related News

Malaysia / 2w

Covid-19 cases in Malaysia stable, no deaths recorded this year – MOH

Malaysia / 3mth

Bad move to channel EPF dividends into Account 3 for festive withdrawals, cautions economist

Opinion / 7mth

A tale of two administrations: How Warisan and GRS shaped Sabah’s future

Malaysia / 1y

MOH closely monitoring Covid-19 amid rising cases in neighbouring countries

Opinion / 1y

The Trump dilemma and reclaiming balance: The urgent need for fair global trade

Culture & Lifestyle / 1y

Renowned public health expert honoured at award ceremony in Penang

Spotlight

Malaysia

Anwar congratulates Modi on becoming India's longest-serving elected PM

Malaysia

Missing jewellery: Rosmah ordered to pay RM67.5 million

People

Malay kampongs in Bangkok: Echoes of southern heritage in Thailand’s capital

Opinion

Johor MB’s exclusionary rhetoric betrays the people, exposes UMNO’s political hypocrisy

Malaysia

Johor and NS polls first major test of post PAS-Bersatu political order

Malaysia

Claimed installation of 12th N. Sembilan ruler invalid - Pengelola Bijaya Diraja

Malaysia

4WD driver who drove backwards on highway nabbed, positive for drugs (video)

By Ian McIntyre

Malaysia

Seven in ten Malaysian workers earn RM5k or less - economist

You may be interested

Malaysia

Anwar warns global order lacks direction, calls for renewed international cooperation

Malaysia

Economic strains from West Asia crisis must not fracture national unity, warns Fadillah

Malaysia

Johor and NS polls first major test of post PAS-Bersatu political order

Malaysia

Retail prices of diesel, RON95 remain unchanged - at RM4.67, RM3.72 per litre

Malaysia

Court allows Daim's daughter to permanently keep passport

Malaysia

Authorities previously raided viral ‘illegal flat’ linked to Rohingya settlement claims

Malaysia

4WD driver who drove backwards on highway nabbed, positive for drugs (video)

By Ian McIntyre

Malaysia

Scam fight enters new phase as police back MyDigital ID to combat rising online fraud