Malaysia

‘MoH-approved ‘Super Admin’ downloaded data of 3 mil MySejahtera users’

A single IP address also tried 1.12 mil times to break into database, reveals A-G report

Updated 1 year ago · Published on 16 Feb 2023 3:49PM

‘MoH-approved ‘Super Admin’ downloaded data of 3 mil MySejahtera users’
Concerns have previously been raised over the possibility of security and data breaches within MySejahtera after scores of users expressed alarm over receiving unsolicited emails and OTP messages from the app. – SADIQ ASYRAF/The Vibes file pic, February 16, 2023

by Qistina Nadia Dzulqarnain

KUALA LUMPUR – An account with full access to security settings and administrative features of the Covid-19 tracking app MySejahtera downloaded data on three million vaccine recipients over the span of three days. 

This was revealed in the Auditor-General’s Report 2021, which stated that the account, a “Super Admin” approved by the Health Ministry, began downloading the information on October 28, 2021 with the help of multiple internet protocol (IP) addresses. 

“Audits on the user data for administrative matters found that the Super Admin account has MySejahtera vaccine administrator access. 

“The vaccine admin allows (those with access) to upload or download vaccination appointments, exemptions, and records individually or in bulk from the MySejahtera database,” the report released today said.  

It added that it “cannot confirm” the exact data downloaded from MySejahtera by the account. 

Recommending that the data security management on the MySejahtera app be tightened to ensure the safety of vaccine recipient’s data, the report also said that the Health Ministry had cancelled the account on November 2 – two days after the final download. 

While a police report on the incident was lodged on November 5, other safety measures were put in place, including informing the National Cyber Security Agency to block any repeated requests from the same source. 

Citing a response from the ministry on September 9 and October 7 this year, the report said that the ministry is still attempting to determine the exact information acquired by the account.

“(During the first MySejahtera security meeting last year), the supplier stated that on October 28, 2021, a Super Admin account with registration approval from the Health Ministry was misused. 

“As soon as the matter was identified by the suppliers, the account was blocked immediately,” the response detailed. 

The ministry added that while the case is still being investigated by the Royal Malaysian Police, it will continue to work together with authorities to secure more information and identify the culprit behind the event.

Besides that, the report also highlighted that a single IP address had attempted 1.12 million times to break into the MySejahtera app database. 

The attempts had begun on 27 October, 2021 – the day before the Super Admin attack – following which MySejahtera developers Entomo Malaysia had taken down the IP address and installed a firewall on November 1. 

A note from the ministry included in the report stated that a separate police report on the matter was also lodged on November 5 while remedial measures were taken. 

Concerns had previously been raised over the possibility of security and data breaches within MySejahtera after scores of users expressed alarm over receiving unsolicited emails and OTP messages from the app. 

The Health Ministry had subsequently responded by saying that the false emails and text messages were the result of misuse of the MySejahtera app’s programming interface, and not due to a database leak. – The Vibes, February 16, 2023 

Related News

Malaysia / 1w

Address growing nurse vacancies at public hospitals, MCA veep tells MoH

Malaysia / 1mth

Unity Govt cowardly, irresponsible for snuffing out GEG, bowing to pressure: Khairy

Health / 2mth

As dengue cases surge, health authorities resort to technology to fight disease

Malaysia / 4mth

Health Ministry recommends 3rd Covid vaccine booster

Malaysia / 4mth

Govt should establish pandemic prevention guidelines for schools, says MCA

Malaysia / 4mth

MOH denies reports of full hospitals, rising virus death toll

Spotlight

Malaysia

Chow wants to meet Guan Eng over ‘missed investment’ remarks

By Ian McIntyre

Malaysia

How will Sarawak's 'region' status benefit the poor, asks activist

By Stephen Then

Malaysia

Dr Mahathir's sons say they are not subject of MACC probe

Malaysia

Despite hikes, Penang water tariffs 'among lowest in country’

By Ian McIntyre

Malaysia

4-way fight for Kuala Kubu Baharu

By Noel Achariam

Malaysia

BN chief Zahid hopeful MCA will help campaign for KKB

You may be interested

Malaysia

How will Sarawak's 'region' status benefit the poor, asks activist

By Stephen Then

Malaysia

Defence Ministry pushing for veteran registration so they can receive govt aid

By Stephen Then

Malaysia

KKB Raya open house isn’t campaigning, says Selangor MB

Malaysia

Be a smart consumer to beat inflation

Malaysia

Chow wants to meet Guan Eng over ‘missed investment’ remarks

By Ian McIntyre

Malaysia

Gerakan accepts PN decision not to field party’s candidate in Kuala Kubu Baharu

Malaysia

BN chief Zahid hopeful MCA will help campaign for KKB

Malaysia

Dr Mahathir's sons say they are not subject of MACC probe