Malaysia

What’s going on, MySejahtera?

Several users report a few disturbing problems such as prank emails

Updated 4 years ago · Published on 20 Oct 2021 11:50AM

What’s going on, MySejahtera?
A number of MySejahtera users have expressed concern that their profile on the application may have been compromised. – The Vibes file pic, October 20, 2021

by Amar Shah Mohsen

KUALA LUMPUR – Not for the first time, MySejahtera users are facing issues with the government-developed mobile app.

This time, scores of users are receiving unsolicited one-time password (OTP) messages for check-in QR registrations, raising security and data breach concerns within the app.

Some have also received prank emails claiming they have tested positive for Covid-19.

The issue surrounding the OTP messages supposedly first surfaced on Monday, after several users posted on social media about receiving the SMS at odd hours.

A user by the name of “Darkripper” also posted on a Lowyat.net forum highlighting how the OTP can be pushed by anyone to random phone numbers.

“You can instruct MySejahtera to spam OTP to others at will. Just run the following code at (the) terminal of choice and change (the) contact number,” the user wrote in his post with an accompanying code.

On Twitter, a number of users have expressed concern that their profile on the app may have been compromised.

“Hi @KhairyKJ @my_sejahtera, I received an OTP number for check-in registration at 3.52am whereas I did not request any action at that moment. I was sleeping. Can you help? I’m afraid someone will use my identity for their needs,” @nazirulatic posted.

Meanwhile, @chewmeiling said: “Hey, I got an OTP too at 2.11am this morning! I think maybe some people are trying to access others’ MySejahtera accounts.”

“Why did I get an OTP for MySejahtera at 12am? Is someone trying to steal my ID?” posted another user @pawtanbunn. A simple search on Twitter will find many more such cases.

In response to media enquiries, MySejahtera’s team said it has investigated the issue and found that the check-in feature meant for business premises has been misused by some malicious scripts to send the OTPs to random numbers.

“Since then, these application programming interface end points have been blocked and a fix to enhance security will be moved tonight.

“We want to reassure all our users that no user data was accessed by these scripts, but random phone numbers were spammed to verify their numbers. We apologise for this inconvenience,” it said.

Today, another issue surfaced with multiple users claiming to have received an email from MySejahtera, jokingly informing them that they are Covid-19-positive.

“You’ve tested positive for covid nahhh, joking. Plenty of exploits to show,” the email read.

The email was signed off by “CPRC MOH” (Crisis Preparedness and Response Centre, Health Ministry) and delivered from [email protected].

Twitter user @kavitamaheendra, who was among those to have received the unsolicited email, questioned if the app is truly safe and asked if this was a kind of joke.

The Health Ministry has yet to officially respond to this issue. – The Vibes, October 20, 2021

Related News

Malaysia / 1w

Covid-19 cases in Malaysia stable, no deaths recorded this year – MOH

Malaysia / 3mth

Bad move to channel EPF dividends into Account 3 for festive withdrawals, cautions economist

Opinion / 7mth

A tale of two administrations: How Warisan and GRS shaped Sabah’s future

Malaysia / 1y

MOH closely monitoring Covid-19 amid rising cases in neighbouring countries

Opinion / 1y

The Trump dilemma and reclaiming balance: The urgent need for fair global trade

Culture & Lifestyle / 1y

Renowned public health expert honoured at award ceremony in Penang

Spotlight

Business

Tycoon Vincent Tan trims BCorp stake further in RM115m share sale

Malaysia

UMNO’s solo gamble in Johor: A show of strength or risky miscalculation?

By The Vibes Says

Malaysia

Nik Aziz’s grandson allegedly slapped by senator: Father ready to take case to court

Malaysia

Lorry driver jailed a day, fined for making obscene gestures, dangerous driving (video)

Malaysia

PKR leader defends MyKhas access suspension for PJ, Subang MPs, cites ‘political choices’

Opinion

Social media set to dominate Johor polls as election kingmaker

Malaysia

Man charged in Butterworth parang attack case that left victim fearing permanent disability

Malaysia

Teen mothers must return to school, says Fadhlina as education remains priority

Malaysia

Penang water tariffs to increase from July 1 after year-long deferment

You may be interested

Malaysia

'I was once spat on by a pakcik' — Marina denies fear of contesting Malay-majority seats

Malaysia

Pahang police logistics chief killed in motorcycle crash on Genting road

Malaysia

PKR leader defends MyKhas access suspension for PJ, Subang MPs, cites ‘political choices’

Malaysia

Jewellery shop among six premises destroyed in fire (video)

Malaysia

Woman jailed over abduction, extortion and forced nudity case as three admit guilt

Malaysia

JPJ probes couple ‘manja’ incident in car, summons to be issued (video)

Malaysia

Johor State Election: BN to launch machinery this Sunday

Malaysia

Teenager who drove recklessly, causing death remanded for further investigation