🇲🇾 1.38 MILLION SENHENG CUSTOMER RECORDS ALLEGEDLY LEAKED
A threat actor is advertising a database allegedly associated with Senheng, a major Malaysian consumer electronics retailer.
According to the dark web listing:
* Approximately 1.38 million records
* Customer names
* Email addresses
* Customer/payment-related identifiers
* Shopping and customer-related information
* A sample of the alleged database has been published as evidence
⚠️ Analyst Note:
At 1.38 million records, this could represent a significant Malaysian consumer-data exposure if authentic. Customer identity and shopping-related information can be particularly useful for convincing order, payment, delivery and account-themed phishing campaigns.
The dataset's authenticity, freshness and connection to a new Senheng security incident have not been independently verified.
#DDW #DataBreach #Malaysia #ThreatIntelligence
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor.
The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication.
Revolut later concluded they were not authentic.
Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history.
The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators.
It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers.
ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
A bank froze @reubenyap's account for a full year. He was a lawyer for ten years and he pays his taxes. The money came from someone else's scam and the police cleared him. The Firo co-founder gave me his whole case for privacy at @CryptoCanal's #CommonS3nse.
Syarikat telekomunikasi (telco) perlu segera memberi penjelasan berhubung dakwaan terdapat sejumlah besar talian telefon didaftarkan yang dikhuatiri disalahgunakan bagi kegiatan penipuan dalam talian - Menteri Komunikasi Datuk Seri Fahmi Fadzil
https://t.co/5FlJuM2EAk
@NewsBFM Ehemm. PKN is still making passport books, IRIS Corp is still a big global player in border control projects esp biometric cards, ePassport, eVisa projects. Datasonic is not the sole solution provider with consumables. They were the last to join the herd. Smh
POLYMARKET’S LEGAL RESPONSE
I sued Polymarket after they changed the rules on the “MSTR sells Bitcoin” market, scamming me for $500K.
They just filed a 24 page motion in court, attempting to dismiss my case. THIS is how they treat their users. 🧵
RHB jadi bank pertama sediakan unified Payment Gateway kat Malaysia.
Bagi industri online payment di Malaysia, berita ni sebenarnya besar. Sebab bank dah mula provide servis begini. Bank lain confirm menyusul.
Maksudnya apa?
Bisnes anda boleh lantik 1 merchant bank je, pastu customer boleh ada pilihan bayaran guna kad kredit/debit, eWallet (TNG, ShopeePay, Grab), DuitNow (QR/Pay/GXBank/AEON/Boost), FPX (semua bank tradisional) dll kat website masing-masing.
Kat back-end, finance senang nak buat reconciliation, reporting dan settlement. Nak buat integration dan development pun mudah sebab deal dengan 1 pihak je.
Sebab sebelum ni, kalau nak ada banyak option payment gateway, kena guna 3rd party. Yang terkenal seperti Fiuu (Razor). Cuma rate mereka agak tinggi.
Nak dapat rate lagi rendah, kena engage sendiri dengan Paynet, bank A, bank B, Grab, Shopee, Billpliz, SenangPay dsb. Jadi nak buat settlement, reconcile, agreement leceh sebab ada banyak pihak nak berurusan dan maintain.
Bagi orang awam, takde nampak perubahan apa-apa. Tapi bagi bisnes SME, nak buat website yang ada payment gateway, ia sangat mudah nak offer multiple payment online sekarang.
Harap Jabatan kerajaan lain pun guna. Contoh nak bayar bil, saman, yuran sekolah, boleh guna debit card/scan QR DuitNow je. Takdelah paksa guna JomPay je.
Company kecil yang takde IT pun mampu offer pilihan bayaran online yang sebelum ni mustahil nak buat.
Begitulah.
I completely disagree with the govt’s MyDigital ID push to now cover wedding registrations and death certs. What use is our MyKad then? This also severely disadvantages senior citizens or those who don’t have smartphones.
Govt hasn’t proven the safety & security of MyDigital ID.
@acaiijawa@rz_wxyz Won't affect paynet, it's their payment rails lol. RHB just integrated a multiple APIs and offering it as a service. Let's see what's the pricing structure; if its the same as Fiuu etc, no difference lah
A 22-year-old student teacher in Illinois sent a private Snapchat message to her boyfriend and two roommates.
A student had walked up to her laptop and deleted her lesson plan mid-class. frustrated, she typed something like "should I shoot him" with a gun emoji. venting. four people. private group chat.
An hour later, police walked into her school and arrested her.
here's what happened in between.
Snapchat's AI scanned the private message. flagged it as a potential threat. automatically reported it to the FBI. the FBI forwarded it to local law enforcement. deputies arrived at the school within the hour.
she cooperated immediately. handed over her phone. when shown the message she said: "oh yes. okay. yeah. i'm realizing that was a bad joke. i did not mean it at all serious at all."
police determined she was not a threat. school officials determined she was not a threat. prosecutors reviewed and issued a disorderly conduct charge. she was released the next morning. she lost her student teaching placement.
This means:
Snapchat scans private messages.
Not just public posts or stories. private group chats between you and your closest contacts. automated AI. no human reviewed it first, got flagged and reported.
Snapchat AI → FBI → local police → school → arrest.
in under an hour.
Snapchat's privacy policy says it may share your information with law enforcement when it believes there is a risk of harm. the definition of "risk of harm" is determined by an algorithm.
you are not told when a message is flagged.
you are not told when a report is filed.
you find out when the police arrive.
the message was private.
it wasn't.
Dear COLDCARD attackers,
Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin.
Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder.
I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor.
Respectfully,
hodlers worldwide