Despite the police assurance that no data has been compromised in the attacks on government websites last night, a set of user data allegedly leaked from Sabah tourism official website has been published over the Internet.

A posting on a free, anonymous web hosting portal provides data on 392 user accounts. The details include user email, user name, first and last name, as well as their encrypted passwords.

NONE The portal claimed that more than 3,456 accounts were at risk, but had so far only released details of 392 users.

Server details, said to be from the one that hosts the Sabah tourism website, are also on the portal.

The portal carries the title #OpMalaysia Anonymous, which is the acronym for Operation Malaysia, the codename of the attack launched by the group of hackers calling themselves 'Anonymous'.

It also carries messages that read “PEACE NO HARM WAS DONE, To sabahtourism.com Please fix the exploit”.

Meanwhile, The Star/Asia News Network reported that the defaced site was spotted early yesterday by the chief executive of a company that organises security conferences.

"A portion of the website was deleted when I saw it," said Dhillon Andrew Kannabhiran, who heads Hack In The Box (M) Sdn Bhd.

hacked sabah tourism The Sabah Tourism website has since gone offline ( left ).

F-Secure Corporation (M) Sdn Bhd, a computer security software company, corroborated Dhillon's account.

Goh Su Gim, its security adviser for Asia, said the Sabah Tourism site had been compromised.

Threat of more exposures

"Worse still, the data from the 392 user accounts were stolen from the site and released to the public," he told The Star/ANN.

NONE According to the Malaysian Communications and Multimedia Commission (MCMC), 51 websites have been hit, with at least 41 disrupted, during the attacks which began shortly before midnight on Wednesday.

However, federal  police chief Ismail Omar was quoted by Reuters then as saying that no personal or financial data had so far been poached and that the authorities were trying to determine the extent of the attacks.

Another website that suffered the same fate was www.cidb.gov.my, which belongs to the Construction Industry Development Board (CIDB).

The original footer had been replaced with a statement protesting the earlier blockade of websites by the government.

“Greetings, Malaysia, We have seen the censorship taken by the Malaysian government, blocking sites like The Pirate Bay , and WikiLeaks . Malaysia is one of the world's strictest governments, even blocking out movies, and television shows.

“These acts of censorship are inexcusable. You are taking away a basic human right. The Internet is here for freedom, without fear of government interference. Do not think that no one else notices,” says the footer posted by Anonymous.

It also said that the attack is a “sign, a warning, and an opportunity to listen to ideas above your own” and the hackers “are obligated to act fast and have no mercy”.

However the CIDB website had recovered by 7am.

Last week, the Malaysian Communications and Multimedia Commission (MCMC) announced that 10 websites , including Pirate Bay and Megaupload had been blocked for infringing copyright laws.

Subsequently the hackers uploaded a short clip on video-sharing website YouTube , threatening retaliatory strikes on government websites from today for imposing the ban.

Gov't portals paralysed by Anonymous hackers group

At least 41 websites hacked, says MCMC

'No measure could have stopped skillful hackers'

DPM: Gov't takes serious view on hackers issue

M'sia upset with cyber-attacks, says minister

'Gov't had been warned to beef up online security'