The government has found a lead into the alleged data theft of civil servant e-payslips and a statement will be made by the National Cyber Security Agency (Nacsa) soon.

Communications and Multimedia Minister Annuar Musa (above) said the government has held several meetings and discussions as it viewed the data leak and theft seriously.

“In the case of alleged data theft involving e-payslips and such, we have agreed that not many should issue statements, as we do not want to distract from the current investigations.

“We have agreed that whatever updates (on this issue) need to be issued, they must be from Nacsa and the Prime Minister’s Department.

“So, what I can inform is that we have certain leads and action is being followed up,” Annuar told reporters in Kota Bharu yesterday.

He said his ministry was developing a framework to improve or curb issues of data theft as this not only occurred in Malaysia but in all countries.

'Many misunderstand the issue'

“I want to state this because many misunderstand (this issue). If data theft involves personal data under the supervision of private companies, it is included under the Personal Data Protection Act and managed by the Data Protection Department under the Communications and Multimedia Ministry.

“Data from ministerial departments and institutions are not under the Data Protection Department, but under Nacsa and the Prime Minister’s Department.

“The alleged e-payslip breach is under Nacsa, but CyberSecurity Malaysia under the ministry will provide assistance in terms of forensics investigation,” Annuar added.

Media outlets had reported earlier about an alleged data theft incident where hackers, claiming to be from a “grey hat” cyber security organisation, said that they had breached the civil servant e-payslip system to expose its weakness.

The group claimed that it could access over a million rows of identities via the database, which is in the format of JavaScript Object Notation and comma-separated values.

- Bernama