LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Malaysian Nuclear Agency Listed by thegentlemen Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Malaysian Nuclear Agency Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 30, 2026
Malaysian Nuclear Agency Listed by thegentlemen Ransomware Group

Occurred July 2026 · publicly disclosed July 30, 2026.

HIGH
Severity
1
Data types exposed
July 30, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Malaysian Nuclear Agency was listed by thegentlemen ransomware group on 30 July 2026 after internal files were exfiltrated. Anyone who has interacted with the agency is urged to monitor accounts and change passwords as a precaution.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Malaysian Nuclear Agency Listed by thegentlemen Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

When a government research body that works with nuclear science appears on a ransomware group's listing, the immediate concern is practical rather than abstract: staff, partners, and anyone whose details sit in internal systems may face exposure of work-related or personal information. Public reporting so far does not say how many people are affected or exactly what records left the organisation's control, but the claim alone is enough to warrant careful attention from those connected to the agency.

On 30 July 2026, the Malaysian Nuclear Agency was reported as listed by the ransomware group known as thegentlemen. The group claims internal files were exfiltrated in a ransomware attack. Independent confirmation of the full scope remains limited, and the number of people affected is unknown. For ordinary individuals who have dealt with the agency, the useful response is to understand what is known, what is not, and what sensible steps follow.

Breaking down the breach

According to the available record, the Malaysian Nuclear Agency was listed by thegentlemen ransomware group on or around 30 July 2026. The reporting states that internal files were exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of affected individuals, or the precise date the intrusion began. The method of initial access, the duration of any dwell time inside networks, and whether systems were encrypted as well as copied are not detailed in the disclosed facts.

What is stated is the group's claim that internal files were taken. Listings on ransomware leak sites are assertions by the actors themselves; they are not the same as a confirmed forensic disclosure by the victim organisation. Until official statements or independent verification fill in the gaps, the scale and exact contents of any compromise remain unconfirmed beyond the description of internal files exfiltrated in a ransomware attack.

Inside thegentlemen

thegentlemen is known publicly as a ransomware operation that follows the now-common double-extortion model: actors seek to copy data before or alongside encryption, then pressure the victim by threatening to publish or sell the material if demands are not met. Groups of this type typically advertise victims on dedicated leak sites, post samples or file listings to demonstrate access, and set deadlines. Their tooling and affiliate structures evolve, but the core pattern—intrusion, data theft, encryption where possible, and public listing—has been documented across multiple campaigns.

Nothing in the provided facts attributes specific additional statements by thegentlemen about the Malaysian Nuclear Agency beyond the listing itself and the claim of internal-file exfiltration. Readers should treat the leak-site appearance as the group's claim rather than as independently verified detail about this incident. Prior activity by similar ransomware crews has involved a wide range of sectors, including government and research entities, precisely because those organisations hold operational and personal data that can increase leverage.

Who is Malaysian Nuclear Agency?

The Malaysian Nuclear Agency, also referred to as Nuklear Malaysia, is the country's leading government research and development organisation in nuclear science and technology. Its work centres on peaceful applications of nuclear innovation in support of national development. That includes areas such as medical radiopharmaceuticals, food security, and industrial safety, along with radiation safety, human-resource development, and the responsible management of radioactive waste.

Organisations of this kind routinely hold personnel records, research documentation, partner and contractor information, safety and regulatory correspondence, and technical material related to controlled or sensitive processes. A breach affecting such an agency is consequential not only because of ordinary personal data that may be present, but because of the trust placed in institutions that handle nuclear-related research and safety oversight. Even when the precise contents of a theft remain unconfirmed, the sector itself raises the stakes for confidentiality, operational continuity, and public confidence.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as employee databases, email archives, research datasets, financial records, or identity documents—is provided. The number of people affected is listed as unknown.

Government research bodies in the nuclear and radiological field typically maintain staff and contractor personal data, access and training records, project files, correspondence with other agencies and industry partners, and documentation tied to safety and waste management. It is reasonable to expect that some mixture of administrative and technical internal files could have been within reach of an intruder. It is not reasonable, on the current record, to assert that any specific category was confirmed stolen. Exact contents remain unconfirmed; only the broad description of internal files is stated.

The real-world impact

For individuals, the practical risks depend on what actually left the organisation. If personnel or contact data were included, possible outcomes include targeted phishing, social-engineering attempts that reference genuine workplace details, or longer-term misuse of identity information. If research or partner files were taken, third parties could face secondary exposure through shared projects or contracts. Because the headcount of affected people is unknown and the file inventory is not public, no one outside the investigation can yet map personal risk with precision.

For the agency, consequences can include operational disruption, the cost of incident response and system hardening, regulatory and oversight scrutiny, and damage to trust among staff, collaborators, and the public. Ransomware incidents also create pressure around whether to negotiate, how to communicate, and how to restore services without reintroducing the same weaknesses. None of these outcomes require assuming negligence; they are the ordinary aftermath when internal files are claimed to have been exfiltrated from a sensitive public-sector research environment.

What to do if you're exposed

If you work with, or have supplied personal information to, the Malaysian Nuclear Agency, treat the situation as a prompt for basic hygiene rather than panic. Watch for unexpected emails, calls, or messages that reference the agency or your role with unusual urgency or requests for credentials, payments, or further personal data. Prefer official channels when verifying any communication. Consider updating passwords on accounts that may have shared credentials or recovery details tied to work email, and enable multi-factor authentication where it is available. Monitor financial and identity alerts if you have reason to believe identity documents or banking-related data could have been involved—though that level of detail is not confirmed here.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets elsewhere. That check does not prove involvement in this specific incident, but it helps you see whether your address appears in previously compiled leak collections and whether further monitoring is warranted. Stay alert for official notices from the agency itself, which remain the authoritative source for confirmed scope and recommended next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMalaysian Nuclear Agency security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Malaysian Nuclear Agency’s full breach history →

More recent breaches

The Garfield County Sheriff Office Listed by thegentlemen Ransomware GroupJuly 30, 2026Angel Hotel Listed by thegentlemen Ransomware GroupJuly 30, 2026Delkart Industries Pvt Listed by thegentlemen Ransomware GroupJuly 30, 2026Indus Protech Solutions Listed by thegentlemen Ransomware GroupJuly 30, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Malaysian Nuclear Agency Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram