LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Mpaj.gov.my Listed by babuk2 Ransomware Group

HIGH severityUnverified claimHow we verify

Mpaj.gov.my Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 21, 2025
Mpaj.gov.my Listed by babuk2 Ransomware Group

Reported March 21, 2025.

HIGH
Severity
March 21, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Mpaj.gov.my was listed by the babuk2 ransomware group on March 21, 2025, with internal files reported exfiltrated. Individuals who may have interacted with the site should review any notices from Mpaj.gov.my and monitor their accounts for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On March 21, 2025, the website Mpaj.gov.my was listed by the ransomware group known as babuk2. Public reporting indicates that internal files were exfiltrated during a ransomware attack, though the number of people affected remains unknown and further details about the incident have not been disclosed. The listing itself represents a claim by the group rather than independent confirmation of a successful compromise.

This matters because Mpaj.gov.my is a Malaysian local government site. Any exposure of internal files from such an organisation can affect residents, staff and the continuity of public services, even when the precise scale and contents stay unconfirmed.

Breaking down the breach

According to available public records, Mpaj.gov.my was listed by babuk2 on March 21, 2025. The only concrete detail provided is that internal files were allegedly exfiltrated in a ransomware attack. No information has been released about the exact date the intrusion began, how long the attackers may have had access, the volume of data taken, or the technical method used to gain entry. The number of individuals potentially affected is listed as unknown. Because the primary source of the report is the group’s own leak-site listing, the claim that a breach occurred and that files were stolen should be treated as unverified until corroborated by the organisation or independent investigators.

Ransomware incidents of this type typically involve both encryption of systems and the theft of data for leverage. In this case, only the exfiltration of internal files has been named; whether systems were also encrypted, whether a ransom demand was issued, or whether any data has been published remains undisclosed.

Who is babuk2?

Babuk2 is associated with the Babuk ransomware operation that first gained public attention around 2021. Groups operating under the Babuk name have historically used double-extortion tactics: they encrypt an organisation’s systems and simultaneously steal data, then threaten to publish the stolen material on a dedicated leak site if a ransom is not paid. They have targeted a range of sectors, including government and large enterprises, and have been known to post victim names and sample files to pressure payment. Public reporting has linked Babuk-related activity to various high-profile listings over the years, though the precise relationship between original Babuk operators and any later “babuk2” branding is not always clear.

In the present case, the group claims Mpaj.gov.my as a victim by listing it. No additional statements, sample files, or specific accusations about this organisation beyond the listing itself have been detailed in the available facts. As with other ransomware leak-site postings, the claim should be viewed as an assertion by the threat actor pending further verification.

About Mpaj.gov.my

Mpaj.gov.my is the online presence of a Malaysian municipal authority, specifically associated with local government administration in the Ampang Jaya area. Organisations of this type manage day-to-day civic services such as planning permissions, licensing, property rates, waste management, community facilities and resident records. They routinely hold personal information about local residents and businesses, internal administrative documents, correspondence, financial records and operational data needed to deliver public services.

A ransomware incident affecting a municipal council website is consequential because local government bodies sit at the intersection of public trust and sensitive personal data. Disruption can affect service delivery, while any leak of internal files raises privacy and security concerns for the people whose information the council holds.

What was likely exposed

The facts state only that internal files were exfiltrated in a ransomware attack. No specific categories of data—such as names, identification numbers, financial details, health records or employee information—have been named, and the volume of material taken is undisclosed. The exact contents therefore remain unconfirmed.

Organisations of this kind typically store a mixture of administrative documents, resident and business records, staff information, correspondence and operational files. In the absence of a detailed inventory or confirmation from the organisation, it is not possible to state what was actually taken. Readers should treat any assumption about particular data types as speculative until official clarification is provided.

Why it matters

For individuals whose information may have been held by the council, the primary risks include potential misuse of personal details if the files later appear online, increased phishing or social-engineering attempts that reference real local-government interactions, and longer-term identity or privacy concerns. Because the number of people affected is unknown and the precise data types are unconfirmed, the scale of individual impact cannot yet be measured.

For the organisation itself, a ransomware event can interrupt public services, create recovery costs, damage public confidence and trigger regulatory scrutiny under data-protection rules. Even when systems are restored, the mere claim of data theft can require notification efforts, forensic work and ongoing monitoring. The absence of Reported Details does not eliminate these practical consequences; it simply means the full picture is still incomplete.

What to do if you're exposed

If you have had dealings with Mpaj.gov.my or believe your details may be held by the council, treat the situation cautiously. Monitor official statements from the organisation for any confirmed notice of affected data. Watch for unexpected emails, calls or messages that reference local-government matters and verify them through known channels rather than links or contact details supplied in the message. Consider placing fraud alerts with relevant credit or identity services if you hold Malaysian financial accounts, and keep records of any suspicious activity.

As a practical first step, you can run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. This will not confirm involvement in this specific incident, but it can indicate whether your address has surfaced elsewhere and help you prioritise password changes and monitoring. Continue to rely on official updates rather than unverified claims circulating online.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMpaj.gov.my security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Mpaj.gov.my’s full breach history →

More recent breaches

rac.gov.my Listed by babuk2 Ransomware GroupMarch 19, 2025tecnologias.mspz2.gob.ec Listed by babuk2 Ransomware GroupApril 6, 2025turkish defense military Listed by babuk2 Ransomware GroupApril 4, 2025Bangladesh Armed Forces (BangLadesh Army) Listed by babuk2 Ransomware GroupApril 3, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Mpaj.gov.my Listed by babuk2 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by babuk2 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram