LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › rac.gov.my Listed by babuk2 Ransomware Group

HIGH severityUnverified claimHow we verify

rac.gov.my Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 19, 2025
rac.gov.my Listed by babuk2 Ransomware Group

Reported March 19, 2025.

HIGH
Severity
March 19, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On March 19, 2025, the Malaysian government domain rac.gov.my appeared on a list published by the Babuk2 ransomware group, indicating that internal files had been exfiltrated. Individuals and organisations connected to rac.gov.my are advised to review their exposure and take appropriate security measures.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For people whose personal or professional details may sit inside Malaysian government systems, a ransomware listing is more than a technical notice. It raises the practical possibility that internal files containing names, contact details, identity numbers or case records could have left official control and may later appear for sale or misuse. Public information about this incident remains limited, yet the claim alone is enough to warrant attention from anyone who has dealt with the organisation.

On 19 March 2025 the ransomware group known as babuk2 listed rac.gov.my on its leak site, asserting that it had exfiltrated internal files during a ransomware attack. The number of people affected is unknown, and no further verified details have been released. What follows is a factual account of what is known, what remains unconfirmed, and what the claim means in everyday terms.

What happened

According to the publicly reported listing, babuk2 claimed responsibility for a ransomware attack against rac.gov.my and stated that internal files had been taken. The listing was recorded on 19 March 2025. No official confirmation of the intrusion, no statement of the precise date of the attack, no figure for the volume of data, and no description of the technical method used have been made public. The number of individuals whose information may be involved is listed as unknown. In short, the only concrete public element is the group’s claim that internal files were exfiltrated; everything else about timing, scale and method remains undisclosed.

Inside babuk2

Babuk2 is associated with the broader Babuk ransomware family, a set of operators that first gained attention in 2021 for double-extortion attacks. In the typical Babuk pattern, the group encrypts systems to disrupt operations and simultaneously steals data, then threatens to publish the material on a dedicated leak site if a ransom is not paid. Victims have historically included enterprises and public-sector bodies across several countries. The group’s listings are claims made by the operators themselves; they are not independent verification that every asserted file was in fact stolen or that every named organisation was successfully compromised. In the present case the listing of rac.gov.my should therefore be read as an unverified assertion by babuk2 rather than as confirmed fact.

About rac.gov.my

rac.gov.my is a Malaysian government domain, placing the organisation inside the country’s public-sector digital infrastructure. Government agencies of this type routinely manage citizen-facing services, administrative records, licensing or regulatory functions, and therefore hold collections of personal and operational data. A breach affecting such an entity is consequential because the information is often linked to real-world identities, official transactions and long-term government records. Even when the precise mandate of the agency is not restated in the breach report, the .gov.my designation alone signals that the data involved is likely to be more sensitive and more widely relied upon than ordinary commercial records.

What was likely exposed

The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No inventory of those files, no list of data fields, and no confirmation of whether personal identifiers, financial details or case documents were among them has been published. Organisations operating under Malaysian government domains typically maintain databases that can include names, national identity numbers, addresses, contact information, application histories and internal correspondence. Because the exact contents remain unconfirmed, it is not possible to state that any specific category of personal data was or was not taken. The claim is limited to the exfiltration of internal files; everything beyond that is presently unknown.

Why it matters

If the group’s claim is accurate, the practical risks for individuals include identity misuse, targeted phishing that references real government interactions, and the long-term circulation of personal details on criminal markets. For the organisation itself, the consequences can include operational disruption, loss of public trust, and the administrative burden of investigating and notifying affected parties. Even when the scale is unknown, the mere possibility that government-held records have left official custody creates lasting uncertainty for anyone who has submitted information to the agency. These are concrete, everyday harms rather than abstract technical issues.

Were you affected?

If you have ever submitted personal details, applications or correspondence to rac.gov.my, treat the listing as a prompt to review your own exposure. Monitor bank and credit accounts for unexpected activity, be alert to phishing messages that appear to come from Malaysian government sources, and consider placing fraud alerts with relevant credit bureaus where available. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Public detail on this particular incident remains limited, so independent verification of your own information is a practical first step while further official statements are awaited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyrac.gov.my security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See rac.gov.my’s full breach history →

More recent breaches

Mpaj.gov.my Listed by babuk2 Ransomware GroupMarch 21, 2025tecnologias.mspz2.gob.ec Listed by babuk2 Ransomware GroupApril 6, 2025turkish defense military Listed by babuk2 Ransomware GroupApril 4, 2025Bangladesh Armed Forces (BangLadesh Army) Listed by babuk2 Ransomware GroupApril 3, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the rac.gov.my Listed by babuk2 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by babuk2 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram