rac.gov.my Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On March 19, 2025, the Malaysian government domain rac.gov.my appeared on a list published by the Babuk2 ransomware group, indicating that internal files had been exfiltrated. Individuals and organisations connected to rac.gov.my are advised to review their exposure and take appropriate security measures.
For people whose personal or professional details may sit inside Malaysian government systems, a ransomware listing is more than a technical notice. It raises the practical possibility that internal files containing names, contact details, identity numbers or case records could have left official control and may later appear for sale or misuse. Public information about this incident remains limited, yet the claim alone is enough to warrant attention from anyone who has dealt with the organisation.
On 19 March 2025 the ransomware group known as babuk2 listed rac.gov.my on its leak site, asserting that it had exfiltrated internal files during a ransomware attack. The number of people affected is unknown, and no further verified details have been released. What follows is a factual account of what is known, what remains unconfirmed, and what the claim means in everyday terms.
What happened
According to the publicly reported listing, babuk2 claimed responsibility for a ransomware attack against rac.gov.my and stated that internal files had been taken. The listing was recorded on 19 March 2025. No official confirmation of the intrusion, no statement of the precise date of the attack, no figure for the volume of data, and no description of the technical method used have been made public. The number of individuals whose information may be involved is listed as unknown. In short, the only concrete public element is the group’s claim that internal files were exfiltrated; everything else about timing, scale and method remains undisclosed.
Inside babuk2
Babuk2 is associated with the broader Babuk ransomware family, a set of operators that first gained attention in 2021 for double-extortion attacks. In the typical Babuk pattern, the group encrypts systems to disrupt operations and simultaneously steals data, then threatens to publish the material on a dedicated leak site if a ransom is not paid. Victims have historically included enterprises and public-sector bodies across several countries. The group’s listings are claims made by the operators themselves; they are not independent verification that every asserted file was in fact stolen or that every named organisation was successfully compromised. In the present case the listing of rac.gov.my should therefore be read as an unverified assertion by babuk2 rather than as confirmed fact.
About rac.gov.my
rac.gov.my is a Malaysian government domain, placing the organisation inside the country’s public-sector digital infrastructure. Government agencies of this type routinely manage citizen-facing services, administrative records, licensing or regulatory functions, and therefore hold collections of personal and operational data. A breach affecting such an entity is consequential because the information is often linked to real-world identities, official transactions and long-term government records. Even when the precise mandate of the agency is not restated in the breach report, the .gov.my designation alone signals that the data involved is likely to be more sensitive and more widely relied upon than ordinary commercial records.
What was likely exposed
The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No inventory of those files, no list of data fields, and no confirmation of whether personal identifiers, financial details or case documents were among them has been published. Organisations operating under Malaysian government domains typically maintain databases that can include names, national identity numbers, addresses, contact information, application histories and internal correspondence. Because the exact contents remain unconfirmed, it is not possible to state that any specific category of personal data was or was not taken. The claim is limited to the exfiltration of internal files; everything beyond that is presently unknown.
Why it matters
If the group’s claim is accurate, the practical risks for individuals include identity misuse, targeted phishing that references real government interactions, and the long-term circulation of personal details on criminal markets. For the organisation itself, the consequences can include operational disruption, loss of public trust, and the administrative burden of investigating and notifying affected parties. Even when the scale is unknown, the mere possibility that government-held records have left official custody creates lasting uncertainty for anyone who has submitted information to the agency. These are concrete, everyday harms rather than abstract technical issues.
Were you affected?
If you have ever submitted personal details, applications or correspondence to rac.gov.my, treat the listing as a prompt to review your own exposure. Monitor bank and credit accounts for unexpected activity, be alert to phishing messages that appear to come from Malaysian government sources, and consider placing fraud alerts with relevant credit bureaus where available. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Public detail on this particular incident remains limited, so independent verification of your own information is a practical first step while further official statements are awaited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Mpaj.gov.my Listed by babuk2 Ransomware Grouptecnologias.mspz2.gob.ec Listed by babuk2 Ransomware Groupturkish defense military Listed by babuk2 Ransomware GroupBangladesh Armed Forces (BangLadesh Army) Listed by babuk2 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the rac.gov.my Listed by babuk2 Ransomware Group →
Publicly posted by babuk2 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.