Theedgemalaysia Bank Rakyat Fined RM1 Million for Cybersecurity Breaches
Article Content
- •Bank Rakyat fined RM1 million for cybersecurity breaches on January 20, 2026.
- •Inadequate cybersecurity controls allowed unauthorized access to Bank Rakyat's IT systems.
- •Remedial measures have been implemented to strengthen cybersecurity post-incident.
Bank Negara Malaysia (BNM) fined Bank Rakyat RM1 million on January 20, 2026, due to breaches in cybersecurity and customer data protection. The breaches were attributed to inadequate cybersecurity controls and incident response, which allowed an external threat actor unauthorized access to Bank Rakyat's IT infrastructure. The central bank stated that the severity of the breaches and the bank's lack of reasonable care in compliance were significant factors in determining the penalty. Bank Rakyat paid the fine on January 26, 2026, and has since implemented remedial measures to enhance its cybersecurity and governance arrangements. BNM emphasized its commitment to enforcing compliance among financial institutions to protect customer data. The incident highlights ongoing vulnerabilities within financial institutions in Malaysia.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Bank Kerjasama Rakyat Malaysia Bhd in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…