Quarter
1 2026 Cyber Incident Summary Report
Cyber999
Incident Response Centre of CyberSecurity Malaysia
TLP
WHITE
1.0
Introduction
The
Q1 2026 Cyber
Incident Summary Report provides an overview of computer security incidents
handled by the Cyber999 Incident Response Centre of CyberSecurity Malaysia during
the quarter.
This report summarises incidents handled by the
Cyber999 Incident Response Centre in Q1 2026 by category, along with security
alerts and advisories issued during the quarter. The statistics reflect only
incidents reported to and handled by Cyber999; they exclude financial losses,
impact assessments, and post-incident consequences. The incidents involved IP
addresses and domains in Malaysia.
CyberSecurity
Malaysia collaborates with local
and international ISPs,
CERTs, Special Interest Groups (SIGs), and Law Enforcement
Agencies (LEAs) to remediate and mitigate computer security incidents
affecting Malaysian organisations and the public.
2.0
Trends Q1 2026
Malaysia had 34.9
million internet users at the start of 2025 and
25.1 million social media users in January 2025, representing 72.2
percent of the population [1]. Between January and May this year, a further
29,434 online fraud cases were reported with losses amounting to RM827.73
million [2].
Cyber999 receives incident reports from internet users, the public, home
users, SMEs, industry, academia, and NGOs.
The centre also gathers cyber threat intelligence through global partnerships
to support mitigation efforts in Malaysia. Cyber999 received 2,188 incidents
in Q1 2026, compared with 1,881 in Q4 2025, a 16 percent increase.
Tables
1 to 3 provide details of incidents reported in Q4 2025 and Q1 2026.
Table
1: Comparison of Incidents Reported in Q4 2025 and Q1 2026
|
Categories of Incidents |
Quarters |
Percentage (%) |
|
|
Q4 2025 |
Q1 2026 |
||
|
171 |
124 |
-27 |
|
|
Denial
of Service |
2 |
5 |
150 |
|
Fraud |
1471 |
1829 |
24 |
|
Intrusion |
101 |
64 |
-37 |
|
Intrusion Attempt |
73 |
81 |
11 |
|
Malicious
Codes |
40 |
28 |
-30 |
|
Spam |
13 |
31 |
138 |
|
Vulnerabilities Report |
10 |
26 |
160 |
|
TOTAL |
1881 |
2188 |
16 |
Table
2: Breakdown of Incidents Based on Months in Q1 2026
|
Categories of Incidents |
Jan |
Feb |
Mac |
|
Data Breach |
36 |
43 |
45 |
|
Denial of Service |
2 |
1 |
2 |
|
Fraud |
574 |
636 |
619 |
|
Intrusion |
21 |
17 |
26 |
|
Intrusion Attempt |
26 |
21 |
34 |
|
Malicious Codes |
12 |
9 |
7 |
|
Spam |
8 |
14 |
9 |
|
Vulnerabilities Report |
8 |
6 |
12 |
|
687 |
747 |
754 |
Table
3: Breakdown of categories and sub-categories of incidents in Q1 2026
|
Categories and Sub-categories of Incidents |
Jan |
Feb |
Mac |
|
Denial of Service |
|
|
|
|
Denial of Service – DoS |
2 |
1 |
2 |
|
Fraud |
|
|
|
|
Fraud -- Bogus Email |
10 |
9 |
15 |
|
Fraud – Business Email Compromise |
4 |
5 |
0 |
|
Fraud – Fraud Site |
2 |
5 |
25 |
|
Fraud – Impersonation & Spoofing |
40 |
15 |
26 |
|
Fraud – Job Scam |
3 |
3 |
1 |
|
Fraud – Love/Parcel Scam |
2 |
3 |
4 |
|
Fraud -- Phishing |
513 |
596 |
548 |
|
Vulnerabilities Report |
|
|
|
|
Vulnerabilities Report – Misconfiguration
Information Disclosure |
3 |
1 |
6 |
|
Vulnerabilities Report -- System |
1 |
2 |
1 |
|
Vulnerabilities Report -- Web |
4 |
3 |
5 |
|
Intrusion |
|
|
|
|
Intrusion – Account Compromise |
17 |
17 |
25 |
|
Intrusion -- Defacement |
4 |
0 |
1 |
|
Intrusion Attempt |
|
|
|
|
Intrusion Attempt – Login Brute Force |
9 |
10 |
5 |
|
Intrusion Attempt – Port Scanning |
0 |
0 |
0 |
|
Intrusion Attempt – Vulnerability Probes |
17 |
11 |
29 |
|
Malicious Codes |
|
|
|
|
Malicious Codes – Botnet C&C |
0 |
0 |
0 |
|
Malicious Codes – Malware |
10 |
9 |
5 |
|
Malicious Codes – Malware Hosting |
2 |
0 |
2 |
|
|
|
|
|
|
Content Related |
|
|
|
|
Content Related – Data Breach |
36 |
43 |
45 |
|
Spam |
8 |
14 |
9 |
|
TOTAL |
687 |
747 |
754 |
Figure 1 provides a
category breakdown of incidents reported in Q1 2026, while Figure 2 shows their
percentage distribution.
Figure 1: Breakdown of incidents based on categories in Q1 2026
Figure
2: Percentage of incidents reported by categories in Q1 2026
Of the 2,188 incidents recorded in Q1 2026, fraud accounted for 1,829 cases, or about 84 percent of all reported activity. Data breaches were the second-highest category with 124 incidents, followed by intrusion attempts at 81 and intrusion at 64. Spam, malicious code, vulnerability reports, and denial-of-service incidents remained comparatively low. This concentration indicates that anti-fraud controls should remain a priority, while organisations must maintain broader defensive coverage for lower-volume but persistent threats.
Based on current trends,
fraud incidents in Malaysia are expected to continue rising through 2026. Data
breach reports also increased slightly this quarter, highlighting the need for
organisations and individual users to strengthen security practices and take
proactive preventive measures.
Fraud techniques beyond
phishing URLs are also expected to become more sophisticated, with scammers
combining social engineering and malicious code to conduct more convincing
online scams in Malaysian cyberspace.
2.1
Top Fraud Incidents Reported in Q1 2026
Fraud remains prevalent, affecting citizens,
end users, and organisations of all sizes. Criminals continue to exploit
limited public awareness, making users easier targets. Cyber999 handled 1,829 fraud incidents in
Q1 2026, a
24 percent
increase from Q4 2025. Reports were received from both
organisations
and public users. The top fraud incidents reported to Cyber999 are listed
below:
Table 4: Top Fraud Incidents Reported in Q1 2026
|
Top Fraud incidents |
Number of Incidents |
|
Phishing |
1657 |
|
Impersonation and
Spoofing |
81 |
|
Bogus Email |
34 |
|
Fraudulent Website |
32 |
|
Job Scam |
7 |
|
Business Email
compromised – BEC scam |
9 |
|
Love and parcel scam |
9 |
Cyber999 statistics show that phishing remained
the dominant fraud type in Q1 2026, accounting for 1,657 cases, or 90.6 percent
of reported fraud incidents. The following trends were
observed in
Malaysia based on reported incidents.
In Q1 2026, Cyber999
recorded 1,829 fraud incidents across
seven categories. Phishing dominated with 1,657 cases (90.6
percent), confirming email-based deception as the main
threat vector. Impersonation and spoofing followed with
81 incidents (4.4 percent), while
bogus email and fraudulent website incidents accounted for
34 and 32 cases, respectively. Business
email compromise and love-and-parcel scams recorded
nine cases each, while job scams recorded seven.
Together, phishing and impersonation represented
nearly 95 percent of fraud
activity during the quarter.
Phishing
Trends Observed in Q1 2026
a.Contextualised and Localised Phishing Themes
Government Aid Scams: Phishing emails or SMS
impersonate legitimate government programs (e.g., bantuan/sumbangan kerajaan),
offering financial aid but requiring victims to provide personal details or
click malicious links.
Fake Promotions and Discounts: Popular
brands like Lazada, Shopee, or local retailers are spoofed, luring victims with
fraudulent discounts or free vouchers.
Traffic Summons Scams: Messages
claim unpaid police summons, providing fake payment links to steal financial
credentials.
Subscription Services: Services
like Netflix or Spotify are impersonated, tricking victims into renewing
subscriptions or fixing payment issues on fake websites.
b.Mobile-Focused Phishing (Smishing and App-Based)
Smishing (SMS Phishing): Attackers send fraudulent SMS messages
mimicking banks, e-wallets, or delivery services (e.g., J&T, Pos Malaysia)
with malicious links.
c.Phishing Calls (Vishing)
Phone Scams: Attackers impersonate government agencies (e.g., police or
LHDN, MCMC), banks, companies, or even CyberSecurity Malaysia, pressuring
victims to disclose sensitive information. Common tactics include threats of
legal action, account suspension, or overdue payments.
Internet
users and organisations should remain vigilant when conducting online and e-commerce transactions
to avoid becoming victims of online fraud.
2.2
Top Malware Incidents Reported in Q1 2026
The
top malware incidents in Q1 2026 involved malicious APKs, malware hosting,
ransomware, backdoors, and trojans. Malicious APK incidents were
most frequently reported by internet banking users and, in
some cases,
local financial institutions.
A
malicious APK is an Android Package file designed to harm
devices, steal data, or perform unauthorised actions. Attackers
often disguise
these files as legitimate
apps, including social media, gaming,
or utility applications, and distribute them through phishing emails, social
media, fake websites, or third-party app stores.
Table
5: List of Malicious APKs from reported incident in Q1 2026
|
Malicious APK |
Total |
|
ChripChripBudgetyPackage.apk |
1 |
|
RFO.apk |
1 |
|
PDF Kad Digital Open Kad.pdf.apk |
1 |
|
MisterCrabKK.apk |
1 |
|
YES5G |
1 |
Five unique malicious Android
installers were reported in Q1 2026,
each recorded once. These installers were typically sideloaded
from outside official app stores and behaved
as banking trojans designed to harvest
login credentials and intercept one-time
passwords.
•
ChripChripBudgetyPackage.apk — Poses
as a budgeting or bargain-shopping “package” app, luring victims with
cheap-deal and parcel themes before stealing banking data.
•
RFO.apk — An
unbranded installer with a deliberately vague name, typically pushed as a form
or “update,” concealing a credential-stealing trojan.
•
PDF Kad Digital Open Kad.pdf.apk — Uses
a deceptive double extension (.pdf.apk) to appear as a harmless digital-ID
document, tricking users into opening an executable.
•
MisterCrabKK.apk — Impersonates
a food-ordering or restaurant brand, offering fake menus or vouchers to
persuade diners to install the malware.
•
YES5G — Spoofs a telco 5G brand,
masquerading as a self-care or registration app to capture account logins and
payment details.
Malware hosting was the second most reported malware-related incident. These cases primarily involved vulnerable servers running outdated software or missing security patches. Reports were often received from foreign entities, including antivirus vendors and special interest groups, regarding Malaysian servers hosting malware. System administrators should keep systems patched and updated to reduce the risk of compromise.
Ransomware
incidents increased from nine in Q4 2025 to 12 in Q1 2026, representing a 33
percent increase.
Organisations should remain vigilant, as
ransomware can
restrict
access to systems and data until a ransom is paid. These
attacks are among the most costly and disruptive cyber incidents because
recovery and remediation can require significant time and resources.
Our
findings show
that businesses remain the most affected by ransomware incidents
in Malaysia, consistent with global trends. Active
Directory (AD) servers have become primary targets because compromising them
can expand the impact of an attack. Attackers may use tools such as PsExec,
Group Policy Objects (GPOs), or Windows Management Instrumentation (WMI) to deploy
ransomware across connected systems. Ryuk and Conti have been observed targeting AD servers
for faster network-wide encryption. Attackers also exploit
virtualisation platforms, including VMware ESXi, to gain control of multiple virtual
machines.
Ransomware operators commonly use phishing, brute force, or
stolen credentials to access management consoles or servers. LockBit has also
been
observed deploying scripts against VMware environments, including actions
to delete
backups and snapshots.
Based on current trends, ransomware incidents
are expected to remain a significant threat in Malaysia in 2026. Organisations
and internet users should maintain strong preventive measures, including
reliable backups, password security, timely patching, and cybersecurity
awareness. Clear backup procedures, policies, and best practices are essential
to reduce ransomware impact.
Table 6: Ransomware Variants Reported in Q1 2026
|
Ransomware
Variant |
Number of Incidents |
|
The
DragonHorse |
2 |
|
Qilin |
1 |
|
Akira |
1 |
|
Lynx
Group |
1 |
|
Black
Shantrac |
1 |
|
Thegentlement |
1 |
|
CrySiS |
1 |
|
NA
(Not identified specific name of the ransomware) |
4 |
Ransomware Variants Reported in Q1 2026
Twelve ransomware incidents were reported across eight
variants. The DragonHorse was the most frequently
reported variant with two cases, while
four incidents could not be attributed
to a known strain.
•
The DragonHorse (2) — An emerging
strain that encrypts files and demands cryptocurrency for a decryption key; the
quarter’s most frequent variant.
•
Qilin (1) — A
Ransomware-as-a-Service operation using double extortion — stealing data before
encrypting it, then threatening to leak it.
•
Akira (1) — A
fast-spreading strain that targets corporate networks and VPNs, combining file
encryption with data-theft extortion.
•
Lynx Group (1) — A
Ransomware-as-a-Service group that hits small and mid-sized organisations with
paired data theft and encryption.
•
Black Shantrac (1) — A
lesser-known variant that locks victim files and issues a ransom note demanding
cryptocurrency payment.
•
Thegentlement (1) — An emerging
actor that encrypts systems and pressures victims with threats to publish
stolen data.
•
CrySiS (1) — A
long-running family (also called Dharma) typically spread through exposed
Remote Desktop connections.
•
Not identified (4) — Four
incidents where files were encrypted but no known strain signature or ransom
branding could be confirmed.
In addition to ransomware and malware hosting, Cyber999 handled infostealer-related incidents in Q1 2026. Infostealers are malware designed to steal sensitive information, including login credentials, browser-saved passwords, credit card data, autofill records, FTP credentials, email data, instant messaging credentials, and VPN access details.
The following table lists infostealers associated
with data breach incidents reported to Cyber999 in Q1 2026.
Table
8: Info stealers reported in Q1 2026
|
Types
of Info Stealers |
Number of Incidents |
|
ULP Stealer |
1 |
|
Unknown |
1 |
|
VIDAR Stealer |
15 |
Cyber999 recorded 17 infostealer
incidents in Q1 2026. VIDAR
Stealer dominated with 15 cases, or about 88
percent of the total, while ULP Stealer and one unidentified stealer
accounted for one case each. Infostealers
silently harvest saved passwords, browser cookies, and other sensitive data
from infected devices.
•
VIDAR Stealer (15) — A widely sold
malware-as-a-service stealer that grabs browser credentials, cookies, and
cryptocurrency wallets; the quarter’s dominant threat, often spread through
cracked software and phishing.
•
ULP Stealer (1) — Harvests credentials in
URL-Login-Password format, producing ready-to-use login lists that attackers
replay against online accounts.
•
Unknown (1) — One incident where data theft was
confirmed but the specific stealer family could not be identified.
2.3
Data Breach Incidents Growing in Malaysia
Data breach incidents decreased by 27 percent
in Q1 2026; however, they remain a significant concern in Malaysia.
High-profile breaches often involve large datasets containing personally
identifiable information (PII), including identification numbers, addresses,
and financial details. Strong security controls must be consistently
implemented to protect personal data and maintain public trust.
Cyber999 also observed cases where perpetrators
exfiltrated sensitive organisational data and used it for extortion, sometimes
following ransomware attacks. Perpetrators may threaten to release or sell the
data on the dark web unless a ransom is paid within a specified timeframe.
Organisations facing extortion should refer the matter to law enforcement
agencies, such as the police. Another observed trend was the resurfacing of
previously breached data, where perpetrators claimed recent compromise even though
analysis confirmed the data originated from older breaches.
Table
9: Data Breaches Reported in Q1 2026
|
Types of Data Breach
|
Description |
|
Personal Identifier
Information (PII) |
Full name, identity
card numbers, home address, age, handphone number, date of birth,
and salary.
|
|
Account Credential |
Username and password
of email accounts, username and password of Internet banking
accounts.
|
|
Appliances Credential |
Admin panel access,
Joomla, wordpress, ftp access, wp-admin access and etc.
|
3.0
Security Advisories and Alerts Released in Q1 2026
In
Q1 2026, the Cyber999 Incident Response Centre issued 73 security
advisories and
one security alert. These included descriptions,
mitigation steps, and recommendations for organisations and internet users. The advisories covered Mozilla, Microsoft,
Apple, VMware, and other CVEs listed in Table 10. The security alert
addressed rising
online fraud and malware threats that could significantly
affect
citizens and organisations in Malaysia if not properly identified and
mitigated.
Table
10: List of Significant CVEs in Q1 2026
The table below summarises the CVEs and their
descriptions.
|
CVE ID |
Description |
|
CVE-2026-21509 |
Microsoft Office Security Feature Bypass
Vulnerability |
4.0
Conclusion
Overall,
Cyber999 recorded 2,188 computer security incidents in Q1 2026, representing a
16 percent increase from Q4 2025. No significant or severe incidents were
observed during the quarter. However, organisations and individuals must remain
vigilant and maintain readiness, prevention, and mitigation measures against
evolving threats. Threat actors continue to adopt new and sophisticated
tactics, techniques, and procedures to conduct cyberattacks.
Cyber999
strongly recommends that all internet users stay informed about current
cybercrime trends and follow cyber hygiene best practices. This includes
handling emails from unknown sources carefully, browsing safely, verifying
online purchases, and using social media securely. Users should keep systems
updated with the latest security patches to reduce the risk of compromise or
malware infection. They should also verify the legitimacy of applications,
portals, merchants, services, and products before conducting online
transactions.
As
cyber threats become more complex, organisations and individuals may become
targets if they lack sufficient security awareness. Ongoing awareness campaigns
for citizens and organisations remain essential to strengthening national
cybersecurity and public trust.
Malaysian
internet
users and organisations may report cybersecurity incidents using the contact
details below:
E-mail:
cyber999[at]cybersecurity.my
Phone:
1-300-88-2999 (monitored during business hours)
Mobile:
+60 19 2665850 (24x7 call incident reporting)
Business
Hours: Mon - Fri 08:30 -17:30 MYT
Web:
https://www.cybersecurity.my
References:
[1]
https://datareportal.com/reports/digital-2025-malaysia
[2] https://www.nst.com.my/news/nation/2026/07/1489207/rm38bil-wiped-out-online-scams-2025