Cyber999 Advisories

9 September 2026     Report

Quarter 1 2026 Cyber Incident Summary Report


Quarter 1 2026 Cyber Incident Summary Report

Cyber999 Incident Response Centre of CyberSecurity Malaysia

TLP WHITE

1.0 Introduction
The Q1 2026 Cyber Incident Summary Report provides an overview of computer security incidents handled by the Cyber999 Incident Response Centre of CyberSecurity Malaysia during the quarter.

This report summarises incidents handled by the Cyber999 Incident Response Centre in Q1 2026 by category, along with security alerts and advisories issued during the quarter. The statistics reflect only incidents reported to and handled by Cyber999; they exclude financial losses, impact assessments, and post-incident consequences. The incidents involved IP addresses and domains in Malaysia.

CyberSecurity Malaysia collaborates with local and international ISPs, CERTs, Special Interest Groups (SIGs), and Law Enforcement Agencies (LEAs) to remediate and mitigate computer security incidents affecting Malaysian organisations and the public.

 
2.0 Trends Q1 2026
Malaysia had 34.9 million internet users at the start of 2025 and 25.1 million social media users in January 2025, representing 72.2 percent of the population [1]. Between January and May this year, a further 29,434 online fraud cases were reported with losses amounting to RM827.73 million [2]. Cyber999 receives incident reports from internet users, the public, home users, SMEs, industry, academia, and NGOs. The centre also gathers cyber threat intelligence through global partnerships to support mitigation efforts in Malaysia. Cyber999 received 2,188 incidents in Q1 2026, compared with 1,881 in Q4 2025, a 16 percent increase.

Tables 1 to 3 provide details of incidents reported in Q4 2025 and Q1 2026.
Table 1: Comparison of Incidents Reported in Q4 2025 and Q1 2026

Categories of Incidents

Quarters

Percentage (%)

Q4 2025

Q1 2026

Data Breach

171

124

     -27

Denial of Service

2

5

150

Fraud

1471

1829

24

Intrusion

101

64

-37

Intrusion Attempt

73

81

11

Malicious Codes

40

28

-30

Spam

13

31

138

Vulnerabilities Report

10

26

160

TOTAL

1881

2188

        16

 

Table 2: Breakdown of Incidents Based on Months in Q1 2026

Categories of Incidents

Jan

Feb

Mac

Data Breach

36

43

45

Denial of Service

2

1

2

Fraud

574

636

619

Intrusion

21

17

26

Intrusion Attempt

26

21

34

Malicious Codes

12

9

7

Spam

8

14

9

Vulnerabilities Report

8

6

12

TOTAL

687

747

754

 

Table 3: Breakdown of categories and sub-categories of incidents in Q1 2026

Categories and Sub-categories of Incidents

 Jan

Feb

Mac

Denial of Service

 

 

 

Denial of Service – DoS

2

1

2

Fraud

 

 

 

Fraud -- Bogus Email

10

9

15

Fraud – Business Email Compromise

4

5

0

Fraud – Fraud Site

2

5

25

Fraud – Impersonation & Spoofing

40

15

26

Fraud – Job Scam

3

3

1

Fraud – Love/Parcel Scam

2

3

4

Fraud -- Phishing

513

596

548

Vulnerabilities Report

 

 

 

Vulnerabilities Report – Misconfiguration Information Disclosure

3

1

6

Vulnerabilities Report -- System

1

2

1

Vulnerabilities Report -- Web

4

3

5

Intrusion

 

 

 

Intrusion – Account Compromise

17

17

25

Intrusion -- Defacement

4

0

1

Intrusion Attempt

 

 

 

Intrusion Attempt – Login Brute Force

9

10

5

Intrusion Attempt – Port Scanning

0

0

0

Intrusion Attempt – Vulnerability Probes

17

11

29

Malicious Codes

 

 

 

Malicious Codes – Botnet C&C

0

0

0

Malicious Codes – Malware

10

9

5

Malicious Codes – Malware Hosting

2

0

2

 

 

 

 

Content Related 

 

 

 

Content Related – Data Breach

36

43

45

Spam

8

14

9

TOTAL

687

747

754


Figure 1 provides a category breakdown of incidents reported in Q1 2026, while Figure 2 shows their percentage distribution.


Figure 1: Breakdown of incidents based on categories in Q1 2026

 

Figure 2: Percentage of incidents reported by categories in Q1 2026

Of the 2,188 incidents recorded in Q1 2026, fraud accounted for 1,829 cases, or about 84 percent of all reported activity. Data breaches were the second-highest category with 124 incidents, followed by intrusion attempts at 81 and intrusion at 64. Spam, malicious code, vulnerability reports, and denial-of-service incidents remained comparatively low. This concentration indicates that anti-fraud controls should remain a priority, while organisations must maintain broader defensive coverage for lower-volume but persistent threats.

Based on current trends, fraud incidents in Malaysia are expected to continue rising through 2026. Data breach reports also increased slightly this quarter, highlighting the need for organisations and individual users to strengthen security practices and take proactive preventive measures.

Fraud techniques beyond phishing URLs are also expected to become more sophisticated, with scammers combining social engineering and malicious code to conduct more convincing online scams in Malaysian cyberspace.

2.1 Top Fraud Incidents Reported in Q1 2026
Fraud remains prevalent, affecting citizens, end users, and organisations of all sizes. Criminals continue to exploit limited public awareness, making users easier targets. Cyber999 handled 1,829 fraud incidents in Q1 2026, a 24 percent increase from Q4 2025. Reports were received from both organisations and public users. The top fraud incidents reported to Cyber999 are listed below:

 Table 4: Top Fraud Incidents Reported in Q1 2026

Top Fraud incidents

Number of Incidents

Phishing

1657

Impersonation and Spoofing

81

Bogus Email

34

Fraudulent Website

32

Job Scam

7

Business Email compromised – BEC scam

9

Love and parcel scam

9

 
Cyber999 statistics show that phishing remained the dominant fraud type in Q1 2026, accounting for 1,657 cases, or 90.6 percent of reported fraud incidents. The following trends were observed in Malaysia based on reported incidents.

In Q1 2026, Cyber999 recorded 1,829 fraud incidents across seven categories. Phishing dominated with 1,657 cases (90.6 percent), confirming email-based deception as the main threat vector. Impersonation and spoofing followed with 81 incidents (4.4 percent), while bogus email and fraudulent website incidents accounted for 34 and 32 cases, respectively. Business email compromise and love-and-parcel scams recorded nine cases each, while job scams recorded seven. Together, phishing and impersonation represented nearly 95 percent of fraud activity during the quarter.

Phishing Trends Observed in Q1 2026

a.Contextualised and Localised Phishing Themes 

Government Aid Scams: Phishing emails or SMS impersonate legitimate government programs (e.g., bantuan/sumbangan kerajaan), offering financial aid but requiring victims to provide personal details or click malicious links.  

Fake Promotions and Discounts: Popular brands like Lazada, Shopee, or local retailers are spoofed, luring victims with fraudulent discounts or free vouchers. 

Traffic Summons Scams: Messages claim unpaid police summons, providing fake payment links to steal financial credentials. 

Subscription Services: Services like Netflix or Spotify are impersonated, tricking victims into renewing subscriptions or fixing payment issues on fake websites. 

b.Mobile-Focused Phishing (Smishing and App-Based) 
Smishing (SMS Phishing): Attackers send fraudulent SMS messages mimicking banks, e-wallets, or delivery services (e.g., J&T, Pos Malaysia) with malicious links. 

c.Phishing Calls (Vishing) 
Phone Scams: Attackers impersonate government agencies (e.g., police or LHDN, MCMC), banks, companies, or even CyberSecurity Malaysia, pressuring victims to disclose sensitive information. Common tactics include threats of legal action, account suspension, or overdue payments. 

Internet users and organisations should remain vigilant when conducting online and e-commerce transactions to avoid becoming victims of online fraud.

 

2.2 Top Malware Incidents Reported in Q1 2026
The top malware incidents in Q1 2026 involved malicious APKs, malware hosting, ransomware, backdoors, and trojans. Malicious APK incidents were most frequently reported by internet banking users and, in some cases, local financial institutions.

A malicious APK is an Android Package file designed to harm devices, steal data, or perform unauthorised actions. Attackers often disguise these files as legitimate apps, including social media, gaming, or utility applications, and distribute them through phishing emails, social media, fake websites, or third-party app stores.

Table 5: List of Malicious APKs from reported incident in Q1 2026

Malicious APK

Total

ChripChripBudgetyPackage.apk

1

RFO.apk

1

PDF Kad Digital Open Kad.pdf.apk

1

MisterCrabKK.apk

1

YES5G

1

 

 



Five unique malicious Android installers were reported in Q1 2026, each recorded once. These installers were typically sideloaded from outside official app stores and behaved as banking trojans designed to harvest login credentials and intercept one-time passwords.

        ChripChripBudgetyPackage.apk — Poses as a budgeting or bargain-shopping “package” app, luring victims with cheap-deal and parcel themes before stealing banking data.

        RFO.apk — An unbranded installer with a deliberately vague name, typically pushed as a form or “update,” concealing a credential-stealing trojan.

        PDF Kad Digital Open Kad.pdf.apk — Uses a deceptive double extension (.pdf.apk) to appear as a harmless digital-ID document, tricking users into opening an executable.

        MisterCrabKK.apk — Impersonates a food-ordering or restaurant brand, offering fake menus or vouchers to persuade diners to install the malware.

        YES5G — Spoofs a telco 5G brand, masquerading as a self-care or registration app to capture account logins and payment details.

 Malware hosting was the second most reported malware-related incident. These cases primarily involved vulnerable servers running outdated software or missing security patches. Reports were often received from foreign entities, including antivirus vendors and special interest groups, regarding Malaysian servers hosting malware. System administrators should keep systems patched and updated to reduce the risk of compromise.

Ransomware incidents increased from nine in Q4 2025 to 12 in Q1 2026, representing a 33 percent increase. Organisations should remain vigilant, as ransomware can restrict access to systems and data until a ransom is paid. These attacks are among the most costly and disruptive cyber incidents because recovery and remediation can require significant time and resources.

Our findings show that businesses remain the most affected by ransomware incidents in Malaysia, consistent with global trends. Active Directory (AD) servers have become primary targets because compromising them can expand the impact of an attack. Attackers may use tools such as PsExec, Group Policy Objects (GPOs), or Windows Management Instrumentation (WMI) to deploy ransomware across connected systems. Ryuk and Conti have been observed targeting AD servers for faster network-wide encryption. Attackers also exploit virtualisation platforms, including VMware ESXi, to gain control of multiple virtual machines. Ransomware operators commonly use phishing, brute force, or stolen credentials to access management consoles or servers. LockBit has also been observed deploying scripts against VMware environments, including actions to delete backups and snapshots.

Based on current trends, ransomware incidents are expected to remain a significant threat in Malaysia in 2026. Organisations and internet users should maintain strong preventive measures, including reliable backups, password security, timely patching, and cybersecurity awareness. Clear backup procedures, policies, and best practices are essential to reduce ransomware impact.

Table 6: Ransomware Variants Reported in Q1 2026

Ransomware Variant 

Number of Incidents

The DragonHorse

2

Qilin

1

Akira

1

Lynx Group

1

Black Shantrac

1

Thegentlement

1

CrySiS

1

NA (Not identified specific name of the ransomware)

4

 

 


 
Ransomware Variants Reported in Q1 2026
Twelve ransomware incidents were reported across eight variants. The DragonHorse was the most frequently reported variant with two cases, while four incidents could not be attributed to a known strain.

        The DragonHorse (2) — An emerging strain that encrypts files and demands cryptocurrency for a decryption key; the quarter’s most frequent variant.

        Qilin (1) — A Ransomware-as-a-Service operation using double extortion — stealing data before encrypting it, then threatening to leak it.

        Akira (1) — A fast-spreading strain that targets corporate networks and VPNs, combining file encryption with data-theft extortion.

        Lynx Group (1) — A Ransomware-as-a-Service group that hits small and mid-sized organisations with paired data theft and encryption.

        Black Shantrac (1) — A lesser-known variant that locks victim files and issues a ransom note demanding cryptocurrency payment.

        Thegentlement (1) — An emerging actor that encrypts systems and pressures victims with threats to publish stolen data.

        CrySiS (1) — A long-running family (also called Dharma) typically spread through exposed Remote Desktop connections.

        Not identified (4) — Four incidents where files were encrypted but no known strain signature or ransom branding could be confirmed.

In addition to ransomware and malware hosting, Cyber999 handled infostealer-related incidents in Q1 2026. Infostealers are malware designed to steal sensitive information, including login credentials, browser-saved passwords, credit card data, autofill records, FTP credentials, email data, instant messaging credentials, and VPN access details.

The following table lists infostealers associated with data breach incidents reported to Cyber999 in Q1 2026.

Table 8: Info stealers reported in Q1 2026

Types of Info Stealers

Number of Incidents

ULP Stealer

1

Unknown

1

VIDAR Stealer

15

 

Cyber999 recorded 17 infostealer incidents in Q1 2026. VIDAR Stealer dominated with 15 cases, or about 88 percent of the total, while ULP Stealer and one unidentified stealer accounted for one case each. Infostealers silently harvest saved passwords, browser cookies, and other sensitive data from infected devices.

        VIDAR Stealer (15) — A widely sold malware-as-a-service stealer that grabs browser credentials, cookies, and cryptocurrency wallets; the quarter’s dominant threat, often spread through cracked software and phishing.

        ULP Stealer (1) — Harvests credentials in URL-Login-Password format, producing ready-to-use login lists that attackers replay against online accounts.

        Unknown (1) — One incident where data theft was confirmed but the specific stealer family could not be identified.

 

2.3 Data Breach Incidents Growing in Malaysia
Data breach incidents decreased by 27 percent in Q1 2026; however, they remain a significant concern in Malaysia. High-profile breaches often involve large datasets containing personally identifiable information (PII), including identification numbers, addresses, and financial details. Strong security controls must be consistently implemented to protect personal data and maintain public trust.

Cyber999 also observed cases where perpetrators exfiltrated sensitive organisational data and used it for extortion, sometimes following ransomware attacks. Perpetrators may threaten to release or sell the data on the dark web unless a ransom is paid within a specified timeframe. Organisations facing extortion should refer the matter to law enforcement agencies, such as the police. Another observed trend was the resurfacing of previously breached data, where perpetrators claimed recent compromise even though analysis confirmed the data originated from older breaches.

Table 9: Data Breaches Reported in Q1 2026

Types of Data Breach

 

Description

Personal Identifier Information (PII)

Full name, identity card numbers, home address, age, handphone

number, date of birth, and salary.

 

Account Credential

Username and password of email accounts, username and password

of Internet banking accounts.

 

Appliances Credential

Admin panel access, Joomla, wordpress, ftp access, wp-admin access and etc.

 

 
3.0 Security Advisories and Alerts Released in Q1 2026
In Q1 2026, the Cyber999 Incident Response Centre issued 73 security advisories and one security alert. These included descriptions, mitigation steps, and recommendations for organisations and internet users. The advisories covered Mozilla, Microsoft, Apple, VMware, and other CVEs listed in Table 10. The security alert addressed rising online fraud and malware threats that could significantly affect citizens and organisations in Malaysia if not properly identified and mitigated.

Table 10: List of Significant CVEs in Q1 2026
The table below summarises the CVEs and their descriptions.

CVE ID

Description

CVE-2026-21509

 Microsoft Office Security Feature Bypass Vulnerability

 

4.0 Conclusion
Overall, Cyber999 recorded 2,188 computer security incidents in Q1 2026, representing a 16 percent increase from Q4 2025. No significant or severe incidents were observed during the quarter. However, organisations and individuals must remain vigilant and maintain readiness, prevention, and mitigation measures against evolving threats. Threat actors continue to adopt new and sophisticated tactics, techniques, and procedures to conduct cyberattacks.

Cyber999 strongly recommends that all internet users stay informed about current cybercrime trends and follow cyber hygiene best practices. This includes handling emails from unknown sources carefully, browsing safely, verifying online purchases, and using social media securely. Users should keep systems updated with the latest security patches to reduce the risk of compromise or malware infection. They should also verify the legitimacy of applications, portals, merchants, services, and products before conducting online transactions.

As cyber threats become more complex, organisations and individuals may become targets if they lack sufficient security awareness. Ongoing awareness campaigns for citizens and organisations remain essential to strengthening national cybersecurity and public trust.

Malaysian internet users and organisations may report cybersecurity incidents using the contact details below:

E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 08:30 -17:30 MYT
Web: https://www.cybersecurity.my


References:

[1] https://datareportal.com/reports/digital-2025-malaysia

[2] https://www.nst.com.my/news/nation/2026/07/1489207/rm38bil-wiped-out-online-scams-2025

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed