ShellCodeX
Tools • Events • News • Insights
Victim Claim

mlit.com.my

stormous 🇲🇾 Malaysia Public Sector mlit.com.my
Claimed by stormous
Listed on leak site 12 Jun 2026
Reported attack date 12 Jun 2026
Group claims tracked 24
Unverified claim. This entry reproduces a listing published by the stormous group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that mlit.com.my suffered a breach, or what data was actually taken.

About the organisation

We have successfully breached the internal servers and network infrastructure of MLIT, gaining full unauthorized access to their active Microsoft Dynamics Management Reporter environment and local storage volumes.The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases.

What the listing means

mlit.com.my appeared on the stormous leak site on 12 June 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 7 claims in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing mlit.com.my as suspicious — leaked data gets weaponised for phishing within days.
  • If you hold an account on mlit.com.my, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Public Sector organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach — check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/bWxpdC5jb20ubXlAc3Rvcm1vdXM=