Skip to content

Malaysia's LHDN Tax Portal Data Offered for Sale, 10 Million Taxpayer Records Exposed

Breach Report Malaysia flagMalaysia Government / Tax Data for Sale

Malaysia's LHDN Tax Portal Data Offered for Sale, 10 Million Taxpayer Records Exposed

A threat actor using the alias dezetat is advertising a database from Malaysia's Inland Revenue Board (LHDN / IRBM), taken from the MyTax portal, for $20,000. The listing claims 10 million taxpayer records in JSON format, exfiltrated in June 2026. Per the post and schema, each record includes the taxpayer's NRIC national ID number, name, tax number (TIN), date of birth, marital status, full address, email, and phone, along with employer details and, for millions of records, bank account numbers and bank names. The seller states roughly 5.29 million records include a bank account number. The claim is unverified.

Data10M records
Price$20,000
CountryMalaysia flagMalaysia
Actordezetat

Post details

TargetInland Revenue Board (LHDN / IRBM), MyTax
CountryMalaysia flagMalaysia
SectorGovernment / Tax
Claim10M taxpayer records (JSON)
DataNRIC, TIN, bank accounts, addresses
Exfil dateJune 2026
Observed
Actordezetat

!Allegedly included

  • 10M taxpayer records
  • NRIC national ID numbers
  • Tax numbers (TIN)
  • Names & dates of birth
  • Full addresses
  • Email & phone numbers
  • Bank accounts (~5.29M) & names
  • Employer & company data

Screenshot(s)

Potential impact

If genuine, this pairs Malaysia's core national identifier (NRIC) with tax numbers, dates of birth, addresses, contact details, and, for millions of records, bank account numbers, which is the combination used for identity theft, financial fraud, and impersonation. NRIC numbers are permanent and cannot be reset, so exposure is lasting. The dataset also includes employer and company affiliations and tax filing details, adding to the fraud and phishing risk. No sample records, identifiers, or the seller's contact channel are reproduced here. The claim is unverified.

iStatus

Unverified

This is a sale listing; the seller offers more samples to serious buyers. No sample records, identifiers, or the Session contact channel are reproduced here. The claim is unverified and LHDN has not publicly addressed it.

Want the non-redacted screenshots? Paid subscribers get all of the claim details and unredacted screenshots. Check out the threat feed or ransomware feed (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest