CTOS Digital detects unauthorised access, says limited consumer data was affected
CTOS Digital Bhd has detected unauthorised access to a specific environment supporting its consumer business, with the company confirming that a limited subset of consumer information was accessed during the cybersecurity incident.
The credit reporting agency disclosed the incident in a filing with Bursa Malaysia, saying its cybersecurity monitoring systems detected the unauthorised access. Once the activity was identified, the company activated its established response protocols and moved quickly to contain the affected environment.
CTOS Digital said the affected environment has since been contained. The company has also appointed an independent incident response team to carry out a comprehensive forensic investigation to determine the circumstances surrounding the incident and assess its impact.
Based on the investigation findings received so far, CTOS Digital said the incident remained confined to the identified environment. The company added that its other systems and environments were not affected and continue to remain secure and operational.
The incident nevertheless highlights how quickly cybersecurity threats can become a serious concern for businesses that handle sensitive consumer and financial information. For customers, the immediate question is often not simply whether an incident occurred, but what information may have been exposed and what steps are being taken to protect them.
CTOS Digital said it is continuing to review its cybersecurity protocols and strengthen its overall security measures in line with the findings and recommendations of the independent forensic investigation.
As part of the remediation process, a subset of the company’s credit reporting services has been temporarily made unavailable. CTOS Digital said the temporary disruption is necessary while it completes the required remediation measures.
The company stressed that its other business operations and services continue to operate normally. It also said the cybersecurity incident is not expected to have a material financial impact on the company.
Relevant authorities have been notified, according to CTOS Digital, and the company said it will continue monitoring the situation closely. Any material developments will be announced as appropriate.
For customers, business partners and other stakeholders, the incident serves as a reminder of the importance of strong cybersecurity practices and timely incident response, particularly for organisations handling personal and credit-related information.
CTOS Digital said its board remains committed to conducting the company’s business responsibly, transparently and in compliance with applicable requirements. The company will continue its investigation and remediation efforts as it works to strengthen its cybersecurity posture.
The incident was reported by Bernama.


