protect 360
- PROTECT 360
- User Guide
- IDENTIFY THEFT CHECKER <check for free>
- CYBER SECURITY CONCERN WEBSITE LIST
- CYBER SECURITY
- ELITE+




A TOTAL INTERNET SECURITY SOLUTION


360 SAFE
360 SAFE offers comprehensive network protection for computers, smartphones, and tablets running Windows, Mac OS, Android or iOS
FEATURES:
• Anti Virus • Banking Protection • Browsing Protection
• Parental Control • Ransomeware Protecion • Gaming Mode




360 VPN
360 VPN Protect your privacy and minimize your digital footprint with encrypted browsing
FEATURES:
• Privacy Protection • WiFi Protection • Trusted WiFi networks
• Tracking Protecion • Protection Statistics • Malware Protection
360 IDP
360 IDP helps to prevent identity theft at the same time find out instantly and get help if a hacker has stolen information from online service
FEATURES:
• Password Manager • Auto-Fill Credentials
• Online Identity Monitoring • Breach Alert




BENEFITS
Get complete security, privacy, identity protection, and parental control- all in one apps


PROTECT 360 PACKAGE COMPARISON




PRIVACY POLICY >
For support, account deletion requests or any other questions related to mobile applications developed by Courts (Malaysia) Sdn Bhd for Protect 360 can be sent to cservice@courts.com.my or contact us at 03-3000 8998
AIG Insurance is a member of PIDM. The benefit(s) payable under eligible certificate/policy/product is(are) protected by PIDM up to limits. Please refer to PIDM’s TIPS Brochure or contact AIG Malaysia Insurance Berhad or PIDM (visit www.pidm.gov.my).
Cyber Security Concern Website List
Cybersecurity Malaysia: “Curb hacking by only using secured Wi-Fi connection”


ONLINE consumers who use e-wallets and other e-payment methods have been strongly advised not to conduct any transactions over a public Wi-Fi connection.
According to CyberSecurity Malaysia cryptography development head Hazlin Abdul Rani, threats and attacks from hackers could immediately happen through an unsecured public Wi-Fi where personal data, and possibly all account information and login credentials, could be accessed during the transaction process.
She also advised users to be cautious about the possibility of attackers impersonating the valid public Wi-Fi network.
“For example, if you are at an airport, the name of the Wi-Fi is ‘Airport ABC’, but the attacker creates a Wi-Fi with the name ‘Airport ABC1’, or even changes the capital or small alphabet letters of the Wi-Fi to make you believe that you are using a valid or legit Wi-Fi. This confusion can also lead users to fall into their trap,” she was reported as saying by Bernama
For more information, visit www.courts.com.my/public-wifi
SafetyDetectives: POS software provider StoreHub leaks 1 mil customers’ data


CYBERSECURITY expert SafetyDetectives has claimed that its team has discovered a major data leak affecting Malaysia-based point of sale (POS) software system provider StoreHub which is mostly used in restaurants and retail stores.
The exposed data was stored on a StoreHub’s Elasticsearch server that was left open without any password-protection or encryption, according to SafetyDetectives which reputed itself to be a publishing group of cybersecurity experts, privacy researchers and technical product reviewers located all over the world.
“The unprotected server potentially compromised the information of thousands of restaurants and retail stores, along with their staff and roughly (that of) 1 million customers,” it said in a report to FocusM.
According to SafetyDetectives, its cybersecurity team discovered that Storehub had misconfigured one of its Elasticsearch server, causing it to leak over 1.7 billion records and over 1 terabyte of data.
This exposed almost one million customers in Malaysia and potentially across Southeast Asian countries.
For more information, visit www.courts.com.my/software-provider
Malaysia records RM560m loss in cyber crime last year


MALAYSIA recorded over 20,000 cyber crime cases last year with losses amounting to RM560 million, said deputy secretary-general (Security) of the Home Ministry, Datuk Abdul Halim Abdul Rahman.
He said the cases recorded included cyber bullying, falsification, hacking, phishing and e-mail scams which were increasing each year.
“For the record, about 13,000 cyber crime cases with RM539 million in losses were recorded in 2019,” added Abdul Halim who did not give the figures for 2020.
“By 2025, the digital economy is expected to contribute about 22.6 per cent to the country’s Gross Domestic Product (GDP).
“Therefore, in Malaysia’s effort to develop itself into a nation that is driven by digital economy, we need to identify the threats with the potential to affect the key targets and the economic sector in general.”
He said this when officiating at the National-Level Key Targets Seminar 2022, representing Home Minister, Datuk Seri Hamzah Zainuddin.
Key targets refer to the applications with the vital output or services that if destroyed or are in disrepair, could cause great losses to the country’s economy and defence, and also affect its image and government’s functions.
For more information, visit www.courts.com.my/cyber-crime
PM lodges report over hacked Telegram, Signal accounts”


KUALA LUMPUR: Prime Minister Datuk Seri Ismail Sabri Yaakob has lodged a report with the Malaysian Communications and Multimedia Commission (MCMC) and the Royal Malaysia Police (PDRM) on his personal Telegram and Signal accounts being hacked by irresponsible parties.
The Prime Minister's Office (PMO) , in a statement on Tuesday (Aug 9), stated that it believed the accounts were used for fraudulent criminal activities and advised those who received messages from the accounts concerned to ignore them and report to the authorities.
For more information, visit www.courts.com.my/pm-hack
Kiplepay informs customers of potential risks by third-party provider
• Informed customers of risks through a thrid-party gateway provider
• Heightened security toprevent any suspicious transaction activities


E-wallet service provider Kiplepay Sdn Bhd, a wholly-owned subsidiary of Green Packet Bhd, has informed its Kiple Visa prepaid card users via email of a risk through a recent third-party payment gateway provider data breach on Aug 15.
In a statement, the firm said the customer communication was released following Bank Negara Malaysia’s (BNM) notification to the company, which highlighted the recent potential third-party data breach incident.
It said it has also requested that the company notify affected cardholders of additional protective measures that are being taken to protect them against risks of fraudulent or unauthorised transactions that may arise from this incident.
Kiplepay said the data breach highlighted was a cybersecurity incident which has occurred to a third-party which may affect Kiplepay users who performed transactions using the third-party payment gateway system.
For more information, visit www.courts.com.my/ewallet-breach
Annuar: Ministry to take immediate action over iPay88 issue
KOTA BARU: The Communications and Multimedia Ministry will take immediate action regarding the data breach incident that hit online payment service provider, iPay88 (M) Sdn Bhd, says Tan Sri Annuar Musa.
“The case is still being investigated further by iPay88’s vendor, SISA from Singapore, who identified the threat Cobalt Strike being used.
For more information, visit www.courts.com.my/payment-provider
Two years on, Apple iOS VPNs still leak IP addresses
Privacy, it's a useful marketing term. *Offer does not apply in China
Apple has left a VPN bypass vulnerability in iOS unfixed for at least two years, leaving identifying IP traffic data exposed, and there's no sign of a fix.
Back in early 2020, secure mail provider ProtonVPN reported a flaw in Apple’s iOS version 13.3.1 that prevented VPNs from encrypting all traffic. The issue was that the operating system failed to close existing connections.
This could potentially allow an attacker to identify a VPN user's source IP address. For those actually relying on hiding that data to avoid attention from a repressive regime or someone seeking private information, this is not a trivial concern.
For more information, visit www.courts.com.my/apple-ios-vpn-leakMonths after 'hacking' incident, MCMC is back on Twitter


PETALING JAYA: The Malaysian Communications and Multimedia Commission (MCMC) is back on Twitter under a new handle – @MCMC_RASMI – six months after it claimed its original account was hacked.
MCMC sent out its first tweet using the new account, which now has over 300 followers, on July 5.
In January, MCMC announced that it had to temporarily suspend its previous account, @SKMM_MCMC, after it was allegedly hacked. The account had over 70,000 followers.
The last tweet from the account before it was deactivated was a statement saying that MCMC will monitor social media for misinformation in regards to the 3Rs – royalty, race and religion.
The account was then inundated with posts of screenshots of what appeared to be old tweets from MCMC's account, mostly from 2014. The messages in screenshots were mostly offensive.
For more information, visit www.courts.com.my/mcmc-hack
3,699 personal data breaches reported in Malaysia since 2017


He told Utusan Malaysia that the leak of personal details happens commonly when people register for things online.
“Among the ways your data can be breached is when you buy things online, make any sort of commercial transaction, registering your bank card, property, marketing, health and many more,” he was quoted saying.
“All these transactions require some form of personal data keyed in like your IC number and telephone number which makes it exposed to external threats. We found telecommunications agents who took a copy of your IC, gave it to these syndicates who then register another number illegally.
For more information, visit www.courts.com.my/personal-data
Your secret Twitter account may no longer be secret
Someone has gotten a hold of this data, and is selling it online.


If you have a secret Twitter account, we've got some bad news for you.
On Friday, Twitter disclosed information about a security vulnerability that allowed someone to find out whether a specific email address or phone number is tied to an existing Twitter accounts.
"In January 2022, we received a report through our bug bounty program of a vulnerability in Twitter's systems. As a result of the vulnerability, if someone submitted an email address or phone number to Twitter’s systems, Twitter's systems would tell the person what Twitter account the submitted email addresses or phone number was associated with, if any," the company wrote in a blog post Friday.
This means that, if you had someone's email address or phone number, you could easily find out whether a Twitter account was tied to that address or number. Say you had Elon Musk's address and checked this, and realized that he had an account that was different from the one he usually tweets from – boom, you've just found his secret account. Not great for anyone who wanted to tweet anonymously and/or privately.
For more information, visit www.courts.com.my/twitter-leak
Carousell faces data breach, database of 2.6 million users including Malaysians allegedly sold for USD 1,000


[ UPDATE 25/10/2022 14:00 ] Carousell has issued us with the following statement:
Based on what we have learned, the information that has been exposed includes:
- - Registered email address
- - Registered mobile number (if provided)
- - Date of birth (if provided)
- Our team is in the midst of assessing the situation and working on security enhancement features to prevent this type of event from happening in the future. We are also working with the relevant authorities on an investigation.
Protecting our users’ personal information has been and will always be of utmost importance to us. We are committed to providing our community with a safe shopping environment, we deeply regret this incident and would like to share our sincerest apologies.
For more information, visit www.courts.com.my/carousell-data-breach
IDENTIFY THEFT CHECKER
*Find out if your personal data has been exposed

4 WAYS TO MINIMIZE YOUR RISK AND WORRIES AFTER A DATA BREACH
5 ways to minimize your risks after a data breach alert
Discover the steps you should take to prevent ID theft and other online crimes when you find out you’ve been the victim of a data breach
Prevent your data from being used against you
Data breaches happen constantly. Unfortunately, no matter how effective your personal online security is, you cannot prevent attackers from stealing your private information from a service you’ve used.
Some breaches only include passwords, but often criminals find ways to steal bank card information, social security numbers, and other crucial pieces of personally identifiable information. These compromises and the leaks that follow can expose your private data to online criminals, who can use that information to fuel phishing attacks, fraud and even identity theft.
We also notes that a data breach doesn’t just put your information at risk, because following an account takeover your personal details may then be used by criminals to commit further online crimes against other individuals.
“We have seen, for example, cryptocurrency scams promoted by stolen Youtube or Twitter accounts,” says Maria Dacuno, Senior Researcher at F-Secure Labs.
But you shouldn’t feel singled out if your details are included in a breach, because just about everyone who uses the internet will eventually get a data breach alert. And in this post you’ll find out the five steps you should take as soon as you get one, which will help prevent your data from being used against you.
(a) Fire but excluding loss or damage:
(i) by its own fermentation, natural heating or spontaneous combustion or by its undergoing any heating or drying process;
(ii) by subterranean fire;
(iii) by burning of property by order of any Public Authority;
(b) Lightning;
(c) Flood which shall mean the overflowing or deviation from their normal channels of either natural or artificial water courses, bursting or overflowing of public water mains and any other flow or accumulation of water originating from outside the Building containing the Goods but excluding loss or damage by subsidence or landslip;
(d) Impact by any road vehicles not belonging to Purchaser or under Purchaser’s control or any member of Purchaser’s family or employees;
(e) Bursting or overflowing of water tanks, apparatus or pipes from within the Building;
(f) Theft consequent upon forcible and violent entry or exit of the Building.
(g) Available only for Flexi Smart Platinum Riots and strikers, locked-out workers or persons taking part in labour disturbances or malicious persons not acting on behalf of or in connection with any political organisation excluding:
(i) loss or damage occasioned by permanent or temporary dispossession resulting from confiscation, commandeering or requisition by any lawfully constituted authority;
(ii) loss or damage occasioned by permanent or temporary dispossession of any Building resulting from the unlawful occupation by any person of such Building;
The expression “Building” refers to the building within the Location, within which the Goods are contained. The expressions “total loss or damage” or “totally damaged” shall mean that the Goods concerned is damaged beyond economic repair.
For the avoidance of doubt, the expression “Goods” shall not include any bullion or unset precious stones, any curios or works of art, manuscripts, plans, drawings or designs, patterns, models or moulds, securities, obligations or documents of any kind, stamps, coins or paper money, cheques, books of account or other business books and computer systems records.
The expression “Damage Event” shall expressly exclude (1) any loss or damage occasioned by or through or in consequence of the burning whether accidental or otherwise of forests, bush, prairie, pampas or jungle and the clearing of lands by fire, (2) loss or damage happening whilst the Building containing the Goods is left without an inhabitant actually in them for a continuous period exceeding seven consecutive days and nights and (3) consequential loss of any kind.
1. Change that password—and any similar password
In the aftermath of a breach, publicity will often lead to websites of the affected services or companies being overloaded with worried individuals, all trying to check their data. In addition, the security team of a breached company may restrict your account access while they assess the damage.
After a few days, though, the breached service will likely be accessible. That’s when you should login and change your password to a new, longer, unique password.
And you should change your password for any service that has been breached, regardless of whether a company told you that your information was affected by the cyber attack. If you have used the same password, or any variation of this password–for example, adding a number or symbol to the end of the password for use on another service–you should also change those passwords.
And it is worth noting here that password tricks, like adding a number or slightly varying the ending of a password for use on multiple logins, add absolutely no additional security to your recycled passwords. And whilst your password may be breached, there are steps you can take to ensure that your account remains secure. According to F-Secure Labs one of the best ways to do this is to make sure that you turn on multi-factor authentication (MFA) for this and every account where it’s available.
“Multi-factor authentication in general adds a layer of protection for your accounts,” says Dacuno. “However, enforcing an MFA through a more secure method like an authenticator app is highly recommended.”
2. Check your cards
Following a breach alert you should check your account on the compromised service and immediately delete any stored bank or credit cards.
In general, it is good practice to avoid storing card details with any online services. So, this is a good time to remove any stored financial account information for any of your online services, unless absolutely necessary.
Even the most careful companies can be breached. And you do not want your cards to be part of any eventual breach.
3. Monitor and cancel
If you have been notified that your bank or credit card details have been leaked, you need to take immediate action. Call your bank and cancel your card.
This is a huge inconvenience, but necessary, especially if you do not have an alternative card to use, or have automatic payments set up with this card. You will have to wait for a new card to arrive, which can take days, or even weeks. But This is exactly why it is good practice to never save your cards with online services.
You should monitor the transactions on any card connected to a breached service, whether you were informed that card data was breached or not. Check for suspicious activity on a weekly basis–at least–and be ready to contact your provider to cancel the card.
4. Use a password manager
The best time to start using a password manager is before your data is breached. The second-best time is right now.
Not only is using a password manager the single best thing most people can do to improve their cyber security, it’s also much easier than most methods of storing and using secure data.
A password manager makes creating, saving, and using strong unique passwords for all your accounts easy. By simply using this tool many cyber security experts trust for their password and refusing to store your card numbers with any online services, your risks of data breach will be quite minimal. Especially if you do a good job of monitoring your online identity in general.
Special thanks to Fennel Aurora, Senior Product Manager at F-Secure, for his contribution to this post.
- PROTECT 360
- IDENTIFY THEFT CHECKER <check for free>
- CYBER SECURITY CONCERN WEBSITE LIST
- CYBER SECURITY
- ELITE+
- User Guide




A TOTAL INTERNET SECURITY SOLUTION


360 SAFE
360 SAFE offers comprehensive network protection for computers, smartphones, and tablets running Windows, Mac OS, Android or iOS
FEATURES:
• Anti Virus • Banking Protection • Browsing Protection
• Parental Control • Ransomeware Protecion • Gaming Mode




360 VPN
360 VPN Protect your privacy and minimize your digital footprint with encrypted browsing
FEATURES:
• Privacy Protection • WiFi Protection • Trusted WiFi networks
• Tracking Protecion • Protection Statistics • Malware Protection
360 IDP
360 IDP helps to prevent identity theft at the same time find out instantly and get help if a hacker has stolen information from online service
FEATURES:
• Password Manager • Auto-Fill Credentials
• Online Identity Monitoring • Breach Alert




BENEFITS
Get complete security, privacy, identity protection, and parental control- all in one apps


PROTECT 360 PACKAGE COMPARISON




PRIVACY POLICY >
For support, account deletion requests or any other questions related to mobile applications developed by Courts (Malaysia) Sdn Bhd for Protect 360 can be sent to cservice@courts.com.my or contact us at 03-3000 8998
AIG Insurance is a member of PIDM. The benefit(s) payable under eligible certificate/policy/product is(are) protected by PIDM up to limits. Please refer to PIDM’s TIPS Brochure or contact AIG Malaysia Insurance Berhad or PIDM (visit www.pidm.gov.my).
Cyber Security Concern Website List
Cybersecurity Malaysia: “Curb hacking by only using secured Wi-Fi connection”


ONLINE consumers who use e-wallets and other e-payment methods have been strongly advised not to conduct any transactions over a public Wi-Fi connection.
According to CyberSecurity Malaysia cryptography development head Hazlin Abdul Rani, threats and attacks from hackers could immediately happen through an unsecured public Wi-Fi where personal data, and possibly all account information and login credentials, could be accessed during the transaction process.
She also advised users to be cautious about the possibility of attackers impersonating the valid public Wi-Fi network.
“For example, if you are at an airport, the name of the Wi-Fi is ‘Airport ABC’, but the attacker creates a Wi-Fi with the name ‘Airport ABC1’, or even changes the capital or small alphabet letters of the Wi-Fi to make you believe that you are using a valid or legit Wi-Fi. This confusion can also lead users to fall into their trap,” she was reported as saying by Bernama
For more information, visit www.courts.com.my/public-wifi
SafetyDetectives: POS software provider StoreHub leaks 1 mil customers’ data


CYBERSECURITY expert SafetyDetectives has claimed that its team has discovered a major data leak affecting Malaysia-based point of sale (POS) software system provider StoreHub which is mostly used in restaurants and retail stores.
The exposed data was stored on a StoreHub’s Elasticsearch server that was left open without any password-protection or encryption, according to SafetyDetectives which reputed itself to be a publishing group of cybersecurity experts, privacy researchers and technical product reviewers located all over the world.
“The unprotected server potentially compromised the information of thousands of restaurants and retail stores, along with their staff and roughly (that of) 1 million customers,” it said in a report to FocusM.
According to SafetyDetectives, its cybersecurity team discovered that Storehub had misconfigured one of its Elasticsearch server, causing it to leak over 1.7 billion records and over 1 terabyte of data.
This exposed almost one million customers in Malaysia and potentially across Southeast Asian countries.
For more information, visit www.courts.com.my/software-provider
Malaysia records RM560m loss in cyber crime last year


MALAYSIA recorded over 20,000 cyber crime cases last year with losses amounting to RM560 million, said deputy secretary-general (Security) of the Home Ministry, Datuk Abdul Halim Abdul Rahman.
He said the cases recorded included cyber bullying, falsification, hacking, phishing and e-mail scams which were increasing each year.
“For the record, about 13,000 cyber crime cases with RM539 million in losses were recorded in 2019,” added Abdul Halim who did not give the figures for 2020.
“By 2025, the digital economy is expected to contribute about 22.6 per cent to the country’s Gross Domestic Product (GDP).
“Therefore, in Malaysia’s effort to develop itself into a nation that is driven by digital economy, we need to identify the threats with the potential to affect the key targets and the economic sector in general.”
He said this when officiating at the National-Level Key Targets Seminar 2022, representing Home Minister, Datuk Seri Hamzah Zainuddin.
Key targets refer to the applications with the vital output or services that if destroyed or are in disrepair, could cause great losses to the country’s economy and defence, and also affect its image and government’s functions.
For more information, visit www.courts.com.my/cyber-crime
PM lodges report over hacked Telegram, Signal accounts”


KUALA LUMPUR: Prime Minister Datuk Seri Ismail Sabri Yaakob has lodged a report with the Malaysian Communications and Multimedia Commission (MCMC) and the Royal Malaysia Police (PDRM) on his personal Telegram and Signal accounts being hacked by irresponsible parties.
The Prime Minister's Office (PMO) , in a statement on Tuesday (Aug 9), stated that it believed the accounts were used for fraudulent criminal activities and advised those who received messages from the accounts concerned to ignore them and report to the authorities.
For more information, visit www.courts.com.my/pm-hack
Kiplepay informs customers of potential risks by third-party provider
• Informed customers of risks through a thrid-party gateway provider
• Heightened security toprevent any suspicious transaction activities


E-wallet service provider Kiplepay Sdn Bhd, a wholly-owned subsidiary of Green Packet Bhd, has informed its Kiple Visa prepaid card users via email of a risk through a recent third-party payment gateway provider data breach on Aug 15.
In a statement, the firm said the customer communication was released following Bank Negara Malaysia’s (BNM) notification to the company, which highlighted the recent potential third-party data breach incident.
It said it has also requested that the company notify affected cardholders of additional protective measures that are being taken to protect them against risks of fraudulent or unauthorised transactions that may arise from this incident.
Kiplepay said the data breach highlighted was a cybersecurity incident which has occurred to a third-party which may affect Kiplepay users who performed transactions using the third-party payment gateway system.
For more information, visit www.courts.com.my/ewallet-breach
Annuar: Ministry to take immediate action over iPay88 issue
KOTA BARU: The Communications and Multimedia Ministry will take immediate action regarding the data breach incident that hit online payment service provider, iPay88 (M) Sdn Bhd, says Tan Sri Annuar Musa.
“The case is still being investigated further by iPay88’s vendor, SISA from Singapore, who identified the threat Cobalt Strike being used.
For more information, visit www.courts.com.my/payment-provider
Two years on, Apple iOS VPNs still leak IP addresses
Privacy, it's a useful marketing term. *Offer does not apply in China
Apple has left a VPN bypass vulnerability in iOS unfixed for at least two years, leaving identifying IP traffic data exposed, and there's no sign of a fix.
Back in early 2020, secure mail provider ProtonVPN reported a flaw in Apple’s iOS version 13.3.1 that prevented VPNs from encrypting all traffic. The issue was that the operating system failed to close existing connections.
This could potentially allow an attacker to identify a VPN user's source IP address. For those actually relying on hiding that data to avoid attention from a repressive regime or someone seeking private information, this is not a trivial concern.
For more information, visit www.courts.com.my/apple-ios-vpn-leakMonths after 'hacking' incident, MCMC is back on Twitter


PETALING JAYA: The Malaysian Communications and Multimedia Commission (MCMC) is back on Twitter under a new handle – @MCMC_RASMI – six months after it claimed its original account was hacked.
MCMC sent out its first tweet using the new account, which now has over 300 followers, on July 5.
In January, MCMC announced that it had to temporarily suspend its previous account, @SKMM_MCMC, after it was allegedly hacked. The account had over 70,000 followers.
The last tweet from the account before it was deactivated was a statement saying that MCMC will monitor social media for misinformation in regards to the 3Rs – royalty, race and religion.
The account was then inundated with posts of screenshots of what appeared to be old tweets from MCMC's account, mostly from 2014. The messages in screenshots were mostly offensive.
For more information, visit www.courts.com.my/mcmc-hack
3,699 personal data breaches reported in Malaysia since 2017


He told Utusan Malaysia that the leak of personal details happens commonly when people register for things online.
“Among the ways your data can be breached is when you buy things online, make any sort of commercial transaction, registering your bank card, property, marketing, health and many more,” he was quoted saying.
“All these transactions require some form of personal data keyed in like your IC number and telephone number which makes it exposed to external threats. We found telecommunications agents who took a copy of your IC, gave it to these syndicates who then register another number illegally.
For more information, visit www.courts.com.my/personal-data
Your secret Twitter account may no longer be secret
Someone has gotten a hold of this data, and is selling it online.


If you have a secret Twitter account, we've got some bad news for you.
On Friday, Twitter disclosed information about a security vulnerability that allowed someone to find out whether a specific email address or phone number is tied to an existing Twitter accounts.
"In January 2022, we received a report through our bug bounty program of a vulnerability in Twitter's systems. As a result of the vulnerability, if someone submitted an email address or phone number to Twitter’s systems, Twitter's systems would tell the person what Twitter account the submitted email addresses or phone number was associated with, if any," the company wrote in a blog post Friday.
This means that, if you had someone's email address or phone number, you could easily find out whether a Twitter account was tied to that address or number. Say you had Elon Musk's address and checked this, and realized that he had an account that was different from the one he usually tweets from – boom, you've just found his secret account. Not great for anyone who wanted to tweet anonymously and/or privately.
For more information, visit www.courts.com.my/twitter-leak
Carousell faces data breach, database of 2.6 million users including Malaysians allegedly sold for USD 1,000


[ UPDATE 25/10/2022 14:00 ] Carousell has issued us with the following statement:
Based on what we have learned, the information that has been exposed includes:
- - Registered email address
- - Registered mobile number (if provided)
- - Date of birth (if provided)
- Our team is in the midst of assessing the situation and working on security enhancement features to prevent this type of event from happening in the future. We are also working with the relevant authorities on an investigation.
Protecting our users’ personal information has been and will always be of utmost importance to us. We are committed to providing our community with a safe shopping environment, we deeply regret this incident and would like to share our sincerest apologies.
For more information, visit www.courts.com.my/carousell-data-breach
IDENTIFY THEFT CHECKER
*Find out if your personal data has been exposed

4 WAYS TO MINIMIZE YOUR RISK AND WORRIES AFTER A DATA BREACH
5 ways to minimize your risks after a data breach alert
Discover the steps you should take to prevent ID theft and other online crimes when you find out you’ve been the victim of a data breach
Prevent your data from being used against you
Data breaches happen constantly. Unfortunately, no matter how effective your personal online security is, you cannot prevent attackers from stealing your private information from a service you’ve used.
Some breaches only include passwords, but often criminals find ways to steal bank card information, social security numbers, and other crucial pieces of personally identifiable information. These compromises and the leaks that follow can expose your private data to online criminals, who can use that information to fuel phishing attacks, fraud and even identity theft.
We also notes that a data breach doesn’t just put your information at risk, because following an account takeover your personal details may then be used by criminals to commit further online crimes against other individuals.
“We have seen, for example, cryptocurrency scams promoted by stolen Youtube or Twitter accounts,” says Maria Dacuno, Senior Researcher at F-Secure Labs.
But you shouldn’t feel singled out if your details are included in a breach, because just about everyone who uses the internet will eventually get a data breach alert. And in this post you’ll find out the five steps you should take as soon as you get one, which will help prevent your data from being used against you.
(a) Fire but excluding loss or damage:
(i) by its own fermentation, natural heating or spontaneous combustion or by its undergoing any heating or drying process;
(ii) by subterranean fire;
(iii) by burning of property by order of any Public Authority;
(b) Lightning;
(c) Flood which shall mean the overflowing or deviation from their normal channels of either natural or artificial water courses, bursting or overflowing of public water mains and any other flow or accumulation of water originating from outside the Building containing the Goods but excluding loss or damage by subsidence or landslip;
(d) Impact by any road vehicles not belonging to Purchaser or under Purchaser’s control or any member of Purchaser’s family or employees;
(e) Bursting or overflowing of water tanks, apparatus or pipes from within the Building;
(f) Theft consequent upon forcible and violent entry or exit of the Building.
(g) Available only for Flexi Smart Platinum Riots and strikers, locked-out workers or persons taking part in labour disturbances or malicious persons not acting on behalf of or in connection with any political organisation excluding:
(i) loss or damage occasioned by permanent or temporary dispossession resulting from confiscation, commandeering or requisition by any lawfully constituted authority;
(ii) loss or damage occasioned by permanent or temporary dispossession of any Building resulting from the unlawful occupation by any person of such Building;
The expression “Building” refers to the building within the Location, within which the Goods are contained. The expressions “total loss or damage” or “totally damaged” shall mean that the Goods concerned is damaged beyond economic repair.
For the avoidance of doubt, the expression “Goods” shall not include any bullion or unset precious stones, any curios or works of art, manuscripts, plans, drawings or designs, patterns, models or moulds, securities, obligations or documents of any kind, stamps, coins or paper money, cheques, books of account or other business books and computer systems records.
The expression “Damage Event” shall expressly exclude (1) any loss or damage occasioned by or through or in consequence of the burning whether accidental or otherwise of forests, bush, prairie, pampas or jungle and the clearing of lands by fire, (2) loss or damage happening whilst the Building containing the Goods is left without an inhabitant actually in them for a continuous period exceeding seven consecutive days and nights and (3) consequential loss of any kind.
1. Change that password—and any similar password
In the aftermath of a breach, publicity will often lead to websites of the affected services or companies being overloaded with worried individuals, all trying to check their data. In addition, the security team of a breached company may restrict your account access while they assess the damage.
After a few days, though, the breached service will likely be accessible. That’s when you should login and change your password to a new, longer, unique password.
And you should change your password for any service that has been breached, regardless of whether a company told you that your information was affected by the cyber attack. If you have used the same password, or any variation of this password–for example, adding a number or symbol to the end of the password for use on another service–you should also change those passwords.
And it is worth noting here that password tricks, like adding a number or slightly varying the ending of a password for use on multiple logins, add absolutely no additional security to your recycled passwords. And whilst your password may be breached, there are steps you can take to ensure that your account remains secure. According to F-Secure Labs one of the best ways to do this is to make sure that you turn on multi-factor authentication (MFA) for this and every account where it’s available.
“Multi-factor authentication in general adds a layer of protection for your accounts,” says Dacuno. “However, enforcing an MFA through a more secure method like an authenticator app is highly recommended.”
2. Check your cards
Following a breach alert you should check your account on the compromised service and immediately delete any stored bank or credit cards.
In general, it is good practice to avoid storing card details with any online services. So, this is a good time to remove any stored financial account information for any of your online services, unless absolutely necessary.
Even the most careful companies can be breached. And you do not want your cards to be part of any eventual breach.
3. Monitor and cancel
If you have been notified that your bank or credit card details have been leaked, you need to take immediate action. Call your bank and cancel your card.
This is a huge inconvenience, but necessary, especially if you do not have an alternative card to use, or have automatic payments set up with this card. You will have to wait for a new card to arrive, which can take days, or even weeks. But This is exactly why it is good practice to never save your cards with online services.
You should monitor the transactions on any card connected to a breached service, whether you were informed that card data was breached or not. Check for suspicious activity on a weekly basis–at least–and be ready to contact your provider to cancel the card.
4. Use a password manager
The best time to start using a password manager is before your data is breached. The second-best time is right now.
Not only is using a password manager the single best thing most people can do to improve their cyber security, it’s also much easier than most methods of storing and using secure data.
A password manager makes creating, saving, and using strong unique passwords for all your accounts easy. By simply using this tool many cyber security experts trust for their password and refusing to store your card numbers with any online services, your risks of data breach will be quite minimal. Especially if you do a good job of monitoring your online identity in general.
Special thanks to Fennel Aurora, Senior Product Manager at F-Secure, for his contribution to this post.




360 SAFE
360 SAFE offers comprehensive network protection for computers, smartphones, and tablets running Windows, Mac OS, Android or iOS
























