People search Malaysia Inland Revenue Board (LHDN) data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 1 Malaysia Inland Revenue Board (LHDN)-linked incident, with headline counts up to 10M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Malaysia Inland Revenue Board (LHDN) breach history matters
Malaysia Inland Revenue Board (LHDN) operates in Government (Malaysia). Across indexed rows, recurring themes include unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — dezetat sale claim (unverified); 10M taxpayer records alleged
Unverified claim — treat actor counts cautiously. Unverified sale claim — indexed July 2–3, 2026. Threat-intelligence monitoring reported actor dezetat advertising a $20,000 sale of what they describe as 10 million taxpayer records exfiltrated in June 2026 from Malaysia's Inland Revenue Board (LHDN/IRBM) MyTax portal, including NRIC national ID numbers, tax numbers, contact details, MyTax security phrases, bank account numbers for roughly 5.29 million records, and tax-filing metadata. Dark Web Informer and VECERTRadar summarized the listing; neither LHDN nor MyCER Exposed categories include Actor-claimed JSON repository with NRIC numbers, tax IDs (TIN), names, dates of birth, marital status, addresses, emails, phones, MyTax security phrases, bank account numbers (~5.2. BreachHistory cites approximately 10M+ affected records in this row. See the lhdn-mytax-sale 2026 record and canonical BreachHistory entry.
Patterns and analysis
- Unverified actor or scraping claims — appears across multiple Malaysia Inland Revenue Board (LHDN) catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the Malaysia Inland Revenue Board (LHDN) company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/malaysia-inland-revenue-board · Latest: lhdn-mytax-sale2026.
Sources: BreachHistory catalog (1 row for Malaysia Inland Revenue Board (LHDN)), company and regulator disclosures cited in individual breach records.