Cyber Alerts
Verified· Officially confirmed
Recently, the Cyber999 Incident Response Centre has been observing a notable increase in ransomware-related incidents targeting organisations across Malaysia. These attacks have affected a wide range of sectors, including businesses, hence highlighting the growing threat posed by ransomware threat actors. Ransomware activity continued at a significant pace into 2026. Building on the 51 incidents recorded throughout 2025, the first two quarters of 2026 alone accounted for 29 incidents (17 in Q1, 12 in Q2), signalling that ransomware remains a sustained operational risk rather than a diminishing one. Active Threat Groups identified across Q1 and Q2 2026 include LockBit, The DragonHorse, Qilin, Akira, Lynx Group, Black Shatrac, Thegentlemen, CrySiS, Obscura, Skynet, Ransom24 Group, DeadLock, and INC Ransom, alongside several unidentified variants. Threat actors continue to leverage compromised credentials (often harvested via Infostealers), unpatched vulnerabilities, and social engineering to gain initial entry. Organisations must reinforce infrastructure defences and ensure rapid incident reporting to mitigate nationwide impact. 2.0 Impacts Below is the list of ransomware impacts that could be devastating to organisations: Service Interruption: Customer-facing services may go offline, damaging trust and reputation.System and network infrastructure compromised.Files on the infected computer are encrypted, and the owner cannot access the files until a ransom (usually in a cryptocurrency such as Bitcoin) is paid.System Downtime: Ransomware often encrypts critical data and systems, halting business operations.Business operations are disrupted due to permanent or temporary loss of sensitive or proprietary data belonging to an organisation.Aside from financial gain, it exploits sensitive data and uses it as a levy. If the ransom is not paid within time, organisations’ confidential data are exposed, and trade secrets are compromised.Financial loss: Some organisations may feel pressured to pay the ransom, which can be substantial. Restoring systems, conducting forensics, and improving security can be very expensive. A data breach can result in reputational harm to the government and diminish trust in government digital transformation programmes.