search

LEMON BLOG

Khairul Aming Sends Letter of Demand to Maxis After Alleged Customer Data Leak

Malaysian entrepreneur and content creator Khairul Aming has taken formal legal action following the alleged exposure of information connected to his Maxis account. His lawyers have issued a letter of demand to Maxis, while separate reports have been lodged with the Malaysian Communications and Multimedia Commission, the police and the Personal Data Protection Commissioner. Khairul said his legal team would manage the case until it is resolved. 

The incident has attracted widespread attention because the information reportedly went beyond an ordinary telephone bill. Khairul expressed concern that details involving his telephone account, payment history, subscriptions and identity card number had been exposed.

Although Maxis has described the incident as isolated and says it has identified the individual linked to the disclosure, investigations by Malaysian authorities are still underway. No final regulatory or judicial finding has been made.

How the Controversy Began on Threads

The issue surfaced after a Threads user posted information that appeared to come from Khairul Aming's telecommunications account.

The post allegedly referred to an outstanding amount of approximately RM498, a previous advance payment and purchases of digital add-ons. Khairul then publicly questioned how another person had obtained information that should ordinarily have remained between him and the service provider.

The original discussion may have begun as commentary about an unpaid bill, but the more serious issue quickly became the source of the information.

A person does not normally need access to another customer's billing records to comment on that person online. If the details genuinely originated from an internal customer-management system, the incident raises questions about who accessed the account, whether that access was authorised and how the information reached social media.

It also shows how a seemingly casual post can become evidence in a much larger privacy investigation.

The Alleged Exposure Went Beyond a Phone Bill

Khairul said the exposed information included telephone details, payment history, subscription information and his MyKad number. He also highlighted the potential seriousness of an identity card number being exposed because it may be used to verify access to other services, including MySARA.

An outstanding balance on its own may appear relatively limited. When combined with an identity number, contact details, transaction history and subscription information, however, the data can create a much more complete profile of the customer.

Criminals may use combinations of accurate information to make impersonation attempts more convincing. Someone who knows a person's telco, billing amount, identification number or account history may appear more credible when pretending to represent a bank, telecommunications provider or government service.

The incident should therefore not be dismissed simply because it did not initially appear to involve passwords or complete banking credentials.

What a Letter of Demand Means

A letter of demand is a formal legal notice sent by one party to another.

It normally sets out the alleged wrongdoing, the action or explanation being requested and a deadline for responding. Depending on the circumstances, it may demand compensation, corrective action, disclosure of information, preservation of evidence or an undertaking that the conduct will not happen again.

Issuing a letter of demand does not mean a court has ruled that Maxis is legally responsible. It also does not automatically begin a lawsuit.

It is usually an early step that gives the receiving party an opportunity to respond before further legal proceedings are considered.

Khairul did not publicly disclose the full contents of the demand or specify the remedy being sought. His announcement instead confirmed that his lawyers had taken over the matter and would pursue it until its conclusion.

Reports Lodged With Several Authorities

The case is now being examined through several different channels.

Khairul lodged a complaint with MCMC, which regulates Malaysia's communications and multimedia sector. He also filed a police report at the Dang Wangi district police headquarters to enable an investigation into the individual believed to be involved.

A separate personal data breach report was submitted to the Personal Data Protection Commissioner.

Each organisation may examine a different part of the incident.

MCMC can consider matters involving the telecommunications provider and communications-related regulation. The police can investigate whether criminal offences may have occurred. The personal data protection authorities can assess whether the handling and disclosure of customer information complied with the Personal Data Protection Act 2010.

These processes may overlap, but one investigation does not replace the others.

JPDP Opens an Investigation Under the PDPA

The Personal Data Protection Department confirmed that it had opened an investigation into the alleged unauthorised disclosure of a telecommunications customer's account and billing information.

The department said the investigation was being conducted under the Personal Data Protection Principles and Section 130 of the Personal Data Protection Act 2010, which addresses the unlawful collection or disclosure of personal data. Appropriate enforcement action may follow if investigators identify non-compliance with Act 709.

The department also reminded data controllers that they must follow Malaysia's seven Personal Data Protection Principles.

These cover general processing, notice and choice, disclosure, security, retention, data integrity and access. The Security Principle specifically requires practical steps to protect personal data against loss, misuse and unauthorised access or disclosure.

For commercial organisations, simply collecting customer information creates a continuing responsibility to control who can access it and how it may be used.

Accessing Information Is Already a Form of Processing

Malaysia's personal data guidance defines "processing" broadly.

It can include collecting, recording, storing, organising, changing, using, disclosing and destroying personal information. The official guidance also states that merely reading or accessing personal data can amount to processing.

That is important in a case involving a possible internal account lookup.

Even when a person does not alter or download a customer record, viewing the information without a valid work-related reason may still be relevant to a privacy investigation. Sharing it outside the organisation creates an additional and more obvious concern.

This is why companies need controls that cover both technical access and employee behaviour. A secure database is not enough when authorised credentials can be misused by someone who has no legitimate reason to open a particular account.

MCMC Was Asked to Produce a Full Report

Communications Minister Fahmi Fadzil directed MCMC to obtain a complete report on the incident after Khairul lodged an official complaint.

Fahmi said the allegations were concerning because they suggested that someone who should not have had access to customer information may have been able to view details held in a telecommunications company's internal systems.

He also urged other consumers who experience similar incidents to submit formal complaints rather than relying solely on social media posts.

Official reports are important because they provide investigators with dates, screenshots, account details and other evidence needed to establish how the information was obtained.

Public attention can pressure an organisation to respond quickly, but a formal complaint creates a clearer path for regulatory follow-up.

Maxis Says the Incident Was Isolated

Maxis has apologised and described the matter as an isolated incident involving an unauthorised action.

The telecommunications company said access to customer accounts is logged and monitored. Based on those records, it identified the individual linked to the disclosure and began immediate action, including legal proceedings.

Maxis also said its preliminary findings showed no indication of a broader incident involving other customers.

That distinction is significant. A large-scale system breach could mean an attacker obtained access to thousands or millions of records. An isolated incident may instead involve the misuse of legitimate access by a particular individual.

However, an isolated incident is not necessarily a minor one.

For the affected customer, the impact can be serious regardless of whether one account or one million accounts were involved. It can also expose weaknesses in employee monitoring, access permissions or the organisation's response to inappropriate account lookups.

Maxis's conclusion remains part of its internal findings, while the authorities are conducting their own investigations.

Why Logging Customer Access Matters

The ability to identify the person linked to the incident appears to have depended on account-access logs.

Good logging records which employee or system opened an account, when the access occurred, what information was viewed and what actions followed. These records are essential for investigating suspected misuse.

However, logs are most useful when they are actively monitored rather than reviewed only after a customer complains.

A telecommunications provider handles large amounts of valuable information. Employees may need access to customer records to resolve billing problems, manage subscriptions or provide technical support, but that access should be limited to legitimate job functions.

A strong control system should be able to flag unusual behaviour, such as:

The objective is not merely to discover who leaked information after it appears online. It is to identify suspicious access before the data leaves the organisation.

The Insider-Threat Problem

Many organisations think of a data breach as an external hacker breaking through a firewall.

In practice, personal information can also be exposed through employees, contractors, outsourced service providers or anyone else with legitimate system credentials.

An insider incident may involve deliberate misuse, curiosity, financial motivation, retaliation or something as simple as showing private information to another person without understanding the consequences.

These situations are difficult because the individual may not need to defeat security controls. The system already recognises their username and password.

The defence therefore requires more than encryption and antivirus software. Organisations need role-based permissions, regular access reviews, behavioural monitoring, staff training, strong disciplinary policies and a clear process for reporting suspicious activity.

Sensitive information should also be masked where possible. A customer-service employee who does not need to see a complete MyKad number should not automatically receive it on the screen.

Why High-Profile Customers Can Become Targets

Public figures are particularly vulnerable to inappropriate account lookups.

Employees may be tempted to access the records of celebrities, politicians, colleagues, former partners or people involved in online controversies simply out of curiosity. Similar incidents have occurred internationally across healthcare, banking and telecommunications environments.

This is sometimes called celebrity snooping, but the risk applies to ordinary customers as well.

An employee may view the account of a neighbour, family member or acquaintance. The absence of fame does not make the intrusion less serious.

Organisations holding sensitive information should therefore monitor access based on behaviour rather than waiting for a well-known customer to complain publicly.

Privacy protection must work equally for someone with millions of followers and someone with none.

What Malaysian Consumers Can Learn From the Incident

Most customers cannot control the internal systems used by their telecommunications provider, bank or other service company.

They can still take several practical precautions.

People should be cautious when callers or message senders mention accurate billing or account information. Possessing genuine details does not prove that the person represents the organisation.

Customers should end unexpected calls and contact the company through its official application, website or published number. Verification codes, passwords and banking credentials should never be provided merely because a caller appears to know personal information.

Consumers should also retain screenshots and report suspicious disclosures quickly. Where relevant, complaints can be lodged with the service provider, MCMC, the police and the Personal Data Protection Commissioner.

The incident demonstrates why privacy-related complaints should not be ignored simply because no money has yet been stolen.

What Companies Should Review

The broader lesson extends well beyond Maxis.

Every Malaysian organisation that holds customer information should examine whether its employees can access more data than they genuinely need.

A useful internal review should ask:

Malaysia's official data-protection framework now places emphasis on data controllers, security standards, Data Protection Officers and breach notification responsibilities.

Policies are important, but they must be supported by technical controls and consistent enforcement.

A Test of Malaysia's Data-Protection Enforcement

The case has become bigger than one influencer's telephone account because it offers a visible test of how Malaysian authorities respond to alleged internal misuse of personal information.

The Personal Data Protection Act is intended to regulate personal data used in commercial transactions and protect the interests of individuals whose information is being processed.

The public will therefore be watching whether the investigations establish:

A transparent conclusion would help customers understand whether the matter was truly limited to one individual and what changes are being made to prevent a recurrence.

Final Thoughts

Khairul Aming's letter of demand has moved the incident beyond an online dispute and into a formal legal and regulatory process.

Maxis says it has identified the individual involved, begun legal action and found no evidence that other customers were affected. JPDP, MCMC and the police are now examining the matter through their respective authorities.

Until those investigations conclude, the incident should continue to be described as an alleged unauthorised disclosure, rather than a proven company-wide data breach.

Even so, the public concern is understandable. Customers provide telecommunications companies with identity details, contact information, billing history and records of their subscriptions because those details are necessary to receive a service—not because they expect them to appear on social media.

The real measure of data protection is not whether an organisation can identify the person responsible after a leak. It is whether its controls can stop an unauthorised person from viewing and disclosing the information in the first place.

OpenAI Models Breached Hugging Face While Trying t...

Related Posts

 

Comments

No comments made yet. Be the first to submit a comment
Wednesday, 22 July 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection