KUALA LUMPUR, Sept 23, 2026 — CTOS Digital Berhad has disclosed a cybersecurity incident involving unauthorised access to a specific environment supporting its consumer business.
In an announcement to Bursa Malaysia, the company said its cybersecurity systems detected the unauthorised access, following which it immediately activated its incident-response protocols and contained the affected environment.
CTOS said it has appointed an independent incident-response team to conduct a comprehensive forensic investigation. Based on the assessment received so far, the incident remains contained within the identified environment, while the company’s other systems continue to operate and no other environments were impacted.
The forensic assessment found that certain data files containing a limited subset of processed consumer information were accessed from the affected environment.
The company said it is continuing to review its cybersecurity protocols and strengthen its security posture in line with recommendations from the independent forensic investigation.
As part of the remediation process, a subset of CTOS’s credit-reporting services has been temporarily made unavailable. Other business operations and services, however, continue to operate normally.
CTOS said that, based on the facts currently available, it does not expect the incident to have a material financial impact on the company.
The company has notified the relevant authorities and said it will continue monitoring the situation. Further announcements will be made if there are material developments.
CTOS also reiterated its commitment to compliance, corporate governance and maintaining the security of its cybersecurity infrastructure, while assuring shareholders, customers, business partners and other stakeholders that it would continue to manage the matter in a responsible and transparent manner.
The announcement was dated Sept 23, 2026.










Leave a Reply