Credit bureau CTOS reports unauthorised access and temporarily suspends some reports
Key points
- CTOS Digital detected unauthorised access to an environment supporting its consumer business and disclosed it to Bursa Malaysia.
- Files containing some consumer information were accessed; the number of people affected was not disclosed.
- Some credit-report services were temporarily unavailable; the company expects no material financial impact.
Facts
Disclosure: on 23 September 2026 private credit bureau CTOS Digital told Bursa Malaysia it had detected unauthorised access to a specific environment supporting its consumer business and that data files containing some consumer information were accessed. Source: Malay Mail (23 September).
Impact: the company engaged an independent investigation team and said the incident was contained within that environment. Some credit-report services were temporarily unavailable during recovery. The number of people affected and the types of data were not disclosed. It said there would be no material financial impact. Same source.
Analysis
For lenders that require a private bureau check in underwriting, an outage at the bureau stops underwriting. The MyKad eKYC issue (21 September) occurred in the same week, exposing infrastructure dependency risk. In Indonesia, OJK has also cautioned against total reliance on private bureaus' AI scores (17 September); managing dependence on external data is a common regional challenge.
Implications
Counterpoints and uncertainties
The company describes the impact as limited; the scope of the leaked data and whether it has been misused await the investigation. Neither source addresses whether alternative bureau or central-register checks were affected.
Sources
Reports are for information only and are not investment advice. Methodology: sources, verification and definitions