
MCMC Ordered to Investigate Alleged Leak of Khairul Aming’s Personal Data
KUALA LUMPUR: Communications Minister Fahmi Fadzil has instructed the Malaysian Communications and Multimedia Commission (MCMC) to conduct a thorough investigation into allegations that the personal data of influencer and entrepreneur Khairul Aming was accessed and disclosed without authorisation by individuals allegedly linked to a telecommunications company.
The directive comes following claims circulating on social media that confidential customer information may have been improperly accessed through a telecommunications provider’s internal system, raising fresh concerns over the handling of personal data and consumer privacy in Malaysia.
Speaking during the International Regulators Conference (IRC) 2026 in Kuala Lumpur, Fahmi said MCMC had been tasked with obtaining a comprehensive report into the matter to determine whether any breach of customer data protection laws had occurred.
According to the minister, the allegations suggest that individuals who were not authorised to access customer records were nevertheless able to view sensitive account information maintained by the telecommunications provider.
Fahmi confirmed that he had already met representatives of the company involved, who informed him they were in the process of contacting Khairul Aming to address the allegations and obtain further information regarding the incident.
The controversy emerged after a user on the social media platform Threads publicly claimed to possess details relating to Khairul Aming’s mobile phone account, including an alleged outstanding bill of RM498 as well as information concerning additional digital purchases linked to the account.
In response, Khairul Aming publicly questioned how such information could have been obtained and called on the telecommunications company to explain whether there had been unauthorised access to his personal records.
Fahmi stressed that the disclosure of personally identifiable information (PII) without an individual’s consent may constitute an offence under Malaysia’s Personal Data Protection Act (PDPA).
He said legal action could be taken against any individual or party found to have unlawfully accessed or shared protected customer information.
The minister also encouraged members of the public who believe they have experienced similar incidents involving unauthorised disclosure of personal information to submit formal reports to MCMC.
He explained that official complaints would enable investigators to gather the necessary evidence and establish whether wider systemic issues exist that require regulatory or enforcement action.
The investigation is expected to examine whether internal access controls, employee conduct and existing data protection measures were sufficient to safeguard customer information from unauthorised viewing or disclosure.
The Communications Ministry said further updates are expected once MCMC completes its inquiry and determines whether any violations of Malaysia’s data protection laws or telecommunications regulations have occurred.
The case has renewed attention on the importance of protecting customer data, particularly as businesses increasingly rely on digital platforms and electronic records to manage sensitive personal information.



