Someone inside Khairul Aming's own telco had already seen his phone bill. Not a hacker breaking through a firewall from some distant server. Someone already on the inside, with legitimate login access, who simply looked.
What Happened To Khairul Aming
It started on Threads. A user publicly claimed to know specifics about the content creator and entrepreneur's mobile account, including an alleged RM498 outstanding balance and details of his digital add-on purchases. Khairul Aming questioned how anyone outside the company could possibly know that and demanded answers.
Communications Minister Fahmi Fadzil moved quickly, ordering the Malaysian Communications and Multimedia Commission to obtain a full report, and stressing that sharing personally identifiable information without consent is a criminal offence under the Personal Data Protection Act.
Maxis has since confirmed it identified the individual responsible, describing it as an isolated case of unauthorised access, apologising directly to Khairul Aming, and confirming legal action is underway. The telco says all account access is logged and monitored, and that its investigation found no evidence of a wider breach involving other customers.
That's reassuring, as far as it goes. But it also confirms the exact fear most of us have never said out loud: someone with the right login credentials can simply look up your bill, and unless they get careless enough to post about it, you'd never know.
This Isn't Malaysia's First Telco Leak
If this feels like a one-off scandal, it isn't. Malaysia's telecommunications sector has a documented history with this exact problem. The 2014 breach that exposed 46.2 million mobile subscriber records, spanning nearly every major telco and MVNO in the country, was traced back in part to a subcontractor connected to the industry regulator itself, with file references pointing directly to internal government and telco systems.
Telekom Malaysia has also had customer data surface on dark web forums in more recent years. The pattern is consistent: the biggest risk to your personal data usually isn't some anonymous hacker overseas. It's someone who already has a legitimate reason to be inside the system, choosing to misuse that access.
The Anxiety I've Always Carried
I'll admit this one hits close to home for me personally. Every time I sign up for a new service, a bank account, a telco line, even a social media platform, there's a small, persistent worry at the back of my mind about who exactly can see what I've handed over. Creating a social media account is, in a very real sense, giving a private company a standing archive of your personal information, and you're trusting that everyone with internal access treats that trust the way they're supposed to.
Most of the time that trust holds. This case is a reminder that it doesn't always, and that the weak point usually isn't the technology, it's the people who work inside it.
The Law Finally Has Teeth
The good news, such as it is, is that the legal consequences here are no longer trivial. Under the 2024 amendment to the Personal Data Protection Act, penalties for breaching the Act's core data protection principles jumped from a maximum RM300,000 fine to RM1 million, and from two years' imprisonment to three. Companies are now also required to appoint a designated Data Protection Officer and notify the Personal Data Protection Commissioner as soon as they become aware of a breach.
These changes came into force through 2025, which means this Khairul Aming case is one of the first high-profile tests of whether the stronger penalties actually translate into consequences, not just headlines.
What To Actually Do If This Happens To You
If you ever suspect your own data has been accessed or shared without your consent, don't just quietly stew over it. Contact the company directly and ask for written confirmation of what happened and who accessed your account. Lodge a formal report with MCMC so there's an official record investigators can act on, since Fahmi himself has urged the public to do exactly this.
You're also entitled to file a complaint with the Personal Data Protection Commissioner separately, since unauthorised disclosure of your information is a breach of your rights under the Act, not just a company policy violation. The paperwork feels tedious in the moment, but it's the difference between an incident quietly disappearing and one that actually gets investigated.
Why Insider Access Keeps Being The Weak Link
Here's the harder truth underneath all of this. Companies can spend enormous amounts on firewalls, encryption, and cybersecurity software, and still lose control of your data because one employee decided to look something up out of curiosity, gossip, or worse. Access logs and monitoring, which Maxis says it has, help catch misuse after the fact, but they don't prevent the moment of temptation itself.
That requires a genuine culture of accountability inside these companies, strict need-to-know access controls, real consequences that are actually enforced, and staff who understand that a customer's phone bill isn't casual reading material. Stronger laws help, but they're a deterrent after the damage, not a wall that stops it from happening in the first place.
My Take
What stays with me about this case isn't really the RM498 balance or the specific add-ons someone leaked, it's how ordinary the exposure was. Khairul Aming didn't get hacked by anything sophisticated. Someone just looked. That should worry all of us a little, because the same access exists for every one of our accounts, at every company we've ever trusted with our details. The law now has real teeth, and that matters.
But until companies treat internal access as seriously as they treat outside threats, the person most likely to see something they shouldn't isn't a stranger on the internet, it's someone already on the payroll.
Kamarul Azwan (k.azwan@gmail.com) is a content creator under the Newswav Creator programme, where you get to express yourself, be a citizen journalist, and at the same time monetize your content & reach millions of users on Newswav. Log in to creator.newswav.com and become a Newswav Creator now!
The User Content (as defined on Newswav Terms of Use) above including the views expressed and media (pictures, videos, citations etc) were submitted & posted by the author. Newswav is solely an aggregation platform that hosts the User Content. If you have any questions about the content, copyright or other issues of the work, please contact creator@newswav.com.


