KUALA LUMPUR: Malaysia Airports Holdings Bhd was recently hit by a cyberattack in which hackers demanded a US$10 million ransom, according to Prime Minister Datuk Seri Anwar Ibrahim. He disclosed the incident on March 25, 2025, in a speech marking the 218th Police Day in Kuala Lumpur, and said the intrusion had taken place a day or two before he spoke.

Anwar said the government would not pay the ransom and would not surrender to pressure from the attackers. He said he did not hesitate to reject the demand once he was informed of it. The prime minister did not say what the attackers were seeking beyond the payment, nor did he identify those responsible for the intrusion.

The disclosure came at a gathering of the country's security and communications leadership. Those present included Home Minister Datuk Seri Saifuddin Nasution Ismail, Inspector-General of Police Tan Sri Razarudin Husain, Deputy Inspector-General of Police Datuk Seri Ayob Khan Mydin Pitchay, Communications Minister Datuk Fahmi Fadzil and Chief Secretary to the Government Tan Sri Shamsul Azri Abu Bakar.

A ransom demand against the national airport operator

MAHB is the listed company that operates airports in Malaysia, so an intrusion that reaches its systems touches aviation infrastructure rather than a single office network. Attacks that pair a break-in with a ransom demand usually involve intruders who either lock up data or copy it, then ask for payment in exchange for restoring access or for a promise not to publish what was taken.

KUALA LUMPUR: Malaysia Airports Holdings Bhd (MAHB) was recently hit by a cyberattack, with hackers demanding a US$10 million ransom, Datuk Seri Anwar Ibrahim said.

Aviation is among the sectors most closely watched for cyber risk because airports run on connected systems for passenger processing, baggage handling, scheduling and security screening. Malaysia groups services of that kind under the national critical information infrastructure category, the label used for assets whose disruption would affect essential services. That is why an intrusion at an airport operator is treated as a national issue rather than a purely corporate one.

  • MAHB was hit by a cyberattack, according to the prime minister
  • Hackers demanded a US$10 million ransom
  • The government refused to pay
  • The incident was disclosed at the 218th Police Day event

Why the government refused to pay

The refusal is consistent with the position taken by many governments, which generally discourage payment on the grounds that it funds further attacks and offers no guarantee that stolen data will be returned or deleted. Anwar framed the decision as a question of national resolve, saying the country could not be safe if its leadership and systems allowed it to submit to such demands. He said the government would work with the relevant agencies to resolve problems of this kind.

There is no way this country can be safe if its leadership and system allow us to submit to the ultimatums of criminals, betrayals, or foreign threats, he said.

The speech left several questions open. Anwar did not state what the attackers wanted beyond the ransom, and he did not name the group or individuals behind the intrusion. He also did not say which parts of MAHB's systems were affected. For an operator of national airports, that uncertainty is itself a concern, because it leaves open whether the incident reached operational technology, corporate information systems or both.

Funding and technical capacity

Anwar said the government would need to spend more on technology and to channel more money to the agencies that respond to incidents of this kind. He named the police and Bank Negara Malaysia as institutions that require stronger technical capacity. The point is that responding to intrusions is no longer only a matter of officers and equipment on the ground but of systems, specialists and the funding that keeps them in place.

  • More investment in technology for response agencies
  • Additional funding for the police
  • Additional funding for Bank Negara Malaysia
  • Coordination with the relevant agencies

For agencies of that kind, technical capacity usually means a security operations centre that runs around the clock, threat intelligence, incident response teams and the ability to trace an intrusion across networks. Bank Negara Malaysia supervises the financial system and sets expectations for how banks manage technology risk, so its own capability feeds into the rules the financial sector has to follow.

What it means for Malaysia's cloud and data centre market

A ransom demand against the national airport operator, disclosed at the top of government, pushes cyber resilience further up the agenda for every organisation that holds critical data. For cloud and data centre operators the practical effect is demand for segmented networks, encryption, logging and monitoring, and for the staff able to run them. Buyers ask providers to show how workloads are isolated and how incidents are detected, not only how much power and space a facility can supply.

The case also underlines that the reputational cost of an incident is now weighed alongside the technical one. A company that loses control of its systems faces questions from regulators, customers and the public, and the answers increasingly depend on evidence gathered before an attack rather than after it. That favours providers able to demonstrate disciplined operations and clear reporting lines.

For Malaysia's cloud and data centre market, the disclosure reinforces a pattern in which security is treated as a national capability rather than a line item. Demand tends to follow for managed detection, backup and recovery services, and for infrastructure that keeps critical workloads inside the country. Operators that can document their controls and their incident response will find that conversations with enterprise buyers start from a different place.

Source: New Straits Times