SHAH ALAM: The Selangor state government has suspended parking payments and enforcement after the Selangor Intelligent Parking (SIP) platform was taken offline in response to a cyberattack. Hackers targeted data transaction systems linked to the nationwide Flexi Parking network, disrupting parking payment services across 64 local authorities in the country. The attack took place within the 48 hours before the incident was reported, and payments and enforcement were halted for that period.
State local government and tourism committee chairman Datuk Ng Suee Lim said the system was taken offline immediately to protect the integrity of user data and to allow a forensic investigation and technical recovery to proceed. He said the shutdown was necessary so that investigators could work on the system and technical teams could carry out repairs.
The concessionaire Rantaian Mesra Sdn Bhd (RMSB) confirmed that enforcement officers have been instructed to stop issuing parking summonses. The instruction remains in force while the platform is offline.
What the shutdown covers
Flexi Parking has recently taken over the management of parking payments for several local authorities, including major Selangor councils such as Shah Alam, Subang Jaya and Selayang. That consolidation means one platform now sits behind the payment channels used by motorists in many different areas, so an intrusion into its data transaction systems reaches every council that depends on it.
- SIP taken offline after the attack
- Parking payments suspended
- Enforcement and summonses suspended
- Data transaction systems linked to Flexi Parking targeted
Disruption reported across 64 local authorities shows how far the effect travelled beyond the state that owns the platform. Selangor's decision to halt payments and enforcement rather than continue with a degraded service reflects the difficulty of collecting money through a channel whose integrity cannot be confirmed.
Why a payment platform is a target
Parking platforms hold more than payment records. They keep account details, vehicle numbers and location history, and they connect to banking channels and enforcement systems, which makes them valuable both for fraud and for disruption. An attack on the transaction layer is also harder to dismiss than a defaced website, because the platform is the point at which money changes hands.
The emergency shutdown of the Selangor Intelligent Parking (SIP) platform was triggered after hackers targeted data transaction systems linked to the nationwide Flexi Parking network, disrupting parking payment services across 64 local authorities throughout the country.
Ng denied that the breach originated with the SIP concessionaire, saying the attack was directed at the centralised Flexi Parking platform instead. That distinction matters for accountability, because the platform is shared infrastructure while the concessionaire runs the service on top of it. Establishing where the intrusion began is the first task of the forensic work now under way.
Recovery and service continuity
Ng said technical teams are working to restore secure payment services as quickly as possible. Forensic investigation and recovery usually run in parallel in cases of this kind: investigators preserve evidence and trace how the intruders entered, while engineers rebuild or clean affected systems and re-establish the connections to partner networks that the platform relies on.
We are working hard on repairs, but the public will face problems paying for parking over these few days, he told reporters.
- Forensic investigation into how the intruders entered
- Technical recovery of affected systems
- Restoration of secure payment channels
- Suspension of parking summonses during the outage
For motorists, the practical consequence is a stretch of days in which payment channels are unavailable and no summonses are issued. For local authorities, the interruption raises questions about how much of their revenue collection now depends on a single shared platform, and about what fallback arrangements exist when that platform cannot be used.
The incident also draws attention to the contracts behind shared municipal services. When one concessionaire and one platform serve dozens of councils, the security posture of that arrangement becomes a matter for every council involved, and the terms of the contract determine how quickly information is shared and how recovery is funded.
What it means for Malaysia's cloud and data centre market
The Selangor case is a reminder that the digitalisation of public services moves data and payments into environments that need the same controls as any enterprise system. Municipal platforms increasingly run on hosted infrastructure and connect to payment gateways, so the security of the hosting environment, the segregation between tenants and the logging that supports investigation all become part of the service that councils are buying.
For providers in Malaysia, incidents of this kind tend to shift buying criteria towards resilience that can be demonstrated: tested backups, clear incident response procedures and the ability to isolate an affected component without taking an entire service offline. Operators that can show how they would contain an intrusion, and how quickly they would restore service, are better placed when public sector buyers review their arrangements.
Source: The Vibes



