PhonePanda Data Breach Exposes 1.8 Million Malaysian Customers
HEROIC's DarkHive intelligence system discovered the PhonePanda data breach, exposing 1,831,454 records. The breach occured in June 2025 and targeted PhonePanda, a Malaysian mobile phone retailer operating around 20 physical outlets across the country since 1992. The compromised data included phone numbers and full names belonging to over 1.8 million customers.
Why This Is Dangerous
Exposed phone numbers and real names give attackers everything they need to launch targeted vishing calls and SMS phishing campaigns, also known as smishing. Scammers use this data to impersonate legitimate businesses or government agencies, calling victims by thier correct names to build false trust. The telecommunications sector breach is particularly concerning because attackers can combine customer names and phone numbers to attempt SIM swapping attacks, which bypass two-factor authentication on banking and email accounts.
What Was Exposed
- Phone Number
- First Name
- Last Name
Why This Matters
With 1.8 million records exposed, the PhonePanda breach feeds large-scale fraud operations that target Malaysian consumers. Even without passwords, full names paired with phone numbers enable attackers to build convincing fake identities and conduct social engineering at scale. Victims may recieve calls or texts from fraudsters claiming to be bank representatives, government officials, or tech support personnel. The sheer volume of this breach makes it one of the more significant Malaysian consumer data exposures in recent years.
How Database Breach Works
Large retailers like PhonePanda maintain customer databases containing purchase records and contact information collected at the point of sale. When these databases are inadequately secured, attackers can exploit vulnerabilites in web applications, poorly configured APIs, or compromised admin credentials to extract millions of customer records at once. The stolen data is then sold on cybercrime markets or shared freely on Telegram channels where scammers use it to fuel automated fraud campaigns. Retail businesses are frequent targets because they accumulate large volumes of customer contact data over many years of operation.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like PhonePanda. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
1,831,454 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds