Sabah.gov.my Leak Puts 1,630 Government Emails at Risk Online
HEROIC analysts found a combolist built from email addresses on the sabah.gov.my domain, the domain used by Malaysia's Sabah state government, uploaded to a Telegram channel on June 10, 2026. The file contains 1,630 records pairing email addresses with plaintext passwords and the URLs each login was used on. Why This Is Dangerous: Government email addresses often serve as gateways to internal systems, official communications, and other accounts tied to public sector work. A working email and password pair tied to a government domain gives an attacker a credible foothold, not just an ordinary account. What Was Exposed: Each of the 1,630 records in this file includes the same three fields. - Email addresses on the sabah.gov.my domain - Plaintext passwords - URLs showing where each credential was used Why This Matters: If any of these government email addresses reused their password on personal accounts, or if the exposed password still works on internal systems, the risk goes beyond a single inbox. Attackers can use credentials like these for phishing, account takeover, or as a stepping stone into more sensitive systems. How a Combolist Like This Works: Lists like this are usually created by filtering larger breach or stealer log collections for entries matching a specific domain, a technique attackers use to build targeted lists against a particular organization or government body. That narrow focus makes the data more useful to anyone planning a targeted attack rather than a random one. Check If You Are Affected: Use HEROIC's free breach scanner, which checks against more than 400 billion leaked records, to see if your sabah.gov.my address or any other email appears in this or another breach.
Breach Breakdown
1,630 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds