Malaysian Nuclear Agency Data Breach

Alleged

Ransomware claim involving Malaysian Nuclear Agency

Published: Jul 30, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Malaysian Nuclear Agency
Industry
Business Services
Threat Actor
The Gentlemen
Date of Incident
Jul 30, 2026

Executive Summary

The Malaysian Nuclear Agency, Malaysia’s national nuclear research and regulatory body, was targeted by the ransomware group The Gentlemen. The listing appeared on the group’s dark web portal on July 30, 2026, and was detected by SOCRadar’s Dark Web Monitoring. This incident represents a notable claim by the group, as it targeted a high-sensitivity public-sector organization, which is often a coveted target for ransomware operators. The agency’s role as a government and defense entity makes it a significant victim within the public sector. In the 60 days preceding this listing, The Gentlemen claimed approximately 175 victims, positioning them as one of the more active ransomware operations. Their typical targets are in the Manufacturing, Business Services, and Healthcare sectors, primarily located in the United States, India, and France. While a government agency falls outside their usual commercial focus, this targeting aligns with a discernible pattern involving Malaysian entities and public sector organizations. Previous victims exhibiting similar characteristics include The Garfield County Sheriff Office, Quanterm Logistics Sdn Bhd, SGS Malaysia, and Angel Hotel.

Technical Analysis

The surfaced stealer-log telemetry indicates a significant exposure for nuclearmalaysia[.]gov[.]my, with twenty-six records found within the queried sample. These records include nine employee credentials specifically related to the agency’s internal infrastructure, such as its organizational mail system, an internal client portal, an SSDL application, an HR/attendance system, and an Oracle Cloud tenant. Additionally, five records are for external-user credentials on organizational URLs, and another five are corporate credentials for third-party research and academic services. The exposure points predominantly to corporate intrusion risks. The timestamps on these logs, spanning July 26 to July 29, 2026, place them just days before the ransomware group’s listing. One employee account was found across more than a dozen internal and third-party systems, suggesting a potentially compromised workstation or extensive credential reuse by the individual. Infostealer-harvested credentials are a known pathway for groups like The Gentlemen to gain organizational access. Threat actors or access brokers typically acquire these logs, validate the corporate credentials, and then leverage them to access systems such as Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. While this stealer-log evidence does not definitively confirm that The Gentlemen used these specific credentials, the direct exposure of email and cloud-tenant access on government infrastructure days before a leak-site listing is a strong indicator of the type of access this threat category exploits. Given the evidence of credential exposure immediately preceding the ransomware listing, immediate actions are recommended. This includes resetting passwords for all affected accounts, revoking active sessions and tokens associated with them, and conducting a forensic review of mail and Oracle Cloud access logs. Continued monitoring of dark web and stealer-log feeds for the organization is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.