Home / Telco / JPDP opens investigation over Khairul Aming data leak

JPDP opens investigation over Khairul Aming data leak


By Alyaa Najwa July 23, 2026

Khairul Aming has served a letter of demand (LOD) to Maxis following the leak of his account and phone bill details on social media, with the content creator saying his lawyers will be taking over the case until it is resolved

In a post on Threads, Khairul revealed that beyond the LOD, his team has lodged reports with several authorities. A police report has been filed at IPD Dang Wangi to open an investigation into the individual behind the leak, while separate reports have also gone to MCMC and to the personal data protection authorities over the breach itself.

According to Khairul, what was exposed went far beyond an overdue bill. He said his phone details, payment history and subscriptions were all made public, along with his IC number, which he claimed was enough for someone to access his MySara information as well. He described feeling both sad and scared over how easily his privacy could be taken away.

In case you missed it, the whole thing kicked off earlier this week when a now-deactivated Threads user began posting Khairul’s billing details, prompting him to call out the telco publicly. Maxis responded with a statement of its own, calling it an isolated incident involving an unauthorised action, confirming that it had identified the individual linked to the case, and apologising to the customer.

The government has since stepped in. The Personal Data Protection Department (Jabatan Perlindungan Data Peribadi, or JPDP) under the Ministry of Digital issued a media statement on 22 July confirming that it is treating the unauthorised disclosure of a Maxis customer’s account and phone bill details on social media as a serious matter, and that an investigation is underway.

“JPDP is conducting an investigation under the Personal Data Protection Principles and Section 130 of the Personal Data Protection Act 2010 [Act 709] in relation to the unlawful collection or disclosure of personal data. Appropriate enforcement action will be taken if the investigation finds non-compliance with Act 709,” – Jabatan Perlindungan Data Peribadi, in a media statement on Facebook

JPDP also used the statement to remind data controllers of their obligations, stressing that all seven Personal Data Protection Principles must be complied with, including making sure customer data is protected from unauthorised access and disclosure. The department added that data controllers should continue strengthening their technical and organisational security measures, and ensure that their data storage infrastructure and network systems are kept at an appropriate level of security.

Read more of our articles below!