
Railway Assets
Data Breach on March 20, 2025
| Data Breach Report | |||
|---|---|---|---|
| Victim | rac.gov.my | ||
| Threat Actor | Babuk | ||
| Date Discovered | Mar 20, 2025 | ||
| Description | The Railway Assets Corporation (RAC) is a federal statutory body under the Ministry of Transport. | ||
| Leak Size | 150GB |
Credential Exposure for rac.gov.my
We've indexed 13 @rac.gov.my accounts from external breaches, plus 18 credentials for rac.gov.my itself.
Last checked Aug 16, 2026
| @rac.gov.my addresses from external breaches | |
|---|---|
| Third-party breaches | 9 accounts · across 17 breaches · 9 with a plaintext password · most recent Dec 14, 2020 |
| Combo lists | 7 accounts · most recent Jul 26, 2026 |
| Passwords for rac.gov.my accounts | |
|---|---|
| Combo lists | 17 logins · most recent Aug 6, 2026 |
| Infostealer logs | 2 logins · 1 infected devices · most recent Jun 28, 2026 |
Logins may belong to customers or to staff, and the data doesn't say which. None of this is necessarily connected to the ransomware attack above.
Is your organization next?
Railway Assets was breached. Check if your company's credentials have been exposed in this or other data breaches.
Check your exposure →Continuous dark web monitoring alerts you when we find leaked credentials or session tokens for your company.