Railway Assets

Railway Assets

Data Breach on March 20, 2025
Data Breach Report
Victimrac.gov.my
Threat ActorBabuk
Date DiscoveredMar 20, 2025
DescriptionThe Railway Assets Corporation (RAC) is a federal statutory body under the Ministry of Transport.
Leak Size150GB

Credential Exposure for rac.gov.my

We've indexed 13 @rac.gov.my accounts from external breaches, plus 18 credentials for rac.gov.my itself.

Last checked Aug 16, 2026

@rac.gov.my addresses from external breaches
Third-party breaches9 accounts · across 17 breaches · 9 with a plaintext password · most recent Dec 14, 2020
Combo lists7 accounts · most recent Jul 26, 2026
Passwords for rac.gov.my accounts
Combo lists17 logins · most recent Aug 6, 2026
Infostealer logs2 logins · 1 infected devices · most recent Jun 28, 2026

Logins may belong to customers or to staff, and the data doesn't say which. None of this is necessarily connected to the ransomware attack above.

Is your organization next?

Railway Assets was breached. Check if your company's credentials have been exposed in this or other data breaches.

Check your exposure →

Continuous dark web monitoring alerts you when we find leaked credentials or session tokens for your company.