Ransomware victim disclosure
← All victimsKedah State Government
listed as Kedah · Claimed by Nova · listed 7 hours ago
Status timeline
- ListedJun 16, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe Kedah State Government operates an official corporate portal providing information and services to citizens, businesses, and tourists. The portal facilitates online transactions, customer satisfaction surveys, government policy updates, and maintains dedicated sections for tourism, education, and corporate financing.
- Industry
- Government Administration
Attack summary
Severity: high — Confirmed exfiltration from a government entity with access to citizen PII, business data, and official government records. State-level government data exposure poses significant regulatory and public safety concerns.Nova claims to have exfiltrated data from the Kedah State Government portal. The group states it can provide samples from stolen data upon contact.
Data the group says was taken
AI dossier — extracted from the leak post- Government records
- Citizen personal information
- Business transaction data
- Survey responses
- Policy documentation
What the group claims
The Kedah State Government operates an official corporate portal that provides information and services to the public, businesses, and tourists. It offers various services including online transactions, customer satisfaction surveys, and updates on government policies. The portal also features sections dedicated to tourism, education, and corporate financing, aiming to enhance the quality of life for residents and visitors. Its intended clients include citizens of Kedah, local businesses, and tourists seeking information about the state - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 7 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

