Ransomware victim disclosure
← All victimsMyIPO
listed as myipo.gov.my · Claimed by Payload · listed 13 hours ago
Status timeline
- ListedJun 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Payload
- Status
- Data leaked
- Country
- Malaysia
- Sector
- Public Sector
- Listed on leak site
- Jun 13, 2026
About the victim
AI dossier — public-source company profileMyIPO is the Malaysian government agency responsible for administering intellectual property protection services, including patents, copyrights, trademarks, geographical indications, industrial designs, and integrated circuit layouts. It serves creators, inventors, and businesses seeking to protect their IP rights.
- Industry
- Government – Intellectual Property Administration
Attack summary
Severity: high — MyIPO is a critical government agency handling sensitive intellectual property records and potentially personal data of inventors and businesses. A breach of this agency poses operational risk to the IP system and potential exposure of applicant information at scale.The Payload group claims to have compromised MyIPO and published data from the breach. The post does not explicitly state whether data was exfiltrated, encrypted, or both, nor does it specify the nature or scope of compromised data.
Data the group says was taken
AI dossier — extracted from the leak post- IP registration records
- Patent applications
- Trademark filings
- Copyright records
- Potentially applicant personal data
What the group claims
MyIPO provides a range of intellectual property services including patents, copyrights, trademarks, geographical indications, industrial designs, and integrated circuit layout designs. The organization aims to protect the rights of creators and innovators by offering exclusive rights for inventions and creative works. MyIPO serves a diverse clientele, including authors, inventors, and businesses seeking to safeguard their intellectual property.
Sources
Source
Indexed 13 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

