Ransomware victim disclosure
← All victimsPLUS Malaysia Berhad
Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Malaysia
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 6, 2026
About the victim
AI dossier — public-source company profilePLUS Malaysia Berhad is Malaysia's largest highway concessionaire, operating expressways across the north, central, and south regions of Peninsular Malaysia. The company provides toll road infrastructure, rest-and-recharge (R&R) facilities, traffic management services, and traveller products such as the PLUS App, PLUSMiles rewards, and PLUSTrack fleet management. It serves millions of road users across Peninsular Malaysia and operates an emergency helpline (PLUSLine) at 1-800-88-0000.
- Industry
- Highway Toll Road Operations & Expressway Management
- Address
- Peninsular Malaysia (headquarters not explicitly stated in available excerpt)
Attack summary
Severity: medium — The status is 'data_published', suggesting exfiltration has occurred, but the leak post content is entirely inaccessible (blocked by bot-check), no ransom amount is stated, no data size is given, and no specific data categories or proof files are confirmed. A national highway operator handling user PII and financial transaction data elevates this above low, but the absence of any verifiable evidence of regulated or sensitive data exposure prevents a higher rating.The group 'thegentlemen' has listed PLUS Malaysia Berhad under a 'data_published' disclosure status, implying data has been exfiltrated and released; however, the leak post itself is blocked by an anti-bot verification page and yields no specific claims about encryption, exfiltration scope, or data categories.
What the group claims
plus.com.my zoominfo.com/c/plus-malaysia-berhad/450191982 PLUS Malaysia Berhad provides a comprehensive travel experience through its expressways, offering facilities for relaxation and refreshment along the routes. The company enhances travel convenience with its PLUS App, which includes features like traffic updates, toll fare calculations, and a rewards program called PLUSMiles. Their services are designed for all road users in Peninsular Malaysia, ensuring smooth and safe journeys.
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
- Victim siteplus.com.my
- Leak posthttp://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

