On July 14, 2026, the Malaysian public library authority Perpustam.gov.my appeared on the leak site operated by the ransomware group ArcusMedia. The listing states that internal files were exfiltrated during a ransomware attack and sets a public deadline of July 21, 2026 for the organisation to negotiate or face full publication of the stolen data. The leak-site entry does not specify the number of records involved or list exact file types, only that sensitive internal documents were taken.
Watch Perpustam
Get alerted the next time Perpustam files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Perpustam’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Primary Listing
The ArcusMedia leak page, accessible via the onion address indexed by ransomware.live, states that Perpustam — the Malacca Public Library Corporation — was compromised through a ransomware deployment. It explicitly notes that data was successfully exfiltrated before encryption and warns that samples or the full archive will be released if the deadline passes without resolution. No victim count is provided, and the disclosure does not describe the initial access vector or the precise systems affected. Public trackers show this is the group’s standard publication format: a countdown timer followed by incremental data dumps when victims refuse to pay.
Why This Matters for You and Your Family
Even though Perpustam is a government library body, millions of ordinary Malaysians have used its services over the years. Library membership records, inter-library loan requests, event registrations, and staff contact lists frequently contain full names, home addresses, phone numbers, email addresses, and national identification numbers. If those records are among the exfiltrated files, your personal information could be exposed without your knowledge. Children’s library cards, school-group registrations, and family reading-programme sign-ups are often stored in the same systems, creating long-term privacy risks for every member of the household.
The breach is another reminder that institutions holding everyday civic data are attractive targets. Once files leave the organisation’s control, they can circulate indefinitely on dark-web forums, resale markets, and extortion groups.