Friday 02 Oct 2026
main news image

This article first appeared in The Edge Malaysia Weekly on May 5, 2025 - May 11, 2025

WITHIN three minutes of the market opening at Bursa Malaysia on March 11, more than RM0.5 million worth of Hang Seng Index put warrants — HSI-PWD4 and HSI-PWDU — were purchased through an online trading account belonging to “Datuk Z”.

The problem is, he did not execute the orders. Instead, his corporate online trading account is believed to have been hacked by an unknown party or parties, who then executed purchases of structured warrants that are subject to high time decay at prices several times the closing price of the previous trading day.

By the time he noticed the transactions after getting his account statement the following day, it was all too late. He was already in possession of the put warrants that had been bought at such high prices, and he would not be able to sell them and would have to bear the huge losses.

To make matters worse, the brokerage house demanded that Datuk Z fulfil the payments for the warrants as they had been bought using margin accounts, or buying securities using leverage provided by the brokerage. He alerted Bursa Malaysia about the incidents, but his complaints did not get the attention he had hoped for.

“So, on that day itself, I tried to contact, using my network, each of the broker houses [of the sellers’ accounts]. I asked them to please check this deal, this transaction — they are withdrawing the money the next day. When you sell a share, T+2, you withdraw money. So, they’re allowed to be withdrawn. So that means it’s a done deal,” says Datuk Z, who requested anonymity as the matter is being looked into by the police. A copy of the police report was sighted by The Edge.

He adds that he tried to get the brokerage and Bursa Malaysia to cancel the trades on the first day after the transaction, or T+1, but his pleas fell on deaf ears. “I think that is the attitude of each party, because it looks like I’m the one who made the wrong call,” he tells The Edge.

What is certain at this point is that Datuk Z’s case of hackers gaining access to his online trading account and making unauthorised transactions looks like an isolated event (see box story for more details), unlike the hacking that took place on April 24, when many accounts were said to be compromised. It is not clear whether the two incidents are linked.

Datuk Z’s case happened more than a month before the unauthorised transactions on Bina Puri Holdings Bhd’s (KL:BPURI) shares and Warrant B securities, which were said to involve around 70 accounts on April 24. In that incident, preliminary estimates put the losses in the high teens of millions of ringgit.

“During the incident last week (on April 24), there were about 80 accounts affected, which amount to less than 0.01% of total online trading accounts,” according to a source close to Bursa Malaysia. 

How could the hacks happen?

Cybersecurity experts point to tell-tale signs

As the forensic investigations into the April 24 incident is ongoing, the sequence of events leading up to it may provide some indication of what happened, according to the cybersecurity experts contacted by The Edge.

A white hat hacker, who declines to be named due to the nature of the subject matter, notes an incident of mass leakage or illegal sale of credentials this year. “There is suspicion that this [trading platform hack] may be related to that, but we will leave it to the investigation,” he adds.

White hat hackers are described as ethical cybersecurity professionals who help organisations improve the integrity of their systems and networks, as opposed to black hat hackers who are driven by self-interest and malicious intent.

Zooming in on the perpetrators, the team involved must not only be familiar with hacking processes, but also have an in-depth understanding of trading operations and processes such as the fund clearance period, links between brokerages and trading system operators, and surveillance alert thresholds, the white hat hacker explains. Investigators may pinpoint the IP addresses involved in the transactions and the timing of the placements of orders to spot trends that could help track the perpetrators.

“If I were the investigator, I would also identify the accounts that profited from those trades, namely the sellers [who managed to sell at abnormally high prices],” he says, adding that it remains to be seen whether the perpetrators are linked to the hacked trading of Japanese securities involving more than US$700 million since February this year.

Unlike banks, operators and vendors of trading platforms are not subject to the Risk Management in Technology guidelines of Bank Negara Malaysia, which requires, for example, multi-factor authentication (MFA) such as a one-time password (OTP), says a cybersecurity expert.

“There is less regulatory scrutiny on these players. Therefore, it opens up opportunities [for such hacking incidents]. While many point out that additional layers of security input would slow down time-sensitive trading actions, we have seen more mature markets having those mechanisms in place,” says the expert.

Another cybersecurity professional involved in “red teaming”, or simulation of real-life cyberattacks, says that while there are multiple points for a potential breach, the hackers’ end-goal is to control trading accounts en masse for profit. As such, they may go for “the easiest way to compromise” an entire group of trading accounts such as through third-party vendors or data holders, rather than spending time cracking individual accounts at the onset.

The attack would have required an extended period of preparation as the hackers “would have needed to sift through accounts” to identify those with funds, says the cybersecurity professional. “This was definitely not done by hacktivists. My suspicion is that it [was done by] organised crime.”

Since the attack occurred, brokers and trading platforms have encouraged users to change their login credentials. However, he says, “Changing the password doesn’t completely stop the hackers from repeating the attack and perpetrating further [as the threat will remain within the system if nothing is done].”

Those affected will have to patch the loopholes and heighten system monitoring to ensure the threat is neutralised and all entry points are closed. “If [the system operators] don’t do anything beyond changing passwords, the same attack can happen again,” he points out.

Vincent Lau, head of equity sales at Rakuten Trade, agrees that having added security measures such as MFA and biometric authentication will be sufficient to reduce the risk of cyberattacks on online trading platforms. However, there should be a balance between ease of user experience and security measures, he adds.

The hacking episode requires the industry to learn about improving its practices and systems in use, says the first cybersecurity expert. For that purpose, transparency in post-incident reporting will go a long way, the expert adds.

More importantly, many successful breaches came about due to lapses along the value chain, including non-technology controls.

“Above all technologies and processes, humans are always the weakest link,” quips an analyst at a cybersecurity agency. “Unless everyone wakes up and invests in cybersecurity, and improves regulations and the enforcement of those regulations, many of these issues will persist.”

The Association of Stockbroking Companies Malaysia (ASCM) tells The Edge that following the April 24 incident of unauthorised trades, ASCM and its member firms immediately implemented enhanced security measures. These included mandatory password resets, strengthening security protocols such as blocking high-risk IPs, and thorough reviews of internal systems.

“The industry recognises the need for continuous improvements and actively explores wider adoption of MFA alongside strong password practices. Bursa Malaysia continues to engage and work closely with ASCM and the brokers on the matter. The capital market regulators have issued security system guidance and are closely monitoring the situation. Brokers are fully supportive and actively collaborating to enhance and strengthen access controls,” it adds.

The association assures investors that all necessary steps are being taken to further secure systems and accounts. It adds that the industry remains committed to enhancing cybersecurity and ensuring a safe trading environment for all investors.

Impact on market integrity

Despite Datuk Z’s efforts to have the capital market operator and authority look into his case to stop or void the transactions, his efforts were futile. That is because while the transactions look fishy, his online trading account was accessed in just one attempt.

For this reason, the brokerage firm and capital market operator did not stop the settlement of the transactions from going through, and for the selling accounts to withdraw the proceeds, he alleges.

For Datuk Z, who is a substantial shareholder of a few public-listed companies, he has connections with the brokerages. He was able to call the selling brokerage houses and also strike a deal with his own broker to settle the transactions over a period of time.

However, regular retail investors who also trade on leverage provided by the brokerage firms might have to settle the entire amount that was fraudulently purchased using their accounts’ leverage limits should such transactions occur.

If there are no proper standard operating procedures put in place by the authorities such as Bursa Malaysia when it comes to suspicious or fraudulent online trading account transactions, the capital market’s integrity could be eroded.

“First thing, when this happens, everyone [investors] will be afraid. [They would say] ‘Cancel my account, I’m not using it’. Who will suffer? Brokers, because all these while you prepare all the limits so that the investors or traders can buy shares any time … Then eventually Bursa will suffer, because the trading size will go down. And then who will suffer? The PLCs (public-listed companies). The shares of the company that goes for IPO (initial public offering) will suffer because there are no buyers in the market,” Datuk Z points out.

Rakuten Trade’s Lau says the number of accounts affected by unauthorised access and transactions on April 24 represents an extremely small percentage of the number of Central Depository System (CDS) accounts in Malaysia.

“[There will be] no impact on investors from trading. Market sentiment and valuation, prospects, will be the main deciding factor on whether investors will trade,” he says.

Nevertheless, a bigger concern is if such breaches are employed to liquidate the holdings of strategic shareholders, mount a hostile takeover or undertake manipulative acquisitions, especially in illiquid counters. Such actions would compromise not only individual investors but also the broader capital market ecosystem, says Datuk Z.

He alleges that his efforts to engage the broker, the police, the Malaysian Communications and Multimedia Commission (MCMC), Bursa Malaysia and the Securities Commission Malaysia have so far yielded no clear direction in nabbing those behind the March 11 trades, with him receiving only formal replies and no substantive assistance.

He questions why the brokers did not suspend accounts pending investigation or use the financial risk advisory system to trace irregular trading patterns. He also urges brokers, the police and regulators to streamline their collaboration in tracking the money trail, as the current protocol may take a long time to yield meaningful developments.

Meanwhile, with many questions being asked following the April 24 incident, Bursa Malaysia, in response to those posed to the exchange, says: “Bursa Malaysia is currently investigating the incident of unauthorised access and trade. To ensure the integrity of the investigation, we are unable to comment further at this point.”

As Malaysia seeks to cement its position in the digital economy, the issue of safety of its digital ecosystem is paramount. The latest string of deepfake scams and cyberattacks on online trading accounts, websites and other digital platforms serve as a reminder to the government and participants of the digital economy of the weaknesses in the ecosystem that need to be addressed urgently.

See also “The ugly side of AI strikes the heart of Corporate Malaysia” — Page 47

 

Save by subscribing to us for your print and/or digital copy.

P/S: The Edge is also available on Apple's App Store and Android's Google Play.

      Print
      Text Size
      Share