Flexi Parking Hit By Cyberattack, Disrupting Parking Payments Across Local Councils Nationwide

Low Boon Shen
2 Min Read

Just recently Malaysia was hit with high-profile cyberattack incidents, now there’s another one that gets even more disruptive. The Flexi Parking platform is the latest victim, and that meant motorists across the country couldn’t pay for street parking; according to cybersecurity firm Gotchaa Lab, this all started last weekend in which two “preventable” bugs allowed hackers to break into the system.

Flexi Parking Breached, Parking Payments Currently Inoperative

Flexi Parking Hit By Cyberattack, Disrupting Parking Payments Across Local Authorities Nationwide
Selangor authorities have informed the public of the service disruption of its Smart Selangor Parking app, which relies on Flexi Parking’s systems. Image: Smart Selangor

Earlier today, Selangor exco Datuk Ng Suee Lim confirmed the incident was not isolated to Selangor but affected all 64 local authorities currently using the Flexi Parking platform nationwide. Specifically, the breach “targeted the centralized Flexi Parking platform, which recently took over the network to manage parking, including major Selangor cities and municipalities like Shah Alam, Subang Jaya and Selayang,” he said. Due to this, enforcement of parking summons has been paused for the time being.

Meanwhile, Gotchaa Lab’s blog pointed the breach to a threat actor identifying itself as “MelayuSpiritual.” According to its findings, the group claimed to have obtained root access to the Flexi Parking server and gained entry into a database reportedly containing around 7 million user records. Perhaps more damning is the attack vector, as it involved two vulnerabilities involving SQL injection and unauthenticated file uploads, both of which are common and easily preventable exploits.

Flexi Parking’s operator Suasa Efektif has said that restoration work is ongoing; in the meantime, motorists across the country are urged to make use of the alternative payment options recommended by their respective local councils. For now, authorities have not yet confirmed whether user data has been breached or whether formal investigations have been initiated.

Sources: The Star | Soyacincau

Pokdepinion: As the saying goes – rookie mistake. This kind of breaches shouldn’t happen to begin with.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *