Malaysia’s Duopharma probes stolen data files after network intrusion

A listed Malaysian drugmaker says an intruder pulled data files from its network, triggering a forensic review and a regulator notification.

MedRisk Staff
By
1 Min Read

An unauthorized party reached the network of a major Malaysian drugmaker and walked away with data files that may include personal information.

Detection came from internal cyber-defence tooling, which triggered containment, Duopharma Biotech said in a filing with Bursa Malaysia. Daily operations carried on unaffected, and the core corporate network and internal operational systems stayed available.

A forensic review is now under way, with outside specialists expected to join an incident-response effort aimed at pinning down exactly which files were taken. A review of the company’s security posture, with new safeguards added as gaps surface, is also planned.

Duopharma said it currently sees no financial impact and will notify Malaysia’s Personal Data Protection Commissioner within the required period.

Duopharma makes and markets generics, biosimilars and insulin products and supplies public health programmes, which makes any data loss a supply-chain concern for regional health systems.

For life-sciences security teams, the case reinforces three priorities: segment manufacturing and corporate networks so one intrusion cannot spread, monitor data-egress paths, and rehearse regulator-notification timelines before an incident, not after.

Share This Article