Malaysian authorities have arrested 12 individuals, including six immigration officers, in connection with a hack into the Immigration Department’s MyIMMs work pass system. This breach allowed unauthorized approval of work passes, raising serious concerns about the integrity of Malaysia's immigration controls. In response, the Immigration Department has announced it will revoke all work passes that were fraudulently issued via this exploit.
MyIMMs is an electronic system used by Malaysia's Immigration Department to manage and approve work permits for foreign workers. The system is crucial for regulating legal employment and tracking foreign nationals working in the country. The recent security breach compromised this process, enabling fake or unauthorized work passes to be generated.
Investigations revealed collusion between external hackers and certain immigration officers who exploited system vulnerabilities to approve work passes illegally. These fraudulent passes affect various employers who might unknowingly be hiring unverified foreign staff, potentially impacting labor standards and public security.
The government's crackdown intends to restore trust in the immigration system by removing all invalid work permits and punishing those involved in the scheme. The arrested officers face disciplinary actions and possible legal charges, while further forensic analysis of the system’s security is underway. The Immigration Department has urged employers to verify the legitimacy of their foreign workers' permits amid the revocation process.
This incident highlights vulnerabilities in Malaysia’s digital immigration infrastructure and the risks posed by internal corruption. Strengthening cybersecurity and ensuring transparency remain critical priorities as authorities work to prevent similar breaches. Public updates and tighter controls are expected in the coming weeks to safeguard the integrity of the work pass issuance system.