On August 10, 2024, 27,000 customers of Master Chris Leong, a Tit Tar practitioner in Malaysia, had their personal information listed in a public breach database after his website was compromised. The exposed records include names, physical addresses, dates of birth, phone numbers, email addresses, genders, nationalities, purchase history, and links to Facebook profiles. The practitioner has not issued a public statement or responded to inquiries about the incident.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details Confirmed in the Disclosure
The primary record on Have I Been Pwned states that the breach occurred on the Master Chris Leong website and affects 27K unique email addresses. It lists the specific data types exposed as dates of birth, email addresses, genders, names, nationalities, phone numbers, physical addresses, purchases, and social media profiles. The disclosure notes that the company did not respond when contacted for comment or confirmation. No ransom demand or attacker group is named, and the exact breach method remains unknown.
Why This Matters for You and Your Family
When a practitioner’s customer database is breached, the people affected are typically ordinary individuals who sought traditional medical or wellness services. Your name paired with a physical address, date of birth, and phone number creates a ready-made profile that can be used for identity theft, phishing calls, or targeted scams. If you or a family member visited Master Chris Leong, that combination of details is now loose on the internet and can be resold or combined with other leaks. The inclusion of Facebook profile links further lowers the barrier for attackers to locate your social media activity and build a more complete picture of your daily life.
Doxxing and Identity-Chain Risks
The presence of social media profiles alongside physical addresses and purchase history turns this breach into a starting point for doxxing chains. Attackers can link your real name and address to your Facebook account, then scan for family members, children’s names, or gaming usernames mentioned in posts. These connections often cascade: a leaked email leads to credential-stuffing attempts on gaming platforms, which in turn expose chat logs or voice recordings that reveal even more personal information. Once an identity chain is mapped, harassment, stalking, or financial fraud becomes significantly easier. Purchases data can also reveal health conditions or family circumstances that attackers exploit for social engineering.