What was actually taken on 9 March — and did it include radar?
CSM said minutes of crisis meetings and classified documents, some related to MH370. The working chart asks whether radar information or discussions of the turn-back were in that set. No public loot list answers it. A negative would also be a finding.
The coincidence is real: the intrusion sits on the same day the westbound primary was being played back and twelve hours before KL ARCC was told. Coincidence is not a contents list. FOIA, CSM forensic reporting, and any Annex 13 note on whether investigators’ working radar was compromised are the next records. Until then the steal is confirmed as an event and open as to payload.
Sources
- Working chart; CSM/Star 20 Aug 2014
Related
Investigation networks spear-phished the day after MH370 vanished
CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014
The radar story and the 9 March cyberattack
Working chart · tracks, delays, and a spear-phish of the investigation
West-track disclosure lag — ministerial 10:30, ARCC 22:30, Thai 9–10 days
8 March and 18–19 March 2014
BD764 and BE144 — named radar feeds, and a gap after 18:02:59 UTC
Secondary ends with the transponder · primary westbound · later points still to source
Why did SAR start in the wrong ocean for days?
Two waves of MH370-themed cyberattacks
9 March official-network intrusion · March–April public malware lures
MyCERT: MH370-themed backdoor and fake-transcript spear-phish
MA-381 · 24 March 2014 · MA-386 · 18 April 2014