Breach Intelligence

6,875

Total breached databases

In 2025, a membership database belonging to an association of Pertamina retirees allegedly appeared on a hacking forum. Pertamina is Indonesia's state-owned oil and gas company. Reports suggest that approximately 110 records relating to retired employees were exposed, including full names, home addresses, phone numbers, dates of birth, job titles and the names of family members. The data also contained a small number of administrator accounts with plaintext and MD5-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Family Members Site Activity Job Information Birthdates
  • Records: 111
  • Lines: 119
  • Size: 29.94 KB
  • Passwords: Plaintext, MD5
Sometime before February 2025, the website of Pengadilan Negeri Jayapura (pn-jayapura.go.id), a district court in Indonesia, allegedly suffered a data breach. Reports suggest a small number of records were exposed from the site's content management system, including an administrator account with a salted SHA-512 password hash and a few contact email addresses.
  • Data: Email Addresses Passwords Names Geographic Locations IP Addresses Site Activity
  • Records: 3
  • Lines: 300
  • Size: 72.83 KB
  • Passwords: SHA-512 Salted
  • Cracked: 0%
In 2025, the Mesuji Regency Government (mesujikab.go.id) in Lampung, Indonesia allegedly suffered a data breach of its web portal content-management system. Reports suggest approximately 50 administrative user accounts were exposed, including full names, national identity numbers (NIK/NIP), and passwords stored as bcrypt hashes alongside some plaintext values.
  • Date: 2025
  • Domain: mesujikab.go.id
  • Threat Actor: fkzsecxploit
  • Country: Indonesia
  • Category: Government
  • Data: Passwords Names Geographic Locations Government IDs
  • Records: 49
  • Lines: 53
  • Size: 14.39 KB
  • Passwords: BCrypt, Plaintext
In August 2026, a dataset allegedly associated with postel.go.id was listed for free on a hacking forum. postel.go.id is a domain of Indonesia's Directorate General of Post and Informatics Resources and Equipment (Ditjen SDPPI), the telecommunications and postal regulator under the Ministry of Communication. The post claimed approximately 16,000 records, but the data reportedly resolved to around 1,600 valid entries, including roughly 230 email addresses (largely Indonesian government contact addresses) and about 1,600 Indonesian phone numbers; a large share of the listed rows contained apparently fabricated identifiers.
  • Date: Aug 25, 2026
  • Domain: postel.go.id
  • Country: Indonesia
  • Category: Government
  • Data: Email Addresses Phone Numbers Geographic Locations
  • Records: 1,611
  • Lines: 16,738
  • Size: 325.25 KB
  • Passwords: No
In May 2026, the Gowa Regency Government (goakab.go.id) in South Sulawesi, Indonesia, allegedly suffered a data breach exposing data on its regional civil servants (PNS/ASN). It has been reported that the leak contained records for approximately 90 individuals, including full names, government identification numbers (NIP/NIK), work-unit and job information, and ages, with a subset also exposing phone numbers, email addresses, physical and geographic locations, birthdates, genders, religions, and health information such as blood type. No passwords were included.
  • Date: May 15, 2026
  • Domain: goakab.go.id
  • Country: Indonesia
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Health Information Genders Religions Job Information Birthdates Ages
  • Records: 90
  • Lines: 1,201
  • Size: 57.66 KB
  • Passwords: No
In June 2025, the JDIH portal of the North Sulawesi Provincial Government (jdih.sulutprov.go.id) allegedly suffered a data breach. The site is the official Legal Documentation and Information Network (JDIH) portal of Indonesia's North Sulawesi Province, publishing regional regulations and legal documents. It has been reported that the incident was carried out by a hacktivist group as a form of protest, and that the exposed database included an administrator account comprising a username, a full name, and an MD5-hashed password.
  • Date: Jun 2025
  • Domain: jdih.sulutprov.go.id
  • Threat Actor: V FOR VENDETTA CYBER TEAM
  • Country: Indonesia
  • Category: Government
  • Data: Passwords Names Usernames
  • Records: 1
  • Lines: 175,270
  • Size: 4.26 MB
  • Passwords: MD5
  • Cracked: 0%
In 2026, ppid.kemendagri.go.id, an information-disclosure portal of Indonesia's Ministry of Home Affairs (Kemendagri), allegedly exposed government documents. Reports suggest the leaked files contained the personal data of roughly 150 individuals, including full names, NIK national identity numbers, and detailed home addresses of civilians, alongside names, civil-service (NIP) numbers, and job positions of government employees and auditors.
  • Data: Names Physical Locations Geographic Locations Government IDs Site Activity Job Information
  • Records: 147
  • Lines: 535
  • Size: 132.54 KB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.