Breach Intelligence

6,871

Total breached databases

Sometime before 2025, SD Hati Kudus Rajawali Makassar (sdhatikudus.sch.id), an Indonesian Catholic primary school, allegedly suffered a data breach. Reports suggest the incident was carried out by a hacktivist group as part of a wider campaign against Indonesian institutions, and that a database extracted from the school's student information system was published on a hacking forum. It has been reported that approximately 300 records of teachers, staff, and students were exposed, including full names, phone numbers, physical addresses, genders, and birthdates.
  • Date: 2025
  • Domain: sdhatikudus.sch.id
  • Threat Actor: V FOR VENDETTA CYBER TEAM
  • Country: Indonesia
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Genders Job Information Birthdates Nationalities
  • Records: 298
  • Lines: 302
  • Size: 71.06 KB
  • Passwords: Plaintext
In 2025, a database from the Onno Center (onnocenter.or.id), an Indonesian non-profit foundation running a MediaWiki knowledge base for ICT education, was allegedly leaked on a hacking forum. Reports suggest the exposed `wiki_user` table covered roughly 7,000 accounts and included usernames, real names, email addresses, account registration and activity dates, and passwords stored as MediaWiki PBKDF2-SHA512/SHA256, legacy salted, and MD5 hashes.
  • Date: 2025
  • Domain: onnocenter.or.id
  • Threat Actor: N1KA
  • Country: Indonesia
  • Category: Education
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 14,315
  • Lines: 658,147
  • Size: 454.57 MB
  • Passwords: MD5, SHA-512 Salted, Unknown
Sometime before January 2026, a database of civil servants of the West Java Provincial Government (Pemerintah Provinsi Jawa Barat) was allegedly exposed. It has been reported that the data, sourced from the provincial employee information system (siap.jabarprov.go.id), was subsequently published on hacking forums. The incident allegedly affected approximately 37,000 individuals, with the compromised records including full names, national identity (KTP/NIK) and employee (NIP) numbers, places and dates of birth, home addresses, phone numbers, some email addresses, job titles, work units, religion, gender and marital status. No passwords were included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Relationship Statuses Genders Religions Job Information Company Information Birthdates Nationalities
  • Records: 37,351
  • Lines: 34,444
  • Size: 6.53 MB
  • Passwords: No
In June 2023, a customer order database belonging to UPrint.id (uprint.id) allegedly appeared on a hacking forum. UPrint.id is an Indonesian online printing service. Reports suggest the exposed data was a Magento order export containing approximately 4,400 orders from around 2,500 customers. The data comprised customer names, email addresses, phone numbers, billing and shipping addresses across Indonesia, company names and order/payment details. No passwords were included.
  • Date: Jun 2023
  • Domain: uprint.id
  • Country: Indonesia
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Order Information Site Activity Company Information
  • Records: 4,384
  • Lines: 11,756
  • Size: 3.62 MB
  • Passwords: No
Sometime before June 2025, the job-seeker registration portal of Bekasi Regency, Indonesia (bebunge.bekasikab.go.id), allegedly suffered a data breach. The portal is operated by the local government to register job seekers (pencari kerja). Reports suggest data for approximately 21,000 registrants was exposed. The exposed data was highly personal, including full names, Indonesian national ID numbers (NIK), email addresses, phone numbers, home addresses, dates and places of birth, gender, religion, marital status and education/employment details. The dataset did not contain passwords.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Marital Statuses Relationship Statuses Genders Religions Site Activity Job Information Company Information Birthdates Places of Birth Education
  • Records: 21,079
  • Lines: 14,410
  • Size: 3.7 MB
  • Passwords: No
In April 2023, an employee directory belonging to SIG (sig.id) allegedly appeared on a hacking forum. SIG (Semen Indonesia Group) is Indonesia's largest cement and building-materials producer. Reports suggest the exposed data contained approximately 4,900 employee records, comprising full names, corporate email addresses and job positions. No passwords were included.
  • Data: Email Addresses Names Geographic Locations Site Activity Job Information
  • Records: 4,884
  • Lines: 4,885
  • Size: 868.03 KB
  • Passwords: No
In October 2025, McDonald's Indonesia (mcdonalds.co.id) allegedly suffered a data breach, reportedly carried out by a threat actor known as "wikkid" through a vulnerable work-scheduler system. McDonald's Indonesia operates the Indonesian franchise of the American multinational fast-food chain. Reports suggest the breach exposed approximately 15,000 records across two files — a staff directory of around 14,700 employees and a list of 261 restaurants — including full names, dates of birth, hire and termination dates, phone numbers, home addresses, job titles, genders, pay rates, and restaurant manager names and locations. No passwords were included.
  • Date: Oct 2025
  • Domain: mcdonalds.co.id
  • Threat Actor: wikkid
  • Country: Indonesia
  • Category: Food
  • Data: Names Phone Numbers Geographic Locations Genders Job Information Company Information Birthdates Personal Information
  • Records: 14,945
  • Lines: 14,959
  • Size: 2.32 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.