Breach Intelligence

6,875

Total breached databases

Sometime before 2022, the website of codehost.id allegedly suffered a data breach. Reports suggest the exposed data originated from a WordPress site database backup. It has been reported that a small number of records were exposed, including email addresses, usernames, and hashed passwords.
  • Date: 2022
  • Domain: codehost.id
  • Country: Indonesia
  • Category: Technology
  • Data: Email Addresses Passwords Usernames
  • Records: 22
  • Lines: 5,593
  • Size: 13.4 MB
  • Passwords: WordPress
  • Cracked: 0%
Sometime before 2022, the Indonesian government system at ciptakarya.pu.go.id allegedly suffered a data breach. The system belongs to the Directorate General of Human Settlements (Cipta Karya) of Indonesia's Ministry of Public Works and hosts the national solid-waste management information system (SIM Persampahan). Reports suggest approximately 49,000 records were exposed, including email addresses, usernames, MD5-hashed passwords, names, phone numbers, IP addresses, and geographic location data for waste-management facilities.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Company Information
  • Records: 48,832
  • Lines: 140,921
  • Size: 20.76 MB
  • Passwords: MD5
  • Cracked: 0%
Sometime in or before 2022, messapp.id allegedly suffered a data breach. messapp.id is an Indonesian messaging gateway platform providing WhatsApp and Telegram business-messaging APIs. Reports suggest the exposed data spanned roughly 31,000 distinct individuals captured across an incoming-message log, including phone numbers, contact names, email addresses, and message contents.
  • Data: Email Addresses Names Phone Numbers Messages
  • Records: 893,683
  • Lines: 903,226
  • Size: 420.78 MB
  • Passwords: ?
Sometime before 2023, Breezelabs.id allegedly suffered a data breach. Breezelabs.id is an Indonesian web and software development agency, and the exposed data is a consolidated database covering several applications it built, including a youth football club management platform, an alumni marketplace, and other community systems. Reports suggest approximately 15,000 individuals were affected. The exposed data allegedly included email addresses, names, usernames, Indonesian national ID numbers, phone numbers, geographic locations, places of birth, birthdates, genders, and passwords stored as bcrypt, argon2id, and PHPass hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Genders Site Activity Websites Birthdates Places of Birth
  • Records: 16,948
  • Lines: 1,242,054
  • Size: 317.18 MB
  • Passwords: BCrypt, Hashed, PHPass
  • Cracked: 0%
In July 2022, Botnix (botnix.net) allegedly suffered a data breach. Botnix is an Indonesian VPN and VPS/hosting provider that ran its customer billing on a WHMCS platform. It has been reported that the exposed database contained approximately 1,500 customer records. The compromised data allegedly included email addresses, names, usernames, physical addresses, phone numbers, IP addresses, and passwords stored as bcrypt and phpass hashes.
  • Date: Jul 18, 2022
  • Domain: botnix.net
  • Country: Indonesia
  • Category: Technology
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Websites Company Information Languages
  • Records: 27,817
  • Lines: 1,198,209
  • Size: 265 MB
  • Passwords: BCrypt, PHPass
  • Cracked: 0%
In February 2023, a SQL database belonging to Badan Pusat Statistik (Statistics Indonesia, bps.go.id) was allegedly leaked. Reports suggest the dump originated from a regional office's internal staff attendance system and exposed records for approximately 100 employees. The compromised data was limited to employees' names alongside internal employee identifiers and attendance logs.
  • Date: Feb 20, 2023
  • Domain: bps.go.id
  • Country: Indonesia
  • Category: Government
  • Data: Names
  • Records: 107
  • Lines: 257,418
  • Size: 60.27 MB
  • Passwords: ?
Sometime before 2022, Indonesian motorcycle performance-parts manufacturer and online store Bintang Racing Team (bintangracingteam.com) allegedly suffered a data breach. Reports suggest the database of approximately 16,000 customers and users was exposed, including email addresses, usernames, names, phone numbers, physical addresses, genders, and passwords stored as SHA-1 and MD5 hashes alongside a small number of plaintext administrator credentials.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders
  • Records: 16,212
  • Lines: 50,597
  • Size: 7.57 MB
  • Passwords: SHA-1, MD5, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.