Breach Intelligence

6,875

Total breached databases

Sometime in or before 2024, Universitas Cokroaminoto Yogyakarta (ucy.ac.id), an Indonesian private university, allegedly suffered a data breach that was later published on a hacking forum. Reports suggest the exposed data was extracted from the site's database and includes a small set of records — approximately 10 individuals — containing email addresses, names, phone numbers, plaintext passwords, government-issued identification numbers, and other geographic and site-activity details. The breach was attributed to a group operating under the name V For Vendetta Cyber Team.
  • Date: 2024
  • Domain: ucy.ac.id
  • Threat Actor: V For Vendetta Cyber Team
  • Country: Indonesia
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Site Activity
  • Records: 8
  • Lines: 168
  • Size: 29.66 KB
  • Passwords: Plaintext
Sometime before 2025, WiFi.my.id, an Indonesian WiFi internet service and billing platform, allegedly suffered a data breach. Reports suggest a customer database was exposed and subsequently shared on a hacking forum. It has been reported that approximately 25 individuals were affected, with the exposed data including names, email addresses, phone numbers, postal addresses, account balances, genders, BCrypt-hashed passwords, and their plaintext equivalents.
  • Date: 2025
  • Domain: wifi.my.id
  • Country: Indonesia
  • Category: Telecommunications
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Financial Information Balances Genders Site Activity
  • Records: 26
  • Lines: 27
  • Size: 8.46 KB
  • Passwords: BCrypt, Plaintext
Sometime around 2017, the ACCP 2017 conference subdomain of the Faculty of Pharmacy at Universitas Airlangga (accp2017.ff.unair.ac.id) in Indonesia allegedly had a small amount of data exposed. Reports suggest the exposed data was limited to a single email address.
  • Data: Email Addresses
  • Records: 1
  • Lines: 300
  • Size: 5.27 KB
  • Passwords: No
In 2026, a database belonging to the Institut Pemerintahan Dalam Negeri (IPDN, ipdn.ac.id), an Indonesian government institute under the Ministry of Home Affairs, was allegedly leaked. It has been reported that the data originated from two of the institute's web platforms (a WordPress site and a custom content-management system). The exposed data includes a small set of staff administrator accounts with MD5-hashed passwords, an administrative activity log of usernames and IP addresses, and website commenter records containing names, email addresses and IP addresses. In total the data of roughly 190 individuals was affected.
  • Date: 2026
  • Domain: ipdn.ac.id
  • Country: Indonesia
  • Category: Education
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses Site Activity Websites Job Information
  • Records: 4,145
  • Lines: 4,157
  • Size: 829.88 KB
  • Passwords: MD5
  • Cracked: 0%
In 2026, a dataset belonging to Politeknik Kesehatan Solo (poltekkes-solo.ac.id), an Indonesian health polytechnic, was allegedly leaked. It has been reported that the data originated from a community-service (KKN) program participant export. Reports suggest approximately 4,700 student records were exposed, including full names, genders, faculty and study-program details, postal addresses, and phone numbers. No passwords were included in the exposed data.
  • Data: Names Phone Numbers Geographic Locations Genders Personal Information
  • Records: 4,691
  • Lines: 1,144
  • Size: 341.04 KB
  • Passwords: No
Sometime around 2026, RupaRupa (ruparupa.com), an Indonesian online retailer of home, furniture, appliance and lifestyle products, allegedly suffered a data breach. It has been reported that a set of registered customer records was leaked; while the seller claimed around 1.1 million records, the circulated dataset contains roughly 12,000 customers (about 7,000 with email addresses). The exposed data allegedly included names, email addresses, phone numbers, dates of birth, and genders. No passwords were included.
  • Date: 2026
  • Domain: ruparupa.com
  • Threat Actor: LionDataMarket
  • Country: Indonesia
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Genders Birthdates
  • Records: 11,963
  • Lines: 11,963
  • Size: 777.95 KB
  • Passwords: No
In 2025, internal personnel data of the Indonesian National Police (POLRI, polri.go.id) was allegedly leaked and distributed for free on hacking forums. Reports suggest the dataset was published by a threat actor using the handle MR-Zeeone-Grayhat. It has been reported that approximately 172,000 personnel records were exposed, including full names, ranks, unit and assignment details, phone numbers, and some email addresses. No passwords were included in the data.
  • Date: 2025
  • Domain: polri.go.id
  • Threat Actor: MR-Zeeone-Grayhat
  • Country: Indonesia
  • Category: Law Enforcement
  • Data: Email Addresses Names Phone Numbers Geographic Locations Job Information Law Enforcement Structure
  • Records: 172,627
  • Lines: 1,208,390
  • Size: 31.78 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.