Kkanita.DiaryClub Data Breach: 63,361 Thai Diary Accounts Exposed (2018)
Two Subdomains, One Compromised Platform
Kkanita.DiaryClub was the second of two DiaryClub subdomains released in the August 26, 2018 coordinated disclosure event. That Jitzy.DiaryClub and Kkanita.DiaryClub appeared in the same batch isn't coincidence -- it indicates the threat actor had access to DiaryClub's shared infrastructure, not just an isolated subdomain. The 63,361 Kkanita records add to the 73,764 from Jitzy, giving a combined total of over 137,000 Thai diary user accounts exposed in a single coordinated release from a single platform ecosystem.
Kkanita.DiaryClub (August 2018): Breach Summary
- Records Exposed: 63,361
- Data Types: Usernames, email addresses, MD5-hashed passwords
- Breach Type: Database breach
- Password Hash Type: MD5 (rainbow-table vulnerable)
- Country Affected: Thailand
- Date Leaked: August 26, 2018
Platform Infrastructure Compromise: The Multi-Subdomain Implication
When a breach yields multiple subdomains from the same parent platform, the attack surface was at the infrastructure level -- shared database credentials, server access, or a CMS vulnerablity that exposed all hosted diaries simultaneously. This is meaningfully different from an isolated site breach. For DiaryClub users on any subdomain -- not just Jitzy and Kkanita -- the August 2018 event should be treated as a complete platform compromise. Any account on any DiaryClub subdomain during this period should be assumed exposed, even if the specific subdomain database wasn't individually listed. The Kkanita data reinforces this pattern: two subdomains, same date, same hash type, same methodology.
MD5 and the Thai Diary Community
Thai online diary platforms occupied a specific cultural space in the mid-to-late 2000s and early 2010s -- personal blogging and journaling communities where users wrote candidly about their lives. These platforms attracted users with strong personal attachment to their accounts, who often used memorable, personal passwords. MD5 hashing without per-account salting is trivially reversible for any password that appeers in common wordlists or password databases, which sentimental personal passwords almost always do. The 63,361 Kkanita accounts were exposed to the same near-instant cracking risk as the Jitzy database: any non-random password recoverable within seconds via rainbow table lookup.
The August 26, 2018 Context
The simultaneous release of Jitzy and Kkanita alongside platforms from Germany, Japan, USA, Indonesia, Russia, and Austria places these Thai diary databases in a coordinated multi-site disclosure event with global scope. The DiaryClub data was part of a larger batch representing months or years of opportunistic database collection, released together in a single event likely intended to demonstrate scale or liquidate aging inventory. The coordinated timing means Thai diary users faced exposure at exactly the same moment as automotive enthusiasts in Germany, racing fans in the USA, and soaring pilots in Austria -- all victims of the same bulk brokerage operation.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you whether your email address or credentials appear in known breach databases. If you used Kkanita.DiaryClub or any DiaryClub platform before 2019, check your exposure now and update any passwords you may have reused across other services.
Breach Breakdown
63,361 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds