ScienceAsia Data Breach: 18,252 Academic Records Exposed (2018)
When Thailand's Royal Scientific Society Lost Its Database
ScienceAsia is the official journel of the Science Society of Thailand, published under royal patronage and in collaboration with the National Research Council of Thailand. It's a peer-reviewed, multidisciplinary scientific publication -- exactly the kind of acedemic platform that doesn't expect to appear in an underground forum combolist. In August 2018, its database of 18,252 user records did exactly that, exposing email addresses and password hashes in an unspecified format to underground credential markets where they were absorbed into combolists targeting academic and institutional networks.
ScienceAsia (August 2018): Breach Summary
- Records Exposed: 18,252
- Data Types: Email addresses, password hashes (unknown format)
- Breach Type: Database dump / Combolist
- Country Affected: Thailand
- Date Leaked: August 26, 2018
Unknown Hash Format: The Conservative Security Response
The ScienceAsia database contained password hashes in a format that hasn't been definitively identified. When hash type is unknown, security analysts treat the credentials as fully at risk -- because the uncertainty prevents any meaningful estimate of how long passwords remain protected before cracking is feasible. In practice, unlabeled hashes in older databases often turn out to be legacy schemes with minimal protection. The conservative approach is to assume the hashes are already cracked or crackable, and to treat all assoiciated credentials as compromised until proven otherwise. For the 18,252 affected users, that means any reused passwords across other platforms should have been changed immediately following discovery -- and for those who still haven't, the risk remains active today.
Academic Networks as Pivot Points
Scientific journal platforms attract a specific demographic: researchers, professors, and graduate students at universities and research institutions. This population typically uses institutional email addresses -- which are also the keys to university networks, academic databases, grant management systems, and collaborative research platforms. Attackers who gain access to academic email accounts can pivot into institutional infrastructure, intercept unpublshed research, and access grant application systems with real financial value. The ScienceAsia breach, though rooted in a Thai journal platform, exposes a demographic with disproportionate access to sensitive institutional networks far beyond the journal itself. Thailand's academic community connects to global research networks, making these credentials valuable well outside their geographic context.
Thailand's Second Breach in the August 26, 2018 Cluster
ScienceAsia was Thailand's second contribution to the August 26, 2018 mass release -- alongside SawasdeeKappom, the Thai-Japan social networking portal that appeared the same day. The broader cluster spanned more than ten organizations across Thailand, Germany, the United States, Italy, Ireland, Japan, Nepal, Poland, and the Netherlands. The simultaneous release of databases from such diverse geographies and industries on a single day is consistent with a batch dump operation rather than targeted attacks on Thailand's academic sector specifically.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including academic institution databases like ScienceAsia. If you've published in or accessed Thai scientific journals, or if your organization monitors credential exposure across academic and research networks, a quick scan can reveal whether your email address is active in these attack pipelines.
Breach Breakdown
18,252 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds