Corporate Phishing Got Easier Because of the Siam Cement Group Breach: 473 Contacts Exposed
HEROIC analysts confirmed a database exposure affecting Siam Cement Group, one of Thailand's largest industrial conglomerates, with the breach surfacing on August 20, 2024. A total of 473 records were compromised, containing email addresses and phone numbers belonging to individuals associated with the company. While the record count is comparatively modest, the combination of direct contact channels belonging to personnel at a major industrial organization creates an immediate and actionable threat for targeted phishing and fraud.
When attackers obtain verified email addresses and phone numbers from a company of this scale, the exposure goes beyond simple spam. These contact details can be used to launch spear-phishing campaigns against SCG employees, impersonate the company in supplier or client communications, or fuel vishing attacks where callers pose as internal IT or finance personnel to extract credentials or authorize fraudulent payments.
What Was Exposed
- Email Address
- Phone Number
Why This Matters
Contact information from a large industrial conglomerate is particularly valuable to attackers pursuing business email compromise (BEC) or supply chain fraud. Even a small verified contact list from an organization of Siam Cement Group's size can enable attackers to map out internal communication channels, identify decision-makers, and construct convincing pretexts for fraud. Email addresses from corporate domains are also tested against other services in credential stuffing attacks, since employees frequently reuse work email addresses when registering on third-party platforms.
Phone numbers add another layer of risk, enabling SIM-swapping attempts and SMS phishing (smishing) attacks that can bypass two-factor authentication on financial and corporate accounts.
How Database Breaches Work
A database breach occurs when an unauthorized party gains access to a structured data store, often through SQL injection, exploitation of exposed database ports, or compromised administrative credentials. In many corporate breach cases, contact databases used for CRM, marketing, or HR purposes are targeted because they aggregate verified personal information in one place. Once exported, this data is packaged and circulated on underground forums, where it is purchased by actors looking to run social engineering campaigns or enrich existing data sets. Large industrial organizations often operate complex supplier ecosystems that expand the potential attack surface beyond their core systems.
Check If You Are Affected
If you are an employee, contractor, or contact of Siam Cement Group and are concerned your information may have been exposed, HEROIC's free breach scanner searches a database of over 400 billion compromised records. Visit heroic.com to check your email address and find out what protective steps you should take.
Breach Breakdown
473 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds