Breach Intelligence Report 02 Dec 2025

SIMAK UNSIL

HEROIC
HEROIC Threat Intelligence Team
Email Address Phone Number Password Hash First Name Last
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 18,518
Source Type Database
Origin Darkweb
Password Type MD5

We noticed a significant data leak surfacing on a popular dark web forum on May 28, 2025. What struck us immediately was the specific targeting of an academic institution, SIMAK UNSIL, which serves as the central academic information system for Universitas Siliwangi in Indonesia. The sheer volume of records, totaling 18,518, suggests a comprehensive compromise of user accounts within this critical educational infrastructure. The inclusion of sensitive personal identifiers alongside password hashes raises immediate concerns regarding potential downstream attacks and identity theft.

The breach, identified as a database compromise, exposed a substantial amount of personally identifiable information (PII) for 18,518 users of the SIMAK UNSIL system. The leaked data includes email addresses, phone numbers, first names, last names, and MD5 password hashes. The source structure appears to be a direct dump of user account information, likely extracted from the primary user database. The leak locations were primarily on a prominent hacking forum, indicating an intent to monetize or distribute the compromised credentials. The use of MD5 for password hashing is a particularly concerning element, as this algorithm is known to be highly susceptible to brute-force and rainbow table attacks, rendering the password hashes easily crackable.

While specific news coverage directly linking this leak to SIMAK UNSIL's public announcements is still developing, similar incidents involving educational institutions in Southeast Asia have been reported in recent months. OSINT investigations into the forum where the data appeared indicate a history of similar data dumps from various organizations. Academic systems are increasingly becoming targets due to the high value of student and faculty data, which can be leveraged for phishing campaigns, credential stuffing attacks against other platforms, or even academic fraud. Further research into the forum's activity might reveal patterns or attribution clues.

Our attention was drawn to a recent disclosure on May 29, 2025, detailing a substantial data exfiltration event impacting the SIMAK UNSIL platform, the academic information system for Universitas Siliwangi. The sheer scale of the compromise, affecting 18,518 individuals, and the nature of the data involved – encompassing credentials and personal identifiers – warrant immediate scrutiny. What is particularly noteworthy is the inclusion of MD5 hashed passwords, a legacy hashing algorithm that presents a significantly elevated risk of compromise compared to modern, more robust hashing techniques.

The incident stems from a database breach that resulted in the exposure of 18,518 records from SIMAK UNSIL. The compromised data types include email addresses, phone numbers, first names, last names, and password hashes (MD5). The source structure suggests a direct extraction from the user authentication or profile database. The leak manifested on a well-known hacking forum, indicating a potential for widespread distribution and exploitation. The vulnerability of MD5 hashes means that attackers can likely derive the original passwords for a significant portion of the compromised accounts, facilitating credential stuffing and unauthorized access to other online services used by the affected individuals.

While direct official statements from Universitas Siliwangi regarding this specific breach are yet to be widely disseminated, the incident aligns with a broader trend of attacks targeting higher education institutions globally. Recent cybersecurity reports have highlighted the increasing sophistication of threat actors exploiting vulnerabilities in academic IT infrastructure. Open-source intelligence indicates that the forum hosting the leak has previously been associated with the sale of compromised credentials from various sectors, underscoring the potential for this data to be leveraged in sophisticated cybercrime operations.

We observed the emergence of a dataset on May 28, 2025, originating from the SIMAK UNSIL platform, an academic information system integral to Universitas Siliwangi. The immediate concern was the breadth of the exposure, impacting 18,518 users, and the inclusion of sensitive personal and authentication data. What stood out was the clear indication of a database compromise, leading to the leakage of credentials that, due to their hashing method, are highly susceptible to decryption.

This breach, classified as a database compromise, has led to the exposure of 18,518 user records. The data types compromised include email addresses, phone numbers, first names, last names, and password hashes. The nature of the leak suggests a direct dump from a user account database. The data was found on a prominent hacking forum, signaling an intent for dissemination. The use of MD5 hashing for passwords is a critical vulnerability, as these hashes can be readily cracked, potentially compromising the accounts of a large number of students and faculty. The implications extend beyond SIMAK UNSIL, as these credentials could be reused on other platforms.

While specific public reporting on this SIMAK UNSIL breach is still in its nascent stages, the pattern of attacks against educational institutions is well-documented. Cybersecurity research consistently points to universities as attractive targets due to the wealth of PII and the potential for academic fraud. OSINT analysis of the forum where the leak occurred reveals a consistent trade in compromised data, suggesting a well-established marketplace for such information.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Phone Number,Password Hash,First Name,Last Name
Password Types MD5
Date Leaked 02 Dec 2025
Check in 5 seconds

18,518 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,227 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $134.0K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance