Supreme Court of Indonesia (Mahkamah Agung) Breach Threatens Public Trust: 4,411 Users Exposed
HEROIC identified 4,411 records tied to the Supreme Court of Indonesia (Mahkamah Agung) surfacing on April 10, 2025, exposing email addresses, phone numbers, first names, last names, usernames, and bcrypt password hashes from the country's highest judicial portal. When a government authority leaks user data, the consequences cascade through courts, attorneys, and the public.
Why This Supreme Court of Indonesia (Mahkamah Agung) Database Leak Is Dangerous
This is not a consumer service. The users registered on the Supreme Court portal include lawyers, litigants, and officials who interact with sensitive court information. Exposing their identities, contact data, and credentials hands attackers a directory for targeted phishing around active cases, impersonation of legal counsel, and social engineering of court staff.
What Was Exposed in the Supreme Court of Indonesia (Mahkamah Agung) Breach
- 4,411 email addresses tied to court portal accounts
- Phone numbers used for notifications and account recovery
- First and last names of registered users
- Usernames mapped to roles inside the portal
- bcrypt password hashes that can still fall to weak passwords
Why This Matters: The Consequences
Consequence one is account takeover on the portal itself, which could expose ongoing case information or allow tampering with court submissions. Consequence two is identity theft: leaked names, emails, and phones feed Indonesian language phishing crafted around court notifications. Consequence three is public trust. Government breaches undermine confidence in digital judicial services and invite regulatory scrutiny. Credential stuffing, fraud, and targeted espionage all follow once the data is in circulation.
How This Database Breach Works
A database compromise on a government portal typically traces back to an unpatched web application, a leaked admin credential, or an injection vulnerability in a search or filing function. Once the table is pulled, it surfaces on dark web forums frequented by both financially motivated actors and state-aligned groups interested in the identities of court users.
Check If You Are Affected
If you have registered on the Mahkamah Agung portal, rotate the password and enable stronger authentication on any connected email accounts. HEROIC's breach intelligence platform indexes more than 400 billion compromised records, and scanning your email confirms whether your credentials appear in this leak or related exposures.
Breach Breakdown
4,411 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds