Skip to content

Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000

Breach Report Indonesia flagIndonesia Education / University Data for Sale

Podomoro University Allegedly Breached, 75 Databases and Full Website Source Code Offered for $7,000

A seller posting as LordVoldemort is advertising what they describe as a complete compromise of Podomoro University in Indonesia, an institution established in 2014 under the Agung Podomoro Education Foundation. Rather than a single database, the listing enumerates 75 separate databases by filename, spanning academic records, admissions, alumni, employees and HR, finance, payments, scholarships, research, library, and internal IT systems, alongside academic year tables running from 2014 to 2026. The seller also claims to hold the entire source code of the university's website. Total size is given as 2.31GB, with proof offered as a screenshot of an academic database dump. The asking price is $7,000 in cryptocurrency. The claim is unverified.

Databases75
Size2.31GB
Price$7,000
ActorLordVoldemort

Post details

TargetPodomoro University
CountryIndonesia flagIndonesia
SectorEducation / Higher education
ListingData for sale — $7,000, crypto
Volume75 databases / 2.31GB
RangeAcademic years 2014–2026
Observed
ActorLordVoldemort

!Allegedly included

  • Academic records
  • Admissions data
  • Alumni records
  • Employee & HR databases
  • Finance databases
  • Payment & virtual account data
  • Scholarship records
  • Student life data
  • Learning management systems
  • Research & institute databases
  • Library systems
  • CRM & career services
  • Budgeting & purchasing
  • Audit logs & backups
  • IT, WiFi & web infrastructure
  • Website source code

Screenshot

Potential impact

The modest file size understates this considerably. What is described is not the loss of one system but an institution's entire data estate: the enumerated databases cover admissions through graduation and into alumni relations, and separately cover the staff side through HR, payroll-adjacent finance, and purchasing. With academic year tables running from 2014, the year the university was founded, through to 2026, the affected population plausibly includes everyone who has ever enrolled. Several of the named databases carry a sensitivity beyond ordinary contact details. Scholarship records identify which students required financial assistance, payment and virtual account systems handle tuition transactions and the family bank details behind them, and an HR information system in an Indonesian context would ordinarily hold NIK national identity numbers and tax identifiers for staff, which cannot be reissued. Students are also a population with decades of future exposure ahead of them, so records taken now retain fraud value long after the institution has moved on. The inclusion of website source code changes the character of the incident from a data loss to a persistence problem: source code frequently contains hardcoded credentials and connection strings, and gives any buyer a map for regaining access after remediation. The presence of audit logs and full backups in the listing compounds this, since those are the records an institution would rely on to establish what actually happened. The claim is unverified.

iStatus

Unverified

The listing offers proof in the form of a database dump screenshot and provides sample data only on private request, with payment in cryptocurrency and multiple encrypted contact routes that Dark Web Informer is not reproducing. The dump filename carries a timestamp placing the extraction roughly a day before posting, which if accurate would mean access was current at the time of listing and any credentials within the data should be treated as live. The seller account is long-established with high standing on the forum, a materially different profile from the throwaway accounts behind many listings, though this speaks to reputation within that community and not to the authenticity of the data. Neither the database inventory nor the source code claim has been independently corroborated. The claim is unverified and Podomoro University has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest