> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# PT Betiri Cipta Media Core Database Access Offered for $25K
- URL: https://darkwebinformer.com/pt-betiri-cipta-media-core-database-access-offered-for-25k/
- Published: 2026-09-10T16:02:49.000Z
- Updated: 2026-09-10T16:02:49.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Access Sale Indonesia Financial Systems $25K XMR 

## PT Betiri Cipta Media Core Database Access Offered for $25K

A forum actor posting as **TheTrueWorldCreator** is offering what they claim is **full access to the core money database of PT Betiri Cipta Media**, an Indonesian aggregator and distributor of digital goods operating as a PPOB business. The post describes a B2B platform used by small resellers for **mobile airtime, prepaid electricity, e-wallet top-ups, bank transfers, games and vouchers, and utility bill payments**. The actor claims **direct database access with read and write permissions**, access to transaction and reseller tables, bank and deposit records, gateway credentials, an SMS gateway, the OtomaX management interface, an employee workstation and a corporate Telegram account. The asking price is **$25,000 in XMR**. The claim is **unverified**.

Severity CRITICAL 

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Price$25K

Transactions / day14,301

Daily value\~$97.5K

Resellers1.5K+

### ▣Post details

TargetPT Betiri Cipta Media

CountryIndonesia

SectorDigital goods / PPOB

ListingFull database access

Price$25,000 XMR

PermissionsSELECT / INSERT / UPDATE / DELETE

ObservedSep 9, 2026

ActorTheTrueWorldCreator

### !What the post claims

- Full access to the core money database
- Direct database IP and credentials
- Full read and write permissions
- Ability to alter reseller balances
- Ability to create fake sales or refunds
- Access to bank statement data
- Ability to modify incoming deposit account details
- Access to deposit ticket records
- Gateway passwords and H2H infrastructure
- OtomaX GUI access and credentials
- Access to an employee workstation
- Corporate Telegram account access
- SMS gateway access
- Bulk SMS capability to 1,723+ resellers and clients
- 14,301 transactions on Sep 9, 2026
- 1,690,440,633 IDR in stated daily transaction value
- \~$51K stated daily transaction flow elsewhere in the post
- \~$3.6M stated bank turnover over roughly three weeks
- Remote execution offered on employee systems
- Trustee samples offered through a file-sharing link

### ◱Screenshots

[ ![Forum post offering alleged access to PT Betiri Cipta Media financial systems, part one, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359872.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359872.png) [ ![Forum post offering alleged access to PT Betiri Cipta Media financial systems, part two, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359873.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/12359782359768295786239875692876359873.png) 

Forum post offering alleged access to PT Betiri Cipta Media's database and related financial infrastructure, observed 9 September 2026.

### ☷Mapped techniques

The actor does not explain the initial intrusion method. The techniques below are mapped only to capabilities explicitly claimed in the listing.

- Persistence / Defense Evasion [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts Claimed The listing offers direct database credentials, OtomaX credentials and access to other authenticated internal services.
- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from Information Repositories Claimed The actor describes direct access to SQL Server tables containing reseller balances, transaction journals, bank statements, deposit tickets and other operational records.
- Impact [T1565.001](https://attack.mitre.org/techniques/T1565/001/) Stored Data Manipulation Claimed The post explicitly describes modifying balances, falsifying sales and refunds, changing bank account details and creating deposit records for transfers that did not occur.

### ⚠Potential impact

If the claimed access is authentic, the risk extends well beyond data exposure. The actor describes the ability to **change reseller balances, fabricate sales and refunds, alter bank account details used for incoming deposits and create deposit records**, which could enable direct financial theft or transaction manipulation. Access to the **SMS gateway and corporate messaging infrastructure** could also support targeted phishing, fraudulent payment notifications and impersonation of legitimate business communications. Claimed access to an employee workstation and an offer to execute arbitrary software would further increase the risk of **malware deployment, credential theft and expansion into additional internal systems**.

### iStatus Unverified

The forum listing contains detailed descriptions of database tables, permissions, transaction volumes and internal infrastructure, together with samples presented as evidence. However, Dark Web Informer has **not independently verified the claimed access, transaction figures or the actor's ability to modify the environment**. The listing does not state how the initial access was obtained, when it began or whether the alleged access remains active.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pt-betiri-cipta-media-2026-09-09&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pt-betiri-cipta-media-2026-09-09&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=pt-betiri-cipta-media-2026-09-09&utm%5Fcontent=footer) // Threat Intelligence