PT Betiri Cipta Media Core Database Access Offered for $25K
A forum actor posting as TheTrueWorldCreator is offering what they claim is full access to the core money database of PT Betiri Cipta Media, an Indonesian aggregator and distributor of digital goods operating as a PPOB business. The post describes a B2B platform used by small resellers for mobile airtime, prepaid electricity, e-wallet top-ups, bank transfers, games and vouchers, and utility bill payments. The actor claims direct database access with read and write permissions, access to transaction and reseller tables, bank and deposit records, gateway credentials, an SMS gateway, the OtomaX management interface, an employee workstation and a corporate Telegram account. The asking price is $25,000 in XMR. The claim is unverified.
▣Post details
!What the post claims
- Full access to the core money database
- Direct database IP and credentials
- Full read and write permissions
- Ability to alter reseller balances
- Ability to create fake sales or refunds
- Access to bank statement data
- Ability to modify incoming deposit account details
- Access to deposit ticket records
- Gateway passwords and H2H infrastructure
- OtomaX GUI access and credentials
- Access to an employee workstation
- Corporate Telegram account access
- SMS gateway access
- Bulk SMS capability to 1,723+ resellers and clients
- 14,301 transactions on Sep 9, 2026
- 1,690,440,633 IDR in stated daily transaction value
- ~$51K stated daily transaction flow elsewhere in the post
- ~$3.6M stated bank turnover over roughly three weeks
- Remote execution offered on employee systems
- Trustee samples offered through a file-sharing link
◱Screenshots
☷Mapped techniques
The actor does not explain the initial intrusion method. The techniques below are mapped only to capabilities explicitly claimed in the listing.
- Persistence / Defense Evasion T1078 Valid Accounts Claimed The listing offers direct database credentials, OtomaX credentials and access to other authenticated internal services.
- Collection T1213 Data from Information Repositories Claimed The actor describes direct access to SQL Server tables containing reseller balances, transaction journals, bank statements, deposit tickets and other operational records.
- Impact T1565.001 Stored Data Manipulation Claimed The post explicitly describes modifying balances, falsifying sales and refunds, changing bank account details and creating deposit records for transfers that did not occur.
⚠Potential impact
If the claimed access is authentic, the risk extends well beyond data exposure. The actor describes the ability to change reseller balances, fabricate sales and refunds, alter bank account details used for incoming deposits and create deposit records, which could enable direct financial theft or transaction manipulation. Access to the SMS gateway and corporate messaging infrastructure could also support targeted phishing, fraudulent payment notifications and impersonation of legitimate business communications. Claimed access to an employee workstation and an offer to execute arbitrary software would further increase the risk of malware deployment, credential theft and expansion into additional internal systems.
iStatus Unverified
The forum listing contains detailed descriptions of database tables, permissions, transaction volumes and internal infrastructure, together with samples presented as evidence. However, Dark Web Informer has not independently verified the claimed access, transaction figures or the actor's ability to modify the environment. The listing does not state how the initial access was obtained, when it began or whether the alleged access remains active.
Dark Web Informer // Threat Intelligence