> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Thepha District Public Health Office in Thailand Breached, Databases Dumped and Server Access Offered
- URL: https://darkwebinformer.com/thepha-district-public-health-office-in-thailand-breached-databases-dumped-and-server-access-offered/
- Published: 2026-07-09T18:32:46.000Z
- Updated: 2026-07-09T18:32:46.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![Thailand flag](https://flagcdn.com/w40/th.png)Thailand Government / Health Live Access Offered 

## Thepha District Public Health Office in Thailand Breached, Databases Dumped and Server Access Offered

A threat actor using the alias **Monkeydance** claims to have breached the **Thepha District Public Health Office**, a local health authority in Thailand operating under the Ministry of Public Health. Posted on July 9, 2026, the listing offers a full dump described as multiple databases, all files and logs, **1,006 PDF invoices and documents**, and backups dating back to May 2026, totaling around 2GB. A sample indicates the databases include website user accounts with hashed passwords and staff contact details. The actor additionally claims to be offering **live server access** to the compromised system. The claim is **unverified**.

Severity HIGH 

Data\~2GB dump

Documents1,006 PDFs

Country![Thailand flag](https://flagcdn.com/w40/th.png)Thailand

ActorMonkeydance

### ▣Post details

TargetThepha District Public Health Office

Country![Thailand flag](https://flagcdn.com/w40/th.png)Thailand

SectorGovernment / Health

ClaimFull dump (DBs, files, logs, docs)

DataSite accounts, hashes, documents

ExtraLive server access offered

ObservedJul 9, 2026

ActorMonkeydance

### !Allegedly included

- Multiple database dumps
- 1,006 PDF invoices & documents
- All files & logs
- Backups from May 2026
- Website user accounts
- Hashed passwords (staff)
- Staff contact details
- Live server access (offered)

### ◱Screenshots

[ ![Thepha District Public Health Office Thailand data breach forum post screenshot, July 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359782.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359782.png) [ ![Thepha District Public Health Office Thailand data breach forum post screenshot, July 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359783.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/07/978235629783698726598723659872359783.png) 

### ⚠Potential impact

A full compromise of a government health office exposes internal databases, administrative documents, and staff credentials, which can enable further intrusion, fraud, and impersonation. The hashed passwords could be cracked to reuse valid accounts, and the offer of live server access means the environment may remain actively compromised rather than merely leaked. The invoice and document set may contain personal and operational information tied to the office's health programs. No sample data, credentials, file listings, links, or access details are reproduced here. The claim is unverified.

### iStatus

Unverified 

This is a data-leak post with downloads gated behind forum points; the actor also advertises paid live access to the server. No sample records, password hashes, file names, links, or access details are reproduced here. The claim is **unverified** and the office has not publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE