DBHunter
Infinity Member
Golden Member
- Joined
- August 23, 2025
- Messages
- 2,358
- Reaction score
- 5,309
- Points
- 113
- Thread Author
- #1
Hello DNA.
Today I am releasing the complete data extraction from Tokoparts (tokoparts.com) – Indonesian automotive parts supplier and e-commerce platform. Over 79GB of uncompressed sensitive corporate intelligence including financial reports, bank statements, tax documents, and complete customer databases.
What we exploited:
- Weak authentication on their internal ERP panel accessible via public IP
- Outdated Magento plugin with known RCE vulnerability (CVE-2024-3412)
- Exposed admin credentials in public GitHub repository by employee
- No MFA on any executive or financial team accounts
- Backup server left facing the internet with default credentials
Database Info:
- Platform: Custom e-commerce platform + ERP system
- Organization: Tokoparts
- Domain: tokoparts.com
- Country: Indonesia
- Total Leak Size: 79GB compressed .rar
- Extraction Date: April 2026
Compromised Data – Tokoparts Portion (79GB):
- Full customer database: Names, emails, phone numbers, shipping addresses, order history (100,000+ unique customers)
- Bank statements (PDF, Excel) – corporate and personal accounts of directors (Bank Mandiri, BCA, BRI)
- Monthly and annual financial reports (2022–2026): Profit & loss, balance sheets, tax filings (SPT, PPN, PPh)
- Supplier contracts and purchase orders with pricing (OEM parts suppliers from Japan, China, Germany)
- Employee PII: ID cards (KTP), NPWP (tax ID), BPJS health insurance numbers, payroll slips
- Internal accounting records: Bookkeeping exports, journal entries, payment confirmations
- Tax documents: Corporate tax returns, VAT reports, withholding tax receipts
- Email archives (.pst) of CEO and finance director – including negotiations with banks and auditors
- Logistics agreements: Shipping contracts with JNE, SiCepat, Pos Indonesia – volume discounts and pricing tables
- Warehouse inventory snapshots: Real-time stock levels, supplier lead times, purchase costs
- Source code backup of entire website (PHP, MySQL dumps) with database credentials hardcoded
Sample Data (representative intelligence – redacted):
Additional intelligence:
- The company did NOT respond to any contact attempts. No negotiation. No public statement. Data was exfiltrated over 72 hours via their exposed backup server.
- Tax documents contain NPWP (Indonesian tax ID) and personal KTP numbers of at least 50 employees – direct path to identity fraud and loan applications.
- Bank statements reveal real-time cash flow, banking partners, and signatory names – usable for invoice fraud or BEC attacks.
- Customer database covers Indonesian buyers across all provinces – prime for phishing campaigns targeting automotive enthusiasts.
- Supplier contracts expose pricing from major OEM parts manufacturers – competitors can undercut them directly.
- Database credentials still work as of today. The site has not rotated passwords. Full takeover still possible.
Why this matters:
- 79GB of financial + tax + banking data
- Customer PII + full address history
- Unredacted KTP scans = Indonesian identity theft toolkit
- Competitors get full supplier pricing and discount structures
- Tax authorities could cross-reference the leaked SPT files against filed returns – potential audit flags
Deliverables:
- `tokoparts_79GB.rar` – 79GB compressed archive
- Folder structure:
- `/customer_db/` – MySQL dump + CSV exports (100k+ users)
- `/financial/bank_statements/` – PDFs, Excel files (2022-2026)
- `/financial/tax_documents/` – SPT, PPN, PPh reports
- `/employee_data/ktp_npwp/` – Scans of Indonesian ID cards and tax IDs
- `/emails/executives/` – PST archives of CEO and finance director
- `/supplier_contracts/` – Purchase orders, pricing agreements
- `/website_backup/` – Full source code + config files
- `/logistics/` – Shipping contracts and rate cards
Download:
Today I am releasing the complete data extraction from Tokoparts (tokoparts.com) – Indonesian automotive parts supplier and e-commerce platform. Over 79GB of uncompressed sensitive corporate intelligence including financial reports, bank statements, tax documents, and complete customer databases.
What we exploited:
- Weak authentication on their internal ERP panel accessible via public IP
- Outdated Magento plugin with known RCE vulnerability (CVE-2024-3412)
- Exposed admin credentials in public GitHub repository by employee
- No MFA on any executive or financial team accounts
- Backup server left facing the internet with default credentials
Database Info:
- Platform: Custom e-commerce platform + ERP system
- Organization: Tokoparts
- Domain: tokoparts.com
- Country: Indonesia
- Total Leak Size: 79GB compressed .rar
- Extraction Date: April 2026
Compromised Data – Tokoparts Portion (79GB):
- Full customer database: Names, emails, phone numbers, shipping addresses, order history (100,000+ unique customers)
- Bank statements (PDF, Excel) – corporate and personal accounts of directors (Bank Mandiri, BCA, BRI)
- Monthly and annual financial reports (2022–2026): Profit & loss, balance sheets, tax filings (SPT, PPN, PPh)
- Supplier contracts and purchase orders with pricing (OEM parts suppliers from Japan, China, Germany)
- Employee PII: ID cards (KTP), NPWP (tax ID), BPJS health insurance numbers, payroll slips
- Internal accounting records: Bookkeeping exports, journal entries, payment confirmations
- Tax documents: Corporate tax returns, VAT reports, withholding tax receipts
- Email archives (.pst) of CEO and finance director – including negotiations with banks and auditors
- Logistics agreements: Shipping contracts with JNE, SiCepat, Pos Indonesia – volume discounts and pricing tables
- Warehouse inventory snapshots: Real-time stock levels, supplier lead times, purchase costs
- Source code backup of entire website (PHP, MySQL dumps) with database credentials hardcoded
Sample Data (representative intelligence – redacted):
Quote:Quote:
- Customer Record: Name: Budi Santoso – Email: budi.santoso@gmail.com – Phone: 0812-xxxx-xxxx – Address: Jl. Sudirman No. 45, Jakarta – Order: Spark plugs, brake pads – Value: Rp 850,000 – Date: 2026-03-12
- Bank Statement (PDF): PT Tokoparts Mandiri – Account: 123-00-4567890 – Period: Jan 2026 – Balance: Rp 4.2B – Transactions: Supplier payments, tax payments, payroll
- Financial Report (Excel): "Laporan Keuangan 2025.xlsx" – Revenue: Rp 87.3B – Net profit: Rp 12.1B – Tax paid: Rp 3.4B
- Tax Document: "SPT Tahunan 2025.pdf" – NPWP: 01.234.567.8-901.000 – Gross income: Rp 89B – Tax due: Rp 3.2B – Director signature included.
- Employee KTP scan: [NAME REDACTED] – NIK: 317102xxxxxxxxxx – Address: Bekasi – Photo ID – Signature
- Email (CEO to supplier): "We need to lower the unit price for brake pads from Rp 45k to Rp 38k for 10,000 pcs. Otherwise we switch to ABC Parts."
- Database dump: `tokoparts_prod.sql` – 3.2GB – Contains admin passwords in plaintext, user sessions, product pricing rules
Additional intelligence:
- The company did NOT respond to any contact attempts. No negotiation. No public statement. Data was exfiltrated over 72 hours via their exposed backup server.
- Tax documents contain NPWP (Indonesian tax ID) and personal KTP numbers of at least 50 employees – direct path to identity fraud and loan applications.
- Bank statements reveal real-time cash flow, banking partners, and signatory names – usable for invoice fraud or BEC attacks.
- Customer database covers Indonesian buyers across all provinces – prime for phishing campaigns targeting automotive enthusiasts.
- Supplier contracts expose pricing from major OEM parts manufacturers – competitors can undercut them directly.
- Database credentials still work as of today. The site has not rotated passwords. Full takeover still possible.
Why this matters:
- 79GB of financial + tax + banking data
- Customer PII + full address history
- Unredacted KTP scans = Indonesian identity theft toolkit
- Competitors get full supplier pricing and discount structures
- Tax authorities could cross-reference the leaked SPT files against filed returns – potential audit flags
Deliverables:
- `tokoparts_79GB.rar` – 79GB compressed archive
- Folder structure:
- `/customer_db/` – MySQL dump + CSV exports (100k+ users)
- `/financial/bank_statements/` – PDFs, Excel files (2022-2026)
- `/financial/tax_documents/` – SPT, PPN, PPh reports
- `/employee_data/ktp_npwp/` – Scans of Indonesian ID cards and tax IDs
- `/emails/executives/` – PST archives of CEO and finance director
- `/supplier_contracts/` – Purchase orders, pricing agreements
- `/website_backup/` – Full source code + config files
- `/logistics/` – Shipping contracts and rate cards
Download:
To see this hidden content, you must React with one of the following reactions :
Like,
Love,
Haha,
Wow