Ransomware victim disclosure
← All victimsCazh.id
Claimed by Icarus · listed 15 days ago
Status timeline
- Listed
May 5, 2026
- Data leaked
At a glance
- Group
- Icarus
- Status
- Data leaked
- Country
- ID
- Sector
- Financial Services
- Listed on leak site
- May 5, 2026
About the victim
AI dossier — public-source company profileCazh.id (cazh.id) is an Indonesian financial technology platform operating under the subdomain bkdp.cazh.id, providing digital payment and financial services to schools and educational institutions. The platform manages billing, investor relations, and KYC-verified user accounts across a network of associated schools. It serves students, parents, staff, and institutional partners across Indonesia.
- Industry
- Financial Technology & Education Payment Services
Attack summary
Severity: critical — Mass exfiltration of regulated PII at scale (300,000 users), government-issued identity documents and biometric selfies (KYC vault), financial collateral documents (property deeds, vehicle registrations), and sensitive school records covering minors — all constituting regulated personal and financial data across multiple categories in an Indonesian financial services context.The Icarus ransomware group claims to have exfiltrated data from Cazh.id without stating encryption, publishing a broad dataset including 300,000 user PII records, 12,000 KYC identity documents, 34 school SQL databases, corporate financial records, collateral documents, and full source code of their services.
Data the group says was taken
AI dossier — extracted from the leak post- 300,000 user records (email, password hashes, phone, address, date of birth)
- 7,800 government-issued ID documents
- 4,200 selfie photos including hold-to-face ID selfies
- 34 SQL databases covering students, parents, and staff
- Full investor database
- Partner documents
- Vehicle registration documents
- Property deeds
- Billing proof documents
- Full application source code
What the group claims
- User DB: 300,000 Users (Email, Hash, Phone, Address, DOB) for https://bkdp.cazh.id/. - KYC Vault: 7,800 Government IDs + 4,200 Selfies (including "Hold-to-Face" ID selfies). - 34 SQL Databases for associated schools (Students/Parents/Staff). - Corporate/Financial: Full Investor Database + partner documents - Collateral documents (Vehicle Registration Documents & Property Deeds) - Billing Proofs - Full src code of their services Data stolen: PII, SOURCE CODE, KYC
Sources
- Victim sitebkdp.cazh.id
Source
Indexed 15 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
