Data Breach & Leak
~/ › Data Breach & Leak › article
Conexus Mobile Alliance Target of Data Leak by Dewata Blackhat Hacktivist Group
> By Haider | May 04, 2026 | 3 min read
⚠️ DATA BREACH ALERT:
Conexus Mobile Alliance, one of Asia’s largest mobile alliances, has reportedly suffered a significant data compromise. A pro-Indonesian hacktivist group operating under the name Dewata Blackhat (specifically a threat actor alias ./KeraSakti) has leaked a database allegedly belonging to the organization’s primary domain.
The leak, published via a popular data-sharing host and publicized on Telegram channels, exposes critical user credential structures and administrative login details. Threat intelligence analysts have confirmed the publication of a CSV database containing structured database tables.

Exposed Data Structure and Impact
The leaked dataset exposes several fields that pose immediate operational security and privacy risks if validated. The compromised database schema includes the following fields:
- Internal Identifiers (ID): Unique database keys mapped to user and administrator profiles.
- Account and Profile Names: Individual usernames associated with the network’s interfaces.
- Corporate and User Emails: Personal and business email addresses.
- User Passwords: Credentials stored within the database. The exact hashing mechanism used (if any) is currently under review by threat intel teams.
- Account Status & Creation Dates: Historical metadata indicating when accounts were established and their active authorization status.
- Administrative Authorization Levels (admin_type): Designations indicating which accounts hold elevated administrative privileges.
- Session Metadata (login_time): Network log times tracking user activity.
Contextualizing the Threat Actor: Dewata Blackhat
Dewata Blackhat is a decentralized hacktivist coalition primarily composed of Indonesian actors, often collaborating with regional syndicates like the Akatsuki Cyber Team, Karawang Error System, and Bangladesh Anonymous. While historically focused on web defacement, the group has increasingly shifted toward database exfiltration and public disclosure campaigns (doxxing).
By targeting Conexus Mobile Alliance – which comprises major telecommunications providers across Asia – regional hacktivists seek to raise their operational profile within the Southeast Asian cyber threat landscape. This leak highlights the ongoing vulnerabilities faced by international consortia due to shared administrative nodes.
Mitigation Recommendations
In response to the credential leak, affected organizations and affiliated telecommunications partners should take immediate defensive actions:
- Enforce Global Password Resets: Mandate immediate credential changes for all accounts, particularly those matching administrative profiles exposed in the leak.
- Audit Administrative Privileges: Review all accounts designated with elevated authorization levels to identify and deactivate unauthorized or stale accounts.
- Implement Multi-Factor Authentication (MFA): Enforce hardware or app-based MFA across all corporate portals to prevent credential stuffing attacks utilizing the leaked passwords.
Data compromises in the telecommunications sector can serve as precursors to secondary phishing attacks and network intrusion campaigns. Monitoring and immediate security hardening are essential to isolate potential downstream breaches.
Mitigation & Prevention Strategies
Data breaches involving Personally Identifiable Information (PII) or sensitive corporate databases require immediate containment and long-term security overhauls:
- Database Hardening: Ensure databases (SQL, MongoDB, Elasticsearch) are never exposed directly to the public internet. Bind services to localhost or strict internal VPCs.
- Data Encryption: Implement robust encryption for data-at-rest. Even if threat actors exfiltrate database dumps, properly salted and hashed passwords minimize the blast radius.
- Credential Rotation: Following any suspected breach, force a global password reset for affected users and rotate API keys and service credentials immediately.
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Conexus Mobile Alliance Target of Data Leak by Dewata Blackhat Hacktivist Group is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for data breach & leak threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
Data Breach & Leak
Data Breach & Leak
Data Breach: Cyber Team Indonesia Leaks Pemdes Butuh Citizen Records
> read
Data Breach & Leak