Cazh
bd_f1c3d8d9b8891d43 · schema v1 · pii pii-v1
Full breach record for Cazh →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Icarus on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
- User DB: 300,000 Users (Email, Hash, Phone, Address, DOB) for https://bkdp.cazh.id/. - KYC Vault: 7,800 Government IDs + 4,200 Selfies (including "Hold-to-Face" ID selfies). - 34 SQL Databases for associated schools (Students/Parents/Staff). - Corporate/Financial: Full Investor Database + partner documents - Collateral documents (Vehicle Registration Documents & Property Deeds) - Billing Proofs - Full src code of their services Data stolen: PII, SOURCE CODE, KYC
Source provenance
- Source URL
- https://www.ransomware.live/id/Q2F6aC5pZEBJY2FydXM=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2026
- Raw hash
- 56c396611da8a6737e008c3acf9cdfa2a5ddc4307df21a4df2c7b5394843dc69
Reporting entity
- Name
- Icarusnorm: icarus
Victim entity
- Name
- Cazhnorm: cazh
- Domain
- cazh.id
- Industry
- Financial Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· icarus
- Threat actor
- IcarusExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.