[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3atej99h9f9ic":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":32,"seoTitle":33,"seoDescription":34,"logoUrl":35,"isVerified":36,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"6a45b4f2d3206f0fe8ce5f4b","SawasdeeKappom","SawasdeeKappom Alleged Data Exposure","sawasdeekappom","sawasdeekappom.com","2018-08-26T00:00:00.000Z","2025-09-12T00:00:00.000Z",null,"2026-09-17T16:27:41.515Z","2026-07-27T16:11:14.477Z","Unverified breach record","https:\u002F\u002Fheroic.com\u002Fdarkhive-breaches\u002Fsawasdeekappom-breach\u002F",[17],33216,"known","email_identifiers","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"Medium",[30,31],"Email addresses","Passwords","\u003Cp>The SawasdeeKappom data breach is an unverified security incident affecting the former social network experience linked to the domain sawasdeekappom.com, based in Thailand and focused on Thailand-Japan friendship connections. Detailed breach indexes report a main scope of 33,216 accounts and note that the incident occurred during August 2018, particularly within the August 26, 2018 leak cluster. The leaked fields are limited to email addresses and plain text passwords. The platform is maintained as a retired service due to certificate and response issues on the domain and because it does not operate like a reliable live service today. The unindependent verification is retained as there is no official company confirmation.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The supported data fields are email addresses and plain text passwords. Plain text passwords are one of the fastest types of abuse for attackers; they do not require an additional cracking process and the same email and password pair can be tried on other services. Social network and friendship context also increase the risk. The user having an account on an old dating site can provide clues about personal preferences, language environment, or regional connections. Therefore, the incident is considered sensitive not only in terms of password security but also regarding privacy and targeted fraud.\u003C\u002Fp>\n\u003Cp>Additional personal fields such as phone number, payment card, full address, real name, identification document, or message content were not reliably supported in the main scope. Therefore, data categories were not expanded. The most significant risk is that the password may exist in the same or similar form in other places such as email, social media, cloud storage, financial account, game account, or work session. Even if an old social network account is no longer used, if its password remains unchanged on other services, the impact of the leak continues.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The main scope is 33,216 accounts. The event date was considered as August 26, 2018, and the date of indexing as September 12, 2025. This scope was maintained because the domain name, number of registrations, Thailand connection, social network and friendship category, email address, and plain text password fields are consistent with each other. While some sources provide the date at the month level, a more detailed account of the event indicates the day of the mass leak in the same period. Therefore, it is clearly conveyed to the user that the event belongs to the 2018 period and that the indexing date is 2025.\u003C\u002Fp>\n\u003Cp>The incident is not marked as verified because it is not supported by an official institution report. A certificate error in the domain's current HTTPS check and the lack of healthy content on the HTTP side do not by themselves prove the past incident; they only indicate that the current service status is weak. Public statements are limited to the fields of count and data supported by evidence. Unconfirmed additional types of information are not presented to the user. This limit reduces the risk of false positives and helps the matched person choose the correct security steps.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is seen in individuals who reuse the password they used on the SawasdeeKappom account for their personal email accounts, social media profiles, messaging services, financial accounts, cloud storage, or work accounts. The platform's focus on the Thai and Japanese friendship circles can particularly facilitate the preparation of targeted messages based on email addresses, language usage, and social connections associated with these regions. Since the password is found in plain text, attackers can directly create trial lists without wasting time on weak password guessing.\u003C\u002Fp>\n\u003Cp>Old and forgotten accounts carry a separate risk in such cases. The user may have abandoned the site years ago, but if the same password is used on another account, the risk does not end. Due to privacy concerns, users may ignore old accounts with friendship or dating themes; this also delays password changes. People who have been using the same email address for many years, those who do not use a password manager, and those who continue by making small additions to the same password are at greater risk. For those registered with corporate email, the work account should also be separately audited.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step is to identify and change all accounts that use the same or similar password as the one used for SawasdeeKappom. Email accounts, social media, messaging, financial, cloud storage, and work sessions should be prioritized. A unique, long, and random password should be chosen for each account; old repetitions should be checked with a password manager. Multi-factor authentication should be enabled on email and critical accounts. App-based codes, hardware keys, or passkeys provide stronger protection than SMS codes.\u003C\u002Fp>\n\u003Cp>Suspicious login notifications, unexpected password reset messages, fake alerts themed around friendship or social networks, links received in the regional language, and messages containing payment requests should be examined carefully. Instead of clicking on the links, it is preferable to check by manually entering the address of the relevant service. It should not be forgotten that the same password may also have been used in old forum, shopping, gaming, and file sharing accounts. If there is a relationship with a corporate email or work password, the security team should be informed and the relevant sessions should be monitored separately.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>For permanent protection, a unique password should be used for each account. Old social network, friendship, forum, gaming, and shopping accounts should be reviewed at regular intervals; unused accounts should be closed or set apart with a strong unique password. A password manager should be the main tool both for finding repeated passwords and for generating random strong passwords. Once a plaintext password has circulated, it should no longer be considered secure. Even if the incident date is old, if the password has remained unchanged elsewhere, the risk carries over to today.\u003C\u002Fp>\n\u003Cp>Using a separate email on platforms that are sensitive in terms of privacy can reduce risk. However, a separate email alone is not sufficient; a unique password and multi-factor authentication are the basic layers of protection. Users should consider that leaks from old and small-scale services can be added to large collections years later. Therefore, password health should be reviewed at regular intervals, and the same password should not be allowed to remain on different sites. The most important long-term goal is to ensure that there is no password link between critical accounts and social accounts.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Users who see the SawasdeeKappom result on LeakData should consider it not as an official company notification, but as an unverified risk signal seen in public breach indices. The main scope shown is 33,216 accounts; the data fields are email addresses and plain text passwords. The incident date is August 26, 2018, and the addition date is recorded as September 12, 2025. This distinction helps the user understand that the leak is old but was added to the index later.\u003C\u002Fp>\n\u003Cp>The user in the affected area should first secure their email account, then make changes on all services where they may have used the same or similar password. Repeated passwords should be searched for in the password manager, and old social network and dating accounts should also be examined. Unknown sessions should be closed, multi-factor authentication should be enabled, and unexpected friendship or social network-themed messages should not be trusted. Once passwords become unique, the risk of an old leak spreading to new accounts is significantly reduced.\u003C\u002Fp>","SawasdeeKappom Alleged Data Exposure (33.2 Thousand Email Identifiers)","SawasdeeKappom Alleged Data Exposure. 33.2 Thousand email identifiers are reported. Reported data: Email addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fsawasdeekappom.png",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":40,"websiteStatus":40,"websiteCheckedAt":13},"Dating and social media","Thailand",""]