Dark Web Informer@DarkWebInformer
‼️🇱🇰 The Eastern Provincial Council of Sri Lanka (ep.gov.lk), the regional government body covering the country's Eastern Province, has allegedly been breached, with 10,000 rows of citizen and government employee data put up for sale on a popular cybercrime forum at $150.
⠀
‣ Threat Actor: wh6ami
‣ Category: Data Breach / Government Data Sale
‣ Victim: Eastern Provincial Council, Sri Lanka
‣ Industry: Government / Regional Administration
⠀
The Eastern Provincial Council oversees the Governor's Secretariat, Chief Secretary's Secretariat, Provincial Public Service Commission (PPSC), and Provincial Council Secretariat, handling administration, recruitments, and legislative work for the province.
⠀
What the leak contains:
⠀
▪️ ~10,000 rows of PII
▪️ Phone numbers (mobile and landline)
▪️ Email addresses
▪️ Full names
▪️ National Identity Card numbers (NIC)
▪️ Residential and work addresses
▪️ Dates (exam, appointment, system timestamps)
▪️ Gender, age
▪️ Exam statuses (PASS, NOT APPLIED)
▪️ Job titles and workplaces
▪️ Usernames (login IDs)
▪️ MD5 password hashes
▪️ Full text of personal complaints and grievances filed by citizens
⠀
Two things stand out beyond the standard PII. First, MD5 hashes are trivially crackable for common passwords, so the credential set should be treated as effectively plaintext for any user who didn't pick something exotic. Second, the inclusion of full text citizen complaints and grievances is unusual and high-sensitivity, those records can contain anything from workplace harassment reports to disputes with public servants, and would typically carry confidentiality expectations.