LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › PT Perusahaan Jamu Air Mancur Listed by coinbasecartel Ransomware Group

HIGH severityUnverified claimHow we verify

PT Perusahaan Jamu Air Mancur Listed by coinbasecartel Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 22, 2026
PT Perusahaan Jamu Air Mancur Listed by coinbasecartel Ransomware Group

Reported August 22, 2026.

HIGH
Severity
August 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

PT Perusahaan Jamu Air Mancur has been listed by the coinbasecartel ransomware group, with the disclosure reported on August 22, 2026. An undisclosed number of individuals may have had personal data exposed; anyone who has shared information with the company should check for notifications and consider protective steps such as monitoring accounts and updating passwords.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 22, 2026, the ransomware and extortion group coinbasecartel listed PT Perusahaan Jamu Air Mancur on its leak site. The listing is an unverified claim by that group. As of writing, PT Perusahaan Jamu Air Mancur has not publicly confirmed the claim, and independent confirmation from regulators or established breach indexes is not reflected in the available record.

Public detail is limited. The number of people who might be affected is unknown, and the listing does not set out verified inventories of files or records. For customers, partners, and staff connected to an established Indonesian herbal-medicine producer, the practical question is what a leak-site claim does and does not establish—and what cautious steps make sense if personal or business data were ever involved.

Inside the listing

According to the listing, coinbasecartel has named PT Perusahaan Jamu Air Mancur as a victim. The reported headline frames the company as listed by the coinbasecartel ransomware group. Beyond that naming and the report date of August 22, 2026, the available facts do not describe intrusion method, duration of access, ransom demands, proof packages, or a confirmed volume of material.

People affected are recorded as unknown. Data types named as exposed are not disclosed. Nothing in the provided record confirms that files were copied, published, or sold. A leak-site entry is a form of pressure and publicity used by extortion crews; it is not the same as a company admission, a regulator finding, or a forensic report. Readers should treat scale, timing of any alleged theft, and content of any alleged archive as unconfirmed unless and until authoritative sources say otherwise.

Inside coinbasecartel

coinbasecartel is known publicly as a ransomware and data-extortion actor that advertises victims on dedicated leak infrastructure. Groups in this category typically claim unauthorized access, threaten to release material if demands are not met, and use timed listings to increase pressure on named organizations. Public reporting on such crews often describes double-extortion patterns—encryption paired with alleged data theft—though tactics vary by incident and are not automatically proven by a name appearing on a site.

For this matter, only the group’s listing of PT Perusahaan Jamu Air Mancur is in the factual record. No additional claims by coinbasecartel about file counts, sample documents, or internal systems at this company are included in the facts provided. Prior notoriety of an actor does not convert an unconfirmed listing into a verified breach. The listing remains what it is: an accusation published by the group itself.

Who is PT Perusahaan Jamu Air Mancur?

PT Perusahaan Jamu Air Mancur is an Indonesian company in the traditional herbal medicine industry. Based in Solo, Central Java, it manufactures and distributes jamu—traditional Indonesian herbal remedies—along with related health and wellness products. Founded in 1963, it is one of Indonesia’s well-known herbal medicine producers and serves domestic and export markets across Southeast Asia.

Organizations in this sector commonly manage supplier and distributor relationships, manufacturing and quality records, workforce information, and customer or trade-partner contact data. A claimed incident at a long-standing consumer health brand matters because trust, continuity of supply, and handling of commercial and personal information all sit close to daily operations. That consequence follows from the company’s role and reach; it does not depend on treating the leak-site claim as proven.

The information in question

The facts state that data types named as exposed are not disclosed. It is therefore not established what, if anything, was taken. Asserting a specific inventory would go beyond the record.

If files were taken from a firm of this kind, organizations in herbal manufacturing and distribution typically hold categories such as employee records, customer or retailer contact details, procurement and logistics data, regulatory or quality documentation, and routine corporate correspondence. Those are sector norms, not a confirmed description of any archive tied to this listing. Exact contents remain unconfirmed, and the listing’s marketing language—if any appears on the actor’s site beyond the bare naming—should not be read as an audited inventory.

What's at stake

For individuals, risk is conditional. If personal data were involved in an incident of this type, common concerns include unwanted contact, phishing that references a familiar brand, and misuse of identity details where such details exist in corporate systems. Without a confirmed data set or affected count, no one can truthfully say a given person’s information is in circulation because of this listing alone.

For the organization, a public extortion listing can affect reputation, partner confidence, and operational distraction even when claims are disputed or unproven. Legal and regulatory expectations in Indonesia and in export markets may still call for careful internal assessment when a company is named in this way. None of that requires accepting the group’s narrative as fact; it reflects how leak-site pressure campaigns are designed to work.

What to do now

Because the incident is unconfirmed and details are sparse, responses should stay proportionate and conditional. Practical steps include:

Readers who want a simple check against data already circulating in known breach corpora can run a free exposure scan of their email address. A clean result does not disprove an unconfirmed claim, and a hit may relate to unrelated historical incidents; it is only one modest signal. Public detail on this listing remains limited, coinbasecartel’s naming of PT Perusahaan Jamu Air Mancur is still an unverified claim, and the company has not publicly stated the incident as of writing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPT Perusahaan Jamu Air Mancur security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See PT Perusahaan Jamu Air Mancur’s full breach history →
RelatedMore incidents at PT Perusahaan Jamu Air Mancur

More recent breaches

PT. Bank Perekonomian Rakyat Bintan Listed by coinbasecartel Ransomware GroupAugust 22, 2026Sweet Water Holdings Listed by coinbasecartel Ransomware GroupAugust 14, 2026Kementerian Pertanian Listed by coinbasecartel Ransomware GroupApril 23, 2026Longhorn Investments Listed by coinbasecartel Ransomware GroupAugust 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the PT Perusahaan Jamu Air Mancur Listed by coinbasecartel Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by coinbasecartel — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram