CSIDB logo
Incident

Union Auction Public Company Limited

Incident posture

Attack window
Jul 2022
Location
Thailand
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
Union Auction Public Company Limited
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Union Auction Public Company Limited experienced a data breach by the DESORDEN threat actor group, which publicly claimed unauthorized access to over 30,000 personal records of the organization's members. The attackers offered free samples of the stolen data on a hacking forum while making the remainder available for purchase. No public acknowledgment or breach notification was found on the company's website, and attempts to contact them for confirmation were unsuccessful due to bounced emails and failed contact form submissions. The incident reflects broader targeting of Thai entities by cybercriminal groups seeking to monetize stolen data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around July 28, 2022, DESORDEN threat actors publicly claimed responsibility for a cyberattack against Union Auction Public Company Limited, a Thai publicly listed company. The group announced the breach on a popular hacking-related forum, offering a free sample of the stolen data while making the remainder available for purchase. DESORDEN asserted they had exfiltrated over 30,000 personal data records belonging to the company’s members, though the specific data types were not detailed in their forum post. This announcement followed a pattern of DESORDEN’s recent targeting of Thai entities, including Frasers Property Thailand and Srikrung Broker Co., Ltd., which were breached in the same timeframe. No evidence suggested ransomware deployment in this incident, consistent with DESORDEN’s stated preference for data exfiltration over encryption-based attacks.

DataBreaches.net attempted to verify the breach by checking Union Auction’s website and media sources but found no public acknowledgment or notification regarding the incident. The outlet sent an email inquiry to Union Auction requesting details about notifications or press releases, but the message bounced back as undeliverable. A subsequent attempt to contact the company through its website contact form also failed, leaving the breach unconfirmed by the victim organization. DESORDEN’s broader activities during this period included distributing ransomware builds on hacking forums after pre-submitting them to VirusTotal to reduce their effectiveness, though this tactic was unrelated to the Union Auction intrusion. The incident exemplified persistent targeting of Thai entities by multiple threat actors, with forum listings during this period advertising large datasets from Thai clinics, government agencies, and academic institutions, though DESORDEN cast doubt on one listing’s credibility by hacking the purported victim to disprove its scale.

Sources

Sources available to members: 1 source.

CSIDB