Tokopedia data breach

Tokopedia

What Happened

In April 2020, Indonesia’s largest e-commerce platform Tokopedia suffered a major data breach that exposed approximately 71-91 million user records. The breach, which occurred on March 20, 2020, initially resulted in 15 million records being posted to a hacking forum, but hackers later claimed to have stolen a much larger dataset of 91 million accounts, which they sold on the dark web for as little as $5,000. The exposed data included email addresses, names, dates of birth, genders, and password hashes (stored as SHA2-384 encryption), along with some mobile phone numbers. While Tokopedia initially claimed that passwords remained encrypted and secure, threat actors subsequently began cracking and sharing dehashed passwords on hacking forums. The company acknowledged the breach in early May 2020 and advised users to change their passwords and implement additional security measures like one-time passwords (OTP).

Compromised Assets

  • user id
  • username
  • email
  • password
  • status
  • full name
  • gender
  • birth date
  • location
  • order id
  • messenger
  • flag_email
  • flag_messenger
  • flag_birthdate
  • flag_hp
  • flag_img
  • occupation
  • company name
  • schools
  • hobbies
  • relationship
  • activation_code
  • about_me
  • last_login
  • deposit
  • create_by
  • create_time
  • update_by
  • update_time
  • email_new
  • email_cancel_code
  • email_confirm_code
  • reset_password_code
  • profile_effective_date
  • status_data
  • shop_info
  • lang
  • user_pwd_1
  • uniq_chari

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.

Related Breaches