← Beranda

Pemantauan insiden

Kebocoran Data Indonesia

Satu halaman untuk insiden terverifikasi (Have I Been Pwned) dan klaim lokal yang sedang diselidiki—dengan tautan sumber asli dan implikasi untuk sektor keuangan.

11
HIBP terverifikasi
5
Klaim / insiden lokal
2
Diselidiki
2
Dibantah resmi

Sumber terpercaya

Patuhdata menggabungkan kurasi editorial dengan data terverifikasi dari katalog industri.

  • Have I Been Pwned

    Katalog insiden terverifikasi oleh Troy Hunt — standar industri untuk breach yang sudah dikonfirmasi.

  • BSSN

    Badan Siber dan Sandi Negara — koordinasi insiden keamanan siber nasional. Portal CSIRT untuk pelaporan insiden.

  • Kemkomdigi

    Kementerian Komunikasi dan Digital — pengawasan ruang digital & UU PDP (sementara).

  • Brinztech

    Threat intelligence & alert kebocoran data regional.

Terverifikasi — Have I Been Pwned

Insiden berikut dikonfirmasi dan dikatalogkan oleh Have I Been Pwned (Troy Hunt)—standar industri untuk breach yang sudah diverifikasi, bukan sekadar klaim media.

HIBP terverifikasi

MyPertamina

mypertamina.id

6.0 juta akun

November 2022

In November 2022, the Indonesian oil and gas company Pertamina suffered a data breach of their MyPertamina service . The incident exposed 44M records with 6M unique email addresses along with names, dates of birth, genders, physical addresses and purchases.

Data terdampak: Dates of birth · Email addresses · Genders · Names · Phone numbers · Physical addresses · …

Detail di Have I Been Pwned
HIBP terverifikasi

Travelio

travelio.com

471 ribu akun

November 2021

In November 2021, the Indonesian real estate website Travelio suffered a data breach that exposed over 470k customer accounts . The data included email addresses, names, password hashes, phone numbers and for some accounts, dates of birth, physical address and Facebook auth tokens.

Data terdampak: Auth tokens · Dates of birth · Email addresses · Names · Passwords · Phone numbers · …

Detail di Have I Been Pwned
HIBP terverifikasi

Qraved

qraved.com

985 ribu akun

Juli 2021

In July 2021, the Indonesian restaurant website Qraved suffered a data breach that was later redistributed as part of a larger corpus of data . The breach exposed almost 1M unique email addresses along with names, phone numbers, dates of birth and passwords stored as MD5 hashes.

Data terdampak: Dates of birth · Email addresses · Names · Passwords · Phone numbers

Detail di Have I Been Pwned
HIBP terverifikasi

Jam Tangan

jamtangan.com

435 ribu akun

Juli 2021

In July 2021, the online Indonesian watch store, Jam Tangan (AKA Machtwatch), suffered a data breach that exposed over 400k customer records which were subsequently posted to a popular hacking forum. The data included email and IP addresses, names, phone numbers, physical addresses and passwords stored as either unsalted MD5 or bcrypt hashes.

Data terdampak: Email addresses · IP addresses · Names · Passwords · Phone numbers · Physical addresses

Detail di Have I Been Pwned
HIBP terverifikasi

Lazada RedMart

redmart.lazada.sg

1.1 juta akun

Juli 2020

In October 2020, news broke of Lazada RedMart data breach containing records as recent as July 2020 and being sold via an online marketplace. In all, the data contained 1.1 million customer email addresses alongside names, phone numbers, physical addresses, partial credit card numbers and passwords stored as SHA-1 hashes.

Data terdampak: Email addresses · Names · Partial credit card data · Passwords · Phone numbers · Physical addresses

Detail di Have I Been Pwned
HIBP terverifikasi

Kreditplus

kreditplus.com

769 ribu akun

Juni 2020

In June 2020, the Indonesian credit service Kreditplus suffered a data breach which exposed 896k records containing 769k unique email addresses. The breach exposed extensive personal information including names, family makeup, information on spouses, income and expenses, religions and employment information. The data was provided to HIBP by breachbase.pw .

Data terdampak: Dates of birth · Email addresses · Employers · Family structure · Genders · Income levels · …

Detail di Have I Been Pwned
HIBP terverifikasi

Tokopedia

tokopedia.com

71.4 juta akun

April 2020

In April 2020, Indonesia's largest online store Tokopedia suffered a data breach . The incident resulted in 15M rows of data being posted to a popular hacking forum. An additional 76M rows were later provided to HIBP in July 2020. In total, the data included over 71M unique email addresses alongside names, genders, birth dates and passwords stored as SHA2-384 hashes.

Data terdampak: Dates of birth · Email addresses · Genders · Names · Passwords

Detail di Have I Been Pwned
HIBP terverifikasi

Bhinneka

bhinneka.com

1.3 juta akun

Januari 2020

In early 2020, the Indonesian consumer electronics website Bhinneka suffered a data breach that exposed almost 1.3M customer records . The data included email and physical addresses, names, genders, dates of birth, phone numbers and salted password hashes.

Data terdampak: Dates of birth · Email addresses · Genders · Names · Passwords · Phone numbers · …

Detail di Have I Been Pwned
HIBP terverifikasi

IndiHome

indihome.co.id

12.6 juta akun

November 2019

In mid-2021, reports emerged of a data breach of Indonesia's telecommunications company, IndiHome . Over 26M rows of data alleged to have been sourced from the company was posted to a popular hacking forum and contained 12.6M unique email addresses alongside names, IP addresses, genders and geographic locations. The most recent data was stamped as being recorded in November 2019.

Data terdampak: Device information · Email addresses · Genders · Geographic locations · IP addresses · Names

Detail di Have I Been Pwned
HIBP terverifikasi

Youthmanual

youthmanual.com

938 ribu akun

Januari 2019

In January 2019, the Indonesian college and career platform Youthmanual suffered a data breach that exposed 1.1M records of data . The breached included 938k unique email addresses along with extensive personal information including names, genders, dates and places of birth, phone numbers, physical addresses and salted SHA-1 password hashes.

Data terdampak: Bios · Dates of birth · Email addresses · Genders · Names · Passwords · …

Detail di Have I Been Pwned
HIBP terverifikasi

Bukalapak

bukalapak.com

13.4 juta akun

Oktober 2017

In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017 . The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes.

Data terdampak: Email addresses · IP addresses · Names · Passwords · Usernames

Detail di Have I Been Pwned

Data breach dikutip dari Have I Been Pwned (Troy Hunt). Diperbarui otomatis setiap 24 jam. Hanya insiden yang relevan untuk ekosistem Indonesia (domain .id & layanan populer di Indonesia).

Klaim & insiden lokal (kurasi Patuhdata)

Berita Indonesia 2025–2026 yang mungkin belum masuk HIBP—dari media, pemerintah, dan komunitas keamanan siber.

Kurasi lokal Patuhdata — insiden dan klaim kebocoran di Indonesia dari media & instansi (belum tentu ada di HIBP). Terakhir diperbarui: 17 Mei 2026.

Patuhdata mengkurasi insiden Indonesia dari media, pemerintah, dan threat intelligence—dipadukan dengan insiden terverifikasi Have I Been Pwned untuk layanan relevan. Status dapat berubah. Bukan daftar resmi regulator; bukan opini hukum.

Klaim kebocoran data imigrasi / eVisa di dark web

Pemerintah · Imigrasi

Dibantah instansi terkait

Beredar klaim peretasan sistem eVisa dan penjualan data paspor/visa. Ditjen Imigrasi menyatakan informasi hoaks dan mengusut penyebar klaim.

Catatan status: Ditjen Imigrasi membantah kebocoran; penyelidikan penyebar hoaks berjalan.

Skala klaim
Klaim ~3 juta
Jenis data
Paspor · Visa · Identitas perjalanan

Sumber

Implikasi sektor keuangan

Mengingatkan institusi keuangan untuk memverifikasi klaim breach sebelum komunikasi publik, dan menguji apakah data KYC/perjalanan nasabah terpapar.

Data pengguna Instagram diduga bocor (skala global)

Platform digital · Sosial media

Klaim belum diverifikasi

Laporan media tentang dataset besar pengguna Instagram yang disalahgunakan untuk doxxing dan pemerasan. Dampak langsung ke pengguna Indonesia yang memakai platform yang sama.

Catatan status: Klaim dari laporan keamanan/media; verifikasi resmi platform bervariasi.

Skala klaim
Klaim ~17,5 juta akun
Jenis data
Username · Profil · Metadata akun

Implikasi sektor keuangan

Risiko credential stuffing, social engineering, dan pemulihan akun nasabah yang memakai email/telepon terhubung Instagram.

Diduga kebocoran database penduduk Kota Bandung

Pemerintah daerah

Sedang diselidiki

Komunitas keamanan siber melaporkan dataset warga Kota Bandung di forum underground. Pihak daerah dan aparat menyelidiki validitas klaim.

Catatan status: Laporan VECERT / media keamanan; investigasi pemerintah daerah berlangsung.

Skala klaim
Klaim >1 juta
Jenis data
NIK · Nama · Alamat · Kontak

Sumber

Implikasi sektor keuangan

Data identitas daerah sering dipakai untuk verifikasi alamat/KYC tiruan—perkuat deteksi fraud onboarding.

Klaim database nasional warga Indonesia di underground

Nasional · Multi-sektor

Sedang diselidiki

Intelligence keamanan siber melaporkan paket data besar berisi identitas dan kontak warga. Belum ada konfirmasi resmi terpusat; investigasi lintas instansi.

Catatan status: Klaim dari komunitas threat intelligence; instansi pusat menyelidiki.

Skala klaim
Tidak diverifikasi
Jenis data
NIK · NPWP · Nama · Alamat · Tanggal lahir · Telepon

Sumber

Implikasi sektor keuangan

Jika terbukti, memperbesar risiko penipuan identitas, pembukaan rekening palsu, dan social engineering terhadap nasabah.

Klaim kebocoran data siswa skala nasional

Pendidikan · Pemerintah

Dibantah instansi terkait

Viral di dark web mengenai data siswa Indonesia. Pemerintah membantah indikasi kebocoran; Kemendikbud, BSSN, dan Kemkomdigi melakukan investigasi.

Catatan status: Menko PMK dan kementerian terkait membantah; investigasi teknis berlanjut.

Skala klaim
Klaim ~58 juta
Jenis data
Identitas siswa · Data pendidikan

Implikasi sektor keuangan

Menunjukkan sensitivitas publik terhadap data anak/remaja—relevan untuk produk finansial remaja dan verifikasi usia.

Butuh kesiapan insiden & UU PDP?

Gap assessment memetakan kontrol insiden, vendor, dan bukti audit sebelum tekanan regulator atau mitra B2B meningkat.

Koreksi atau laporan insiden baru? support@patuhdata.id · Status Badan PDP

Chat dengan kami di WhatsApp
1