Tokopedia data breach (2020)
In April 2020, Indonesia's largest online store Tokopedia was breached and roughly 91 million user records — names, emails, hashed passwords, and dates of birth — were put up for sale on dark-web forums.
- Victim
- Tokopedia
- records
- 91.2M
- users
- 91.2M
On 17 April 2020, Tokopedia — Indonesia's largest e-commerce platform — disclosed that attackers had attempted to breach its systems. Within weeks, data on roughly 91 million user accounts was circulating on dark-web forums, making it one of the largest breaches in Southeast Asian history.
What happened
The breach first surfaced in March 2020, when a threat actor advertised a sample of 15 million Tokopedia user records on a hacking forum. In early May, a seller using the Empire Market marketplace offered the full database of roughly 91 million accounts for as little as USD 5,000. Tokopedia publicly acknowledged the incident, stating that while account data had been accessed, payment information and passwords remained encrypted.
The exposed records included names, email addresses, usernames, hashed passwords, dates of birth, gender, phone numbers, and registration details. Although passwords were stored as hashes, the protection proved insufficient: within days, members of the hacking community cracked and published over 200,000 plaintext passwords, sharing them for free or to premium forum users.
Impact
- Approximately 91,173,991 user accounts were exposed — nearly a third of Indonesia's population at the time.
- Cracked credentials enabled credential-stuffing attacks, since many users reused the same email/password pairs across services.
- The breach became a national flashpoint, prompting scrutiny of Indonesia's then-immature data-protection regime and accelerating calls for a comprehensive personal-data-protection law (eventually passed in 2022).
- Tokopedia urged all users to reset passwords and enable two-factor authentication.
Attribution
No actor was ever definitively confirmed, but the prolific data-trading group ShinyHunters was widely associated with the sale and redistribution of the dataset, consistent with its broader 2020 campaign of selling stolen databases from dozens of companies. Investigators never established a precise initial-access vector, though weak rate-limiting and API exposure were suspected.
Why it matters
The Tokopedia breach is a textbook case of how hashed passwords are not a guarantee of safety: weak or fast hashing algorithms can be cracked at scale within days of a leak. It also underscored the systemic risk of password reuse across a single national user base, and it became a catalyst for Indonesia's eventual data-protection legislation. For consumers, it reinforced the value of unique passwords and multi-factor authentication; for platforms, it highlighted the need for slow, salted hashing and aggressive API rate-limiting.
Timeline
A threat actor using the handle 'Whysodank' advertises data on 15 million Tokopedia users on a hacking forum.
Tokopedia confirms a data breach after attackers attempt to compromise its systems; user-account data is found exposed.
A seller offers the full 91 million-record database on the Empire Market dark-web marketplace for around USD 5,000.
Over 200,000 cracked (dehashed) account passwords are shared for free on hacking forums.
An additional tranche of records is provided to Have I Been Pwned, bringing the indexed total to roughly 91 million accounts.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Tokopedia
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/hacker-sells-91-million-tokopedia-accounts-cracked-passwords-shared/
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/tokopedia-breach-91-million/
- thejakartapost.comhttps://www.thejakartapost.com/news/2020/05/04/tokopedia-data-breach-exposes-vulnerability-of-personal-data.html