[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f27jt5pakjrt1j":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda4882512d","Bukalapak","Bukalapak Data Breach","bukalapak","bukalapak.com","2017-10-23T00:00:00.000Z","2019-04-18T01:57:35.000Z","2019-04-18T02:10:15.000Z","2026-07-20T09:04:53.146Z","Database leak","https:\u002F\u002Fwww.bukalapak.com\u002Fblog\u002Ffeature-updates\u002Fpetunjuk-teknis-105502",[16,18,19,20,21],"https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fbukalapak-2017","https:\u002F\u002Fwww.thejakartapost.com\u002Fnews\u002F2020\u002F05\u002F08\u002Four-data-is-secure-bukalapak-denies-reports-of-user-data-breach","https:\u002F\u002Fen.tempo.co\u002Fread\u002F1339523\u002Fbukalapak-denies-alleged-data-breach-on-dark-web","https:\u002F\u002Fvoi.id\u002Fen\u002Ftechnology\u002F5567\u002F",13369666,"known",null,"unknown","Critical",[28,29,30,31,32],"Email addresses","IP addresses","Names","Passwords","Usernames","\u003Cp>The \u003Cstrong>Bukalapak data breach\u003C\u002Fstrong> is a verified record involving 13,369,666 unique email addresses from backups dated 23 October 2017.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified corpus contained email addresses, usernames, IP addresses, names and \u003Cstrong>password hashes protected with bcrypt and salted SHA-512\u003C\u002Fstrong>. There is no evidence that plaintext passwords were distributed, but strong hashing does not remove the risk created by weak or reused passwords. Forum listings also claimed fields such as addresses, birth dates or phone numbers, but those fields are not added because they were not sufficiently established in the canonical data classes. The figure of 13,369,666 measures unique email addresses; it is not a total row count, the full Bukalapak user population or the number affected by every field.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The record relates to Bukalapak backup data dating through 23 October 2017. The incident was discovered in March 2019 and added to public breach catalogues in April 2019. The initial access method, exploited weakness and exact system from which the backup was removed have not been confirmed, so no detailed attack vector is stated as fact. In May 2020, the reappearance of approximately 13 million Bukalapak records was interpreted as a new incident. The company said its investigation found that the circulating reports came from the previous year’s attempt and that no new breach had occurred. A separate 91 million-record dataset reported around the same period belonged to another Indonesian e-commerce platform and must not be added to Bukalapak’s total.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The greatest risk applies to people who had a Bukalapak account before late 2017 and reused the same password on other services. Someone who closed or abandoned the account years ago may still be exposed because an email address, username and password hash can continue circulating without changing. Short, predictable or dictionary-based passwords are weaker against offline guessing even when protected with bcrypt or salted SHA-512. Risk increases if the same password protected the email account, since email access can expose password-reset links for many services. Records containing a name and IP address are more useful for targeted phishing that refers to a location or past shopping activity. A match does not mean that payment cards, bank accounts or identity documents were exposed; those fields are not among the verified data classes.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you remember the password used for Bukalapak in 2017, identify every account that still uses the same or a similar password. Starting with email, banking, shopping and social accounts, create a long \u003Cstrong>unique password\u003C\u002Fstrong> for every service; a trusted password manager makes reuse easier to eliminate. Enable two-step verification on Bukalapak and the email account, then review active sessions and connected devices. Check the email recovery address, phone number and forwarding rules for changes you do not recognise. Do not respond to a message that uses a Bukalapak order, refund, seller payment or breach compensation as a reason to request a password, one-time code or payment. Open the application or type the official address yourself instead of following the supplied link. If a failed sign-in alert, unexpected password reset or new-device notice appears, change the relevant password immediately and close other sessions. Preserve the date and sender details of suspicious contact and report it to the service provider.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Old credentials taken from backups can circulate for years, so protection should not end when attention to the incident fades. Use password-manager security reports to replace reused, weak or previously exposed passwords on a regular schedule. Treat the email account as the centre of your digital identity and protect it with a strong password, two-step verification and current recovery options. If one username is used across many platforms, remember that attackers may connect those accounts. A shopping message that correctly states a name or order detail is not automatically trustworthy; verify it independently against order history in the application. Before closing an unused account, remove saved payment methods, connected applications and unnecessary profile fields. Backup retention and access policies need the same protection as production systems. When another Bukalapak claim appears, compare its date, unique-account total and exposed fields to determine whether it is a new event or a recirculation of old data.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search LeakData.io with the email address used for Bukalapak around 2017 to check whether it matches this record. A match shows that the address exists in the verified corpus; it does not mean that a username, IP address, name and password hash were all complete in the same record. An empty result does not prove that no account created with another address is present, so check old work and personal addresses separately. Never provide a password, password hash, one-time code, payment information or identity document in response to a search result. If a match appears, prioritise removing old password reuse, securing the email account and enabling two-step verification. Do not add the Bukalapak sale listings from 2020 to the total as a separate 13 million-account incident. Likewise, do not attach the 91 million-record figure belonging to another platform to this record. Keeping incident and measurement boundaries separate prevents the risk from being exaggerated or assigned to the wrong organisation.\u003C\u002Fp>","","Bukalapak Data Breach (13.4 Million Reported Records)","Bukalapak Data Breach. 13.4 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fbukalapak_com.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":24},"E-commerce marketplace","Indonesia"]