[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3h3vxcm13dy0y":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda4882523c","IndiHome","IndiHome Data Breach","indihome","indihome.co.id","2019-11-01T00:00:00.000Z","2023-11-27T07:02:10.000Z","2026-07-29T15:01:55.152Z","Third party breach","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20220821120528id_\u002Fhttps:\u002F\u002Fwww.kominfo.go.id\u002Fcontent\u002Fdetail\u002F43821\u002Fsiaran-pers-no-339hmkominfo082022-tentang-dugaan-kebocoran-data-pelanggan-layanan-indihome-pt-telkom-indonesia-persero\u002F0\u002Fsiaran_pers",[15,17,18],"https:\u002F\u002Fen.antaranews.com\u002Fnews\u002F245609\u002Fcommunication-ministry-studying-report-of-indihome-data-leak","https:\u002F\u002Fwww.marketing-interactive.com\u002Fdone-indonesian-communications-ministry-investigates-leaked-indihome-users-data-on-illegal-websites",12629245,"known",null,"email_identifiers","Critical",[25,26,27,28,29,30],"Device information","Email addresses","Genders","Geographic locations","IP addresses","Names","\u003Cp>The \u003Cstrong>IndiHome data leak\u003C\u002Fstrong> is a verified collection containing 12,629,245 unique email addresses, with its newest timestamp dated 1 November 2019.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified collection contained device information, email addresses, genders, geographic locations, IP addresses and names. The presence of \u003Cstrong>12,629,245 unique email addresses\u003C\u002Fstrong> among more than 26 million rows indicates that one person or address could appear in multiple activity records; row count and unique addresses are different measures. Combining a name, email, IP address and location increases the risk of identity matching, targeted phishing and user profiling. Device details such as browser, platform or screen characteristics may help criminals make a message appear more credible. Reports alleged passwords, phone numbers, identity documents and browsing history, but these are not separately verified data classes in this corpus and are excluded from this record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>A collection of 26,730,798 rows attributed to IndiHome was reported as posted to a hacking forum in August 2022. Review of the available copy identified 12,629,245 unique email addresses, while its newest records carried timestamps from November 2019; the catalog therefore uses 1 November 2019 as its reference date. That date does not prove when access occurred or when the incident was disclosed. It marks the latest period represented in the collection. In August 2022, Indonesia's communications authority announced that it was examining the alleged customer-data leak, would summon Telkom management for an explanation and would coordinate with the national cyber security agency. The official notice still described the incident as an allegation. Later verification provides stronger support for the corpus, but public evidence does not establish the original access method.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People whose email addresses were connected with an IndiHome account or network profile during the represented period face the greatest risk. A matching name and email address can personalise fake invoices, package upgrades, modem replacements, technical-support calls or refund messages. An IP address does not reveal an exact home address on its own, but it may indicate an approximate location, internet provider and service area. Combined with geographic and device details, it helps an attacker appear to know the recipient's city, platform or browser. Passwords are not included among the verified data classes for this record, so the confirmed corpus does not demonstrate direct password exposure. It can still support phishing designed to collect credentials or manipulate account-recovery processes. Former customers should not assume that ending service removed the risk because copied datasets may remain in circulation for years.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Review recent sign-ins, active sessions, recovery addresses and forwarding rules on the email account associated with IndiHome, then sign out devices you do not recognise. Even without a verified password field, fake support or billing messages sent to an accurate address can attempt to collect account credentials. Enable \u003Cstrong>multi-factor authentication\u003C\u002Fstrong> on email, customer and financial accounts, preferring an authenticator app or hardware security key over SMS where possible. Do not follow links in unexpected messages promising a modem replacement, speed upgrade, debt settlement or service restoration. Type the provider's address into the browser or contact a known customer-service channel independently. Unrequested one-time codes and password-reset notices may signal an account takeover attempt. If a fraudulent payment occurred, contact the bank, preserve transaction evidence and revoke active sessions.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Generate a random, different password for every service with a password manager so that a successful phishing attempt cannot spread easily to other accounts. Separating email identities by purpose keeps telecommunications, shopping and social-media memberships from being linked through one address. Update contact and recovery information in old customer profiles, and request deletion or anonymisation of accounts that are no longer required. Replace the default modem administration password, keep device firmware current and disable remote administration unless it is genuinely needed. Providers should restrict customer-data access, minimise retention periods and monitor unusual bulk exports. Store multi-factor recovery codes offline and leave account alerts enabled. Continued breach monitoring is useful because historical collections can be reposted or merged with later leaks long after the underlying service relationship ends.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Check the email address used for IndiHome with a reputable breach-search service to learn whether it appears among the 12.6 million verified addresses. A match does not mean that a device is currently compromised or that a password was definitely exposed; it confirms that the address appears in the collection attributed to the incident and calls for greater caution around targeted messages. No match is not an absolute guarantee because 26.7 million rows may contain repeated addresses, some rows may have no email field, or a different address may have been used. Never enter your email password into a breach-checking page and provide only the information needed for the lookup. Treat unexpected bills, support calls, modem requests or messages containing accurate location and device details as suspicious. Verify the sender through an independent channel, review account activity and revoke sessions if anything appears unusual.\u003C\u002Fp>","","IndiHome 2019 Data Breach (12.6 Million Email Identifiers)","The IndiHome dataset contains 12,629,245 unique emails plus names, IP, location, gender, and device data; no local corpus is imported.","\u002Fuploads\u002Flogo\u002Findihome_co_id.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Telecommunications","Indonesia"]