[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f201i4usr08dar":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":28,"seoTitle":14,"seoTitleEn":29,"seoDescription":14,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825247","jam-tangan","Jam Tangan 2021 Data Breach","jamtangan.com","2021-07-06T00:00:00.000Z","2023-11-27T03:49:33.000Z","2026-07-29T17:57:15.135Z","Verified breach record","",[],434784,"known",null,"email_identifiers","High",[22,23,24,25,26,27],"Email addresses","IP addresses","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>\u003Cstrong>The Jam Tangan 2021 data breach\u003C\u002Fstrong> concerns customer data attributed to the Indonesia-based online watch store that was later posted to a hacking forum. A verified external breach record dates the event to July 6, 2021 and reports 434,784 unique email addresses. This is not a local import total; production has no Jam Tangan import job or locally indexed person-level corpus.\u003C\u002Fp>\n\n\u003Ch2>Which data types were confirmed?\u003C\u002Fh2>\n\u003Cp>The external record lists six data types: email and IP addresses, names, phone numbers, physical addresses, and passwords. It says some passwords were stored as unsalted MD5 hashes and others as bcrypt hashes. The source does not state how many records used each algorithm, the bcrypt cost settings, or whether every row contained all six fields.\u003C\u002Fp>\n\u003Cp>Payment cards, bank accounts, order contents, device identifiers, and identity documents are not confirmed for this record. The initial access method is also unknown. Those fields and any assumed attack technique should not be added to the data scope.\u003C\u002Fp>\n\n\u003Ch2>How should the 434,784 figure be read?\u003C\u002Fh2>\n\u003Cp>The 434,784 value is the number of unique email addresses in the verified external corpus. It is not the same measure as people, customer accounts, or source-file rows. One person can use multiple addresses, and more than one account can be associated with an address, so the figure cannot be presented directly as an affected-person count.\u003C\u002Fp>\n\u003Cp>A live production check found no related import job and no locally linked records in the email, password, phone, IP, username, identity, or general-data collections. The 434,784 value is therefore presented only as an external unique-email measure, without implying that it is a local total or imported-record count.\u003C\u002Fp>\n\n\u003Ch2>What does the source prove—and not prove?\u003C\u002Fh2>\n\u003Cp>The verified breach record supports the date, unique-email count, six fields, and two password-hash methods. The review found no operator notice, regulator record, or reliable independent report that details the event separately. The exact access time, discovery and notification dates, forum-posting date, and attack method consequently remain unknown.\u003C\u002Fp>\n\u003Cp>jamtangan.com is currently reachable and confirms the store's identity; a working company domain does not by itself prove a breach. The current company site is therefore not presented as an incident source.\u003C\u002Fp>\n\n\u003Ch2>What does this mean for account security?\u003C\u002Fh2>\n\u003Cp>Unsalted MD5 password hashes are weak against offline guessing. Bcrypt is a stronger password-hashing method, but a weak or reused password can still create risk. If a password used with Jam Tangan during this period was also used for another account, that account should receive a unique password and multi-factor authentication where available.\u003C\u002Fp>\n\u003Cp>The combination of names, phones, addresses, and emails can make targeted phishing more convincing. Instead of following links in unexpected order, coupon, delivery, or password-reset messages, users should open the service address directly. There is no verified evidence in this record that fraud, account takeover, or physical harm occurred.\u003C\u002Fp>","Jam Tangan 2021 Data Breach (434.8 Thousand Email Identifiers)","The 2021 Jam Tangan breach contains 434,784 verified unique emails. Review six data types, MD5\u002Fbcrypt password hashes, and the scope boundary.","\u002Fuploads\u002Flogo\u002Fjamtangan_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":14,"websiteStatus":37,"websiteCheckedAt":38},"Jam Tangan","E-Commerce","Indonesia","active","2026-07-29T17:48:09.000Z"]