[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1uq90731abzae":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":40,"isSpamList":40,"isMalware":40,"company":41},"68e3266eda11adda488252cd","MyPertamina","MyPertamina Data Breach","mypertamina","mypertamina.id","2022-11-01T00:00:00.000Z","2024-01-27T05:19:27.000Z","2026-07-27T16:11:13.895Z","Verified third-party breach record and contemporary reporting","https:\u002F\u002Fvoi.id\u002Fen\u002Feconomy\u002F226502",[15,17,18,19,20,21],"https:\u002F\u002Fvoi.id\u002Fen\u002Ftechnology\u002F226367","https:\u002F\u002Ffinance.detik.com\u002Fenergi\u002Fd-6399218\u002Fbjorka-jual-44-juta-data-diduga-mypertamina-telkom-pertamina-investigasi","https:\u002F\u002Fwww.ruangenergi.com\u002Fpertamina-dan-telkom-investigasi-bersama-memastikan-keamanan-data-dan-informasi-mypertamina\u002F","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fmypertamina.id-2022","https:\u002F\u002Fapps.apple.com\u002Fnz\u002Fapp\u002Fmypertamina\u002Fid1295039064",5970416,"known",null,"unknown","Critical",[28,29,30,31,32,33,34],"Dates of birth","Email addresses","Genders","Names","Phone numbers","Physical addresses","Purchases","\u003Cp>The MyPertamina data breach is a high-volume personal data incident that occurred in November 2022 in digital services related to fuel payments, loyalty transactions, and user registrations within the Indonesia-based Pertamina ecosystem. Verified records track the incident date as November 1, 2022; the breach data was later added to reliable breach indexes on January 27, 2024. The record includes approximately 5,970,416 unique email addresses and claims in the news of more than 44 million raw lines. This distinction is important: the number of unique emails is a more reliable main figure for measuring user impact, while the raw line count can include multiple transactions, records, or duplicates for the same person.\u003C\u002Fp>\u003Cp>MyPertamina is a service associated with finding fuel stations, digital payment, loyalty points, purchase history, and some fuel subsidy processes. Therefore, the types of data involved in the leak are related not only to online account security but also to risks concerning daily life, such as physical address, phone number, and purchasing habits. The publicly available assessment on this page is limited to verified fields: names, email addresses, phone numbers, birth dates, gender information, physical addresses, and purchase information. Although broader identity and tax fields have been claimed in the news, these have not been added to the list of verified data categories.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The prominent types of data in the MyPertamina record are dates of birth, email addresses, gender information, names, phone numbers, physical addresses, and purchase records. The password field is not among the verified data categories for this record; therefore, the incident should not be presented as a direct password compromise. Nevertheless, the risk does not decrease; only its nature changes. When email, phone, name, address, and date of birth are combined, attempts at targeted phishing, fake support calls, delivery- or payment-themed fraud, and bypassing authentication questions become more convincing for an attacker.\u003C\u002Fp>\u003Cp>Purchase data also carries behavioral risk. Fuel or service habits can provide indirect clues about the user's location patterns, vehicle usage, and payment timing. When considered together with physical address and phone number, this information can lay the groundwork not only for digital account issues but also for harassment in the real world, fraudulent campaign calls, and social engineering scenarios. Therefore, the MyPertamina breach should be regarded as a critical record, containing a strong combination of data for personal profiling, even though it does not include passwords.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope. The raw data claim has been reported as more than 44 million rows; however, the raw row count does not mean the same as the number of unique individuals. Transaction history, duplicate records, multiple rows belonging to the same user, or different tables in the data export can increase the raw row volume.\u003C\u002Fp>\u003Cp>The incident date should be recorded as November 2022, and the addition date in the system should be kept as January 2024. If the previous technical update date or bulk import time is shown as the breach date, users may think that the leak occurred in 2025 or 2026. This confusion has been resolved in this record: the breach date is November 1, 2022, the verified index date is January 27, 2024, and the number of affected unique emails is considered to be 5,970,416. The company context should also be updated to Indonesia and energy and fuel payment service.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The first risk group consists of individuals who have opened a MyPertamina account and have used their email and phone information for fuel payments or loyalty transactions. When the name, phone number, address, and purchase context of these individuals appear together, fake customer service calls can become more convincing. The attacker may prompt the user to click a link or provide additional personal information through messages themed around fuel subsidies, payment verification, reward points, campaigns, or account renewal.\u003C\u002Fp>\u003Cp>The second risk group consists of individuals who use the same phone number for banking, e-wallets, delivery, and public services. The phone number and date of birth can be used as auxiliary information that facilitates identity verification conversations in some services. The third risk group consists of employees who open a personal MyPertamina account with their corporate email address. Such a match does not mean direct access to the company system; however, if the employee's real name, phone number, or address context is used in targeted phishing messages, the security risk increases.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users appearing in the MyPertamina registration should first carefully review messages received on their email and phone regarding fuel, payment, reward points, subsidies, or account verification. Instead of logging in through the link in the message, the known official address or mobile application of the service should be preferred. Personal identification numbers, birth dates, addresses, one-time codes, or payment information should not be shared in calls received on the phone. Genuine customer service teams should not request security codes.\u003C\u002Fp>\u003Cp>Even if it is not confirmed that the password has been leaked, strong security measures should be taken for critical accounts using the same email address. Multi-factor authentication should be enabled for email accounts, e-wallets, banking, delivery, and public services; recovery phone numbers and recovery emails should be checked. The user should close suspicious sessions, remove unrecognized devices, and clear old address or phone information from services. Date of birth and address information should now be considered easily guessable, and these details should not be used in passwords or PINs.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The MyPertamina violation shows that personal data beyond the password also has long-term security implications. Users should develop the habit of providing minimal data for each service. Unnecessary fields such as phone number, address, or date of birth should be left blank; whenever possible, email masking, separate contact addresses, and service-specific notification preferences should be used. Once personal data enters circulation, it cannot be fully retrieved; therefore, the primary defense is to prevent the same data from being used as a single security key across different accounts.\u003C\u002Fp>\u003Cp>Purchase history, phone, and address fields do not only have marketing value; when obtained incorrectly, they become a sensitive profile that fuels targeted fraud. Businesses should not collect unnecessary fields, should regularly delete old records, train customer support teams against social engineering attempts, and promptly monitor suspicious data access.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>Since the record does not contain a password, the first action should not be limited only to changing the password. The level of caution should be increased for potential fake calls, fake messages, and fake campaigns that could come through phone numbers, addresses, birth dates, and purchase information.\u003C\u002Fp>\u003Cp>The correct order is to first strengthen email and phone security, then check the account recovery settings for e-wallets, banking, delivery, and public services. The user should review unfamiliar logins on services that use the same email address as MyPertamina and remove outdated personal information from unnecessary accounts. People using corporate email should share this result with the security team; domain monitoring, risky login alerts, and employee awareness checks should be implemented on the company side.\u003C\u002Fp>","","MyPertamina Data Breach (6 Million Reported Records)","MyPertamina Data Breach. 6 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmypertamina_id.webp",false,{"name":7,"sector":42,"country":43,"website":10,"websiteArchiveUrl":36,"websiteStatus":36,"websiteCheckedAt":24},"Energy \u002F Fuel Payments","Indonesia"]