[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3u4zvle7q1htr":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488253e0","Tokopedia","Tokopedia Data Breach","tokopedia","tokopedia.com","2020-04-17T00:00:00.000Z","2020-05-02T23:45:21.000Z","2026-07-27T16:11:14.702Z","Verified breach record","https:\u002F\u002Fcyberscoop.com\u002Findonesian-e-commerce-giant-probes-reported-breach-91-million-credentials\u002F",[15,17,18],"https:\u002F\u002Fsecurityaffairs.com\u002F102666\u002Fdata-breach\u002Ftokopedia-hacked.html","https:\u002F\u002Fwww.tokopedia.com\u002F",71443698,"known",null,"unknown","Critical",[25,26,27,28,29],"Dates of birth","Email addresses","Genders","Names","Passwords","\u003Cp>The Tokopedia data breach is a verified account security incident from April 2020 that affected the Indonesia-based major e-commerce marketplace. The incident exposed customer data associated with 71,443,698 unique email addresses. The confirmed data categories include dates of birth, email addresses, gender information, full names, and password hash values. Passwords are in SHA2-384 hash format; this does not mean plain text passwords, but the risk continues for weak or reused passwords. Individuals with a Tokopedia account who use the same email address for other shopping or payment services and have not changed their old password face significant risk of phishing and account takeover attempts.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In this incident, identity data such as email address, full name, gender, and date of birth were exposed along with password hash values. The combination of email and full name makes fake campaign, order, return, shipping, or store account messages more convincing. Date of birth and gender information help attackers create personalized messages. Although password hash values are protected with SHA2-384, if the same password is reused on different services, attackers may try cracked or guessed passwords on other sites. Therefore, the risk should not be seen as limited to the Tokopedia account alone; other shopping, payment, social media, and email accounts using the same email address should also be considered.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The breach date is tracked as April 17, 2020, the initial listing date as May 2, 2020, and the update date as July 17, 2020. The main scope used by LeakData is 71,443,698 unique email addresses. Some reports mention an initial file of 15 million rows and later claim around 91 million raw records; these numbers may differ from the unique email scope due to duplicate rows, missing fields, or non-email records. The number presented to the user on this page is the unique email address scope that is meaningful as a search result. Verified classes are limited to date of birth, email, gender, name, and password hash values; payment instrument data is not included within this search scope.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The risk is highest for people who opened a Tokopedia account before 2020, used shopping or seller services, used the same email address for other services, and repeated their password. Users associated with Indonesia-based e-commerce services should be more cautious about messages related to order status, returns, payment confirmation, account verification, and promotional coupons. For those with a seller account, the risk may increase through customer messages, the store panel, payment notifications, and fake support requests. If the same email address is also used for a bank, courier, social media, or work account, attackers can combine this information for account attempts and targeted phishing.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>The password for a Tokopedia account or any other accounts opened with the same password should be changed immediately. A unique, long, and random password should be preferred for each account, a password manager should be used, and multi-factor authentication should be enabled for critical accounts. Emails regarding orders, shipping, discounts, returns, account locking, or payment verification should be examined carefully. Instead of clicking on links in the message, the official domain should be typed manually, and one-time codes should not be shared with anyone via phone or message. People using a seller account should also check store panel sessions, authorized devices, and payment settings. If there is a suspicious login notification, sessions should be closed and the password reset process should be initiated through a trusted channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Persistent risk in e-commerce violations arises from the use of customer profile data along with password lists and phishing messages. Users should regularly review old store accounts, close unused accounts, reduce marketing permissions, and use additional verification on critical accounts created with the same email address. From an institutional perspective, customer data should be kept to a minimum, password hash algorithms should be strong and up-to-date, salts and additional protection controls should be applied, and unusual exports and high-volume queries should be monitored with early warning systems. User notifications should be prepared in clear, dated language that explicitly explains data categories, so that users know which accounts to check.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>You can check whether your email address matches the Tokopedia data breach by querying it on LeakData. If there is a match, first prioritize your Tokopedia account, then other accounts using the same email or the same password. Along with changing your password, it is important to enable multi-factor authentication, check session history, and remove authorizations for old devices. Be more suspicious of messages containing personal details due to the exposure of your date of birth and name information. For unexpected delivery, return, account verification, or campaign links, open the official website yourself before entering your information. These steps reduce the likelihood that the 2020-sourced data will be used today for account testing, fake purchase notifications, and targeted fraud.\u003C\u002Fp>","","Tokopedia Data Breach (71.4 Million Reported Records)","Tokopedia Data Breach. 71.4 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ftokopedia_com.webp",false,{"name":7,"sector":37,"country":38,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":21},"E-commerce and online marketplace","Indonesia"]