[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftfhi01ji8mx8":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":41,"isSensitive":4,"isSpamList":41,"isMalware":41,"company":42},"6a46cfab5e9c2cc7bdce5f47","VivaHealth.co.id 2023","VivaHealth.co.id (2023) Alleged Data Exposure","vivahealth-co-id-2023","vivahealth.co.id","2023-08-06T00:00:00.000Z","2026-07-02T20:52:59.841Z",null,"2026-09-17T16:27:41.515Z","2026-07-19T00:10:06.584Z","Third party breach","",[],3091780,"known","email_identifiers","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"Critical",[30,31,32,33,34,35,36],"Email addresses","Names","Phone numbers","Dates of birth","Physical addresses","Password hash metadata","Passwords","\u003Cp>The VivaHealth.co.id data breach is a critical customer account incident associated with the domain vivahealth.co.id, based in Indonesia, within the scope of health and retail services, dated August 2023. This record was added as a single incident supported by a volume of 3,091,780 records. The record contained email addresses, names, phone numbers, dates of birth, physical addresses, password hash information, and passwords; unsupported detailed health content, payment card, bank account, or official ID claims were excluded to avoid misleading the user.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In the verification assessment, the name VivaHealth.co.id, the domain vivahealth.co.id, the time of August 2023, the record volume of over 3.09 million, and the customer ID\u002Fcontact fields along with hashed password information were taken into account. To avoid confusion with similarly named healthcare institutions in other countries, the record was limited to the Indonesian domain and the 2023 event. Data classes were written only according to the supported fields; although it is in the context of healthcare services, it was not expanded as if there were detailed health content.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The VivaHealth.co.id data breach poses the risk of account takeover, health\u002Fretail-themed phishing, and delivery scams for users. When name, phone, email, date of birth, and address fields are combined, attackers can craft notifications that appear to be genuine customer support messages. Password hash information increases the risk of the same or weak passwords being tried on other accounts. Users are more likely to trust messages about appointments, products, over-the-counter purchases, deliveries, or promotions from brands associated with health or pharmacies.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>In this incident, visible data classes are important both for account security and social engineering. The date of birth can be misused in support desk verifications. The physical address makes delivery or return pretexts more convincing. The phone number facilitates targeting via text message and calls. Hashed password data carries an offline guessing risk for weak, short, or reused passwords. Therefore, the incident should not be evaluated solely as a contact list.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Individuals who have a VivaHealth.co.id account or use the same email address should renew their passwords on the relevant account and on other accounts using the same password. Email, shopping, delivery, payment, social media, and healthcare service accounts should be checked as a priority. Multi-factor authentication should be enabled wherever possible, old sessions should be closed, and unexpected login alerts should be examined. Delivery, campaign, account verification, or product return links should be checked directly through known official channels.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>From the perspective of institutions, the VivaHealth.co.id data breach shows that password storage and customer verification processes in health and retail customer accounts need to be evaluated together. Support teams should not approve transactions with only a name, phone number, address, or date of birth. Additional verification is required for address changes, account recovery, contact information updates, and delivery routing. Official domain names, fake message reporting methods, and secure password reset steps should be clearly communicated to users.\u003C\u002Fp>\u003Cp>The scope of the VivaHealth.co.id data breach record was limited to supported areas. The record was kept as 3,091,780 customer records; no claim of detailed health content, payment card, bank account, or official identification document was added. Nevertheless, the combination of email, phone, date of birth, address, and hashed password poses a critical account security risk. In the context of the health brand, users need to pay special attention, as this could help attackers make their messages appear more trustworthy.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The overall risk level has been assessed as critical; because the VivaHealth.co.id data breach combines a large volume of customer communication data with date of birth, address, and password hash information. The most practical steps for users searching for the VivaHealth.co.id data breach are to renew passwords, avoid repeating the same password, enable additional verification on email and shopping accounts, independently verify delivery and campaign links, and not trust messages prepared with personal information. The record has been prepared to explain the actual security impact without adding unsupported health or financial claims.\u003C\u002Fp>","VivaHealth.co.id (2023) Alleged Data Exposure (3.1 Million Email Identifiers)","VivaHealth.co.id (2023) Alleged Data Exposure. 3.1 Million email identifiers are reported. Reported data: Email addresses, Names, Phone numbers. Review the…","\u002Fuploads\u002Flogo\u002Fvivahealth-co-id-2023.svg",false,{"name":43,"sector":44,"country":45,"website":10,"websiteArchiveUrl":17,"websiteStatus":17,"websiteCheckedAt":13},"VivaHealth.co.id","Healthcare retail \u002F Pharmacy services","Indonesia"]