Data breach
Bukalapak
- Records
- 12,957,566
- Breach date
- 23 October 2017Estimated
- Added
- 4 February 2025
What was exposed
2 types of data · 5 more reported
- Usernames12,957,565
- Email addresses12,950,092
- PasswordsReported, not counted
- NamesReported, not counted
- Phone numbersReported, not counted
- Home addressesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Indonesian e-commerce company Bukalapak, one of the country's best-known online marketplaces, was hit by a data breach that our investigation team estimates occurred around October 23, 2017. The incident involved roughly 12.96 million user records. The company did not publicly confirm the event until years later, after the stolen data resurfaced for sale on hacker forums.
According to a notice published on Bukalapak's own blog, the company identified unauthorized access in March 2019 to a "cold storage" backup kept outside its main systems. That storage contained user data from 2017. CEO Rachmat Kaimuddin later told Indonesian media that the leaked material was old data the company had kept for internal purposes but failed to delete, not the active customer database.
The records also circulated among cybercriminals. In March 2019, a hacker known as Gnosticplayers offered roughly 13 million Bukalapak accounts for sale on the dark web, according to reporting by CNN Indonesia. In May 2020, sellers on the RaidForums site offered the same or similar data again, advertising about 12.9 million user records dated to 2017.
Breach Timeline
March 2019: Bukalapak identified unauthorized access to a cold storage backup containing 2017 user data, according to a notice on the company's blog.
March 2019: The hacker Gnosticplayers offered around 13 million Bukalapak accounts for sale on the dark web, as reported by CNN Indonesia.
May 4, 2020: Sellers on the RaidForums forum posted listings offering roughly 12.9 million Bukalapak user records, per The Jakarta Post.
May 6, 2020: Bukalapak's CEO said the listings involved the same data from the earlier 2019 incident and that no new breach had occurred, according to CNN Indonesia and The Jakarta Post.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames (nicknames) for about 12.96 million records and email addresses for about 12.95 million records, according to the investigation team.
Reporting on the 2019 and 2020 sales by CNN Indonesia and The Jakarta Post described additional fields in sample listings, including hashed passwords with salt values, names, phone numbers, home addresses, birth dates, and login timestamps. Bukalapak's notice states that passwords were never stored in plain text and were protected with bcrypt and salted SHA-512 hashing. Whether every field in the sellers' samples was authentic has not been independently verified.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and usernames are useful for phishing, since attackers can send convincing fake messages that appear to come from Bukalapak or other services. Password hashes can be attacked offline, especially where users chose weak or reused passwords. If any of the additional fields, such as phone numbers or birth dates, are genuine, they can support identity fraud, SIM swap attempts, and targeted scams. Criminals may also combine this data with other leaked datasets to build fuller profiles of individuals.
What Is Bukalapak Doing in Response?
In its notice, Bukalapak said it forced a mass password reset on affected accounts, required two-factor authentication for logins, moved its backup storage to a more secure location, and engaged independent external security experts. The company also said it identified and stopped the party responsible for the 2019 access. In 2020, it reiterated that customer data was safe and urged users to change passwords periodically and enable two-step verification.
What Should You Do If You Were Affected?
If you had a Bukalapak account before 2018, treat your credentials as exposed:
Change your Bukalapak password, and enable two-factor authentication if you have not already.
If you reused that password on other sites, change it there too, especially on email and banking accounts.
Watch for phishing emails or texts that reference Bukalapak, and avoid clicking links in unexpected messages.
Be cautious with unexpected calls or messages asking for personal details, since leaked data can make such scams more convincing.
In the news
- Bukalapak blog: Bukalapak Increases Security of Users' Accountsblog.bukalapak.com (opens in a new tab)
- CNN Indonesia: 13 Juta Data Bocor Bukalapak Dijual di Forum Hackercnnindonesia.com (opens in a new tab)
- The Jakarta Post: 'Our data is secure': Bukalapak denies reports of user data breachthejakartapost.com (opens in a new tab)
- Kompas: Anggota Forum Hacker Klaim Punya Data 13 Juta Akun Bukalapaktekno.kompas.com (opens in a new tab)
