Menu
Browse

Cyber Incident Victim: Bukalapak

Date:

Feb 2018

Location:

Indonesia

Summary

A major e-commerce platform experienced a breach involving compromised user data, including usernames, email addresses, encrypted passwords, names, dates of birth, IP addresses, geographic locations, and website activity. Approximately 13 million user records were listed for sale on a dark web forum, with claims that 0.3 million email-password pairs had been cracked. The company denied any new breach, attributing the incident to an earlier attempted intrusion and asserting that no essential data such as passwords or financial information was stolen. However, the exposed dataset contradicted these claims by containing extensive personal details. The firm maintained that its systems remained secure despite evidence of the data being circulated.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early May 2020, reports emerged that a database containing approximately 13 million Bukalapak user records was listed for sale on RaidForum by an account named 'STARTEXMISLEAD.' The listing, dated May 4, 2020, claimed the data originated from February 2018 and included email addresses, IP addresses, names, usernames, dates of birth, geographic locations, website activity, and passwords encrypted with SHA-512/BCRYPT hashing. A subsequent May 8, 2020 listing by 'Megadimarus' added that 0.3 million email-password pairs had been cracked. Sample records showed extensive user details, including contact information, encrypted credentials, and timestamps from 2017. This incident followed closely after a reported breach at Tokopedia, another Indonesian e-commerce platform, raising concerns about systemic vulnerabilities.

Cyber Incident Image

Bukalapak's corporate communications head, Intan Wibisono, denied any new breach, attributing the circulating reports to a 2019 hacking attempt by suspected threat actor GnosticPlayers. The company maintained that no essential data—including passwords, personal identifiers, or financial information—had been compromised during that 2019 incident. However, the RaidForum listings directly contradicted these claims by specifying the extraction date as February 2018 and detailing extensive personal information exposure. The discrepancy remained unresolved, with Bukalapak reiterating its data security assurances while external evidence indicated potential unauthorized access to sensitive user attributes two years prior. No further investigative findings or remediation steps were disclosed by the company beyond these public statements.

Sources
Sources available to members
1 source