Hacker Sells 91 Million Tokopedia User Records on Dark Web
A cybercriminal is selling a massive database of 91 million Tokopedia users for just $5,000, and other attackers are already cracking and sharing the exposed passwords online.
A hacker sells a database containing the personal information of 91 million Tokopedia users on a dark web marketplace for as little as $5,000. Tokopedia is Indonesia's largest online store, and the stolen data originates from a breach that occurs in March 2020. The cybercriminal initially offers a smaller subset of 15 million accounts on a hacker forum before selling the complete 91 million record database, which reportedly sells twice.
The exposed database contains a variety of personal user fields, with the most severe data including full names, email addresses, birth dates, and hashed passwords. Some of the compromised accounts also include mobile phone numbers. While the passwords are hashed rather than stored in plain text, other threat actors quickly begin cracking these passwords and sharing the decrypted credentials online.
Tokopedia's VP of Corporate Communications states that the company conducts a thorough investigation into the data leak with the help of Indonesian government cybersecurity agencies. The company emphasizes that user data security remains its utmost priority and confirms that it actively enhances its security systems to maintain customer trust in the wake of this massive breach.