The Indosat Ooredoo Hutchison Data Quietly Appeared on the Dark Web in Late 2023
HEROIC found 1,006 records from Indosat Ooredoo Hutchison, one of Indonesia's largest telecommunications providers, leaked on December 1, 2023. The exposed data included full names, email addresses, and bcrypt-hashed passwords, pointing to an internal database compromise. For a company managing the communications of millions of subscribers, a breach of employee or customer credentials is a serious concern for everyone whose data was recieved by bad actors.
The Danger of Telecom Credential Leaks
Telecommunications companies hold a unique position because they often manage not just customer accounts but also internal systems tied to network access, billing, and subscriber identity. When employee or customer credentials from a telecom are exposed, attackers can use them to attempt access to account management portals, redirect phone numbers through SIM swapping, or target individuals with highly personalized scams. The combination of real names and email addresses makes phishing attacks much easier to pull off convincingly.
What Was Exposed
- Email Address
- Password Hash (bcrypt)
- First Name
- Last Name
Why This Matters
Bcrypt is a strong hashing method, but it is not a guarantee of safety. If your password was short or simple, it can still be cracked. More importantly, your name and email address together are enough for attackers to launch targeted phishing emails, sign up for services in your name, or attempt account takeover on other platforms where the same credentials were used. Financial fraud and identity theft both become easier when attackers have your real name matched to your email.
How a Database Breach Works
A database breach occured when someone exploits a weakness in a company's systems to gain unauthorized access to stored data. Common methods include SQL injection, where attackers insert malicious commands into a website form, or credential stuffing, where stolen logins from other breaches are tried against a new target. Once the database is accessable, the attacker exports the records and typically posts them for sale on dark web forums. The breach at Indosat Ooredoo Hutchison appears to have followed this pattern, with data surfacing partcularly in underground marketplaces.
Check If You Are Affected
HEROIC maintains a database of over 400 billion leaked records, including data from telecom breaches worldwide. If your email was part of the Indosat Ooredoo Hutchison leak or any other breach, you can check in seconds. Visit heroic.com to run a free scan and see exactly what information of yours is out there.
Breach Breakdown
1,006 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds