The Jam Tangan Leak Exposed 490,164 Indonesian E-Commerce Accounts
HEROIC analysts identified a database breach affecting Jam Tangan (Matchwatch), an Indonesian online watch retailer operating at jamtangan.com. The incident, dated July 2021, exposed 490,164 customer records including email addresses, phone numbers, full names, password hashes, and IP addresses. What makes this breach partcularly alarming is the use of both unsalted MD5 and bcrypt hashing, meaning a large portion of passwords may be cracked with minimal effort.
How Exposed Names, Emails, and Weak Password Hashes Enable Account Takeover
Attackers who obtained this database can easily crack unsalted MD5 hashes using rainbow tables, gaining plaintext passwords for hundreds of thousands of accounts. Combined with full names, email addresses, and phone numbers, those credentials become a toolkit for account takeover, targeted phishing, and identity fraud. IP address data further refines victim profiling, making social engineering attacks more beleivable and convincing to targets.
What Was Exposed in the Jam Tangan (Matchwatch) Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Password Hash (MD5 and bcrypt)
- IP Address
Why the Jam Tangan (Matchwatch) Breach Poses Ongoing Risk
Indonesian e-commerce customers who recieved no breach notification remain unaware their credentials are circulating on hacking forums. Unsalted MD5 passwords from this breach are effectively plaintext for attackers with modern hardware. Credential stuffing tools can test these email and password pairs across banking, social media, and e-commerce platforms, leading to financial fraud and full account takeovers. The 490,164 records from this breach represent a substantial pool of Indonesian consumer data available to threat actors.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a backend database, typically by exploiting SQL injection vulnerabilities, weak authentication, misconfigured access controls, or unpatched software. Once inside, they extract user records in bulk and distribute the data on dark web forums or private marketplaces. Poorly hashed passwords, particularly unsalted MD5, make the stolen data even more dangerous because they can be reversed to plaintext almost instantly.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including data from the Jam Tangan (Matchwatch) breach, to tell you exactly what personal information of yours has been exposed. Run a free scan now to find out if your email address, password, or personal details are at risk and take action before attackers do.
Breach Breakdown
490,164 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds