Source: Kompas Tekno

A data breach affecting 91 million accounts on Indonesia’s most prominent e-commerce platform Tokopedia has raised questions about when the country’s parliament will finally enact a law on data and privacy protection.
The hack affecting Tokopedia’s 91 million active accounts shows how serious the data protection problem in Indonesia, making the law an urgent matter.
Siber Indonesia Communication & Information System Security Research Center (CISSReC), a research firm specialising in cybersecurity, warned that online and offline personal data are prone to be misused by unscrupulous parties.
“The most crucial thing is, personal data has not been protected,” CISSReC chairman Pratama Persadha said in a statement on 4 May.
While Tokopedia was supposed to be accountable for the data leak, such a thing may not occur, as there is no data privacy law, making Tokopedia users’ data prone to cybercrimes such as phishing.
Tokopedia data breach: The chronology
The Tokopedia data breach was first spotted when a hacker nicknamed Whysodank published his hacking result in Raid Forum, an internet forum containing information related to database and data leak, Bisnis wrote.
Another hacker under the nickname ShinyHunter uploaded the sale thread of 91 million accounts of Tokopedia users in Empire Market, one of the dark web forums. From there, the account @underthebreach published the hacking of Tokopedia on Twitter.
Pratama warned that the data leak affecting Tokopedia could spread to other social media platforms if users use the same ID and password, calling on the government’s social media officers to take precautionary actions to protect their accounts.
What is in the draft Bill on data and privacy protection?
On 24 January, President Joko Widodo signed the draft Bill on data protection, which was supposed to be discussed with the parliament after the Omnibus Law.
There are three main points in the draft Bill, as Minister of Communication and Information Johnny G. Plate elaborated: Data sovereignty, data ownership related to personal data or other specific types of data, and data traffic management, KataData reported.
The draft Bill defines personal data as any data about an individual, which is identified separately or can be combined with other information either directly or indirectly, through both electronic and manual systems.
Those who violate or misuse personal data will face a seven-year jail term or pay a fine up to Rp 70 billion.
If there is a failure in data protection, personal data controllers are obliged to inform data owners or supervising agencies within 14 days.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

Indonesian teen defeats world surfing champ Medina in Bali

An Indonesian teenager pulled off a stunning upset Monday by defeating two-time…

West Java to impose large-scale social distancing at provincial level to contain COVID-19 pandemic

Indonesia’s West Java province will expand the implementation of large-scale social distancing…

QuaDream’s spyware operated from several Countries, including Singapore, and used against minority politicians and journalists, reports show

Recent reports from Microsoft and Citizen Lab have revealed that QuaDream, an Israeli spyware company, operated its hacking tools from several countries, including Singapore, and used them against minority-party politicians and journalists. Citizen Lab’s report identified at least five civil society victims of QuaDream’s spyware and exploits, including journalists, political opposition figures, and an NGO worker. The report also highlighted a suspected iOS 14 zero-click exploit used to deploy QuaDream’s spyware, which appears to make use of invisible iCloud calendar invitations sent from the spyware’s operator to victims.

TraceTogether app was inspired by US high school project, GovTech invited student to support its development

With doubts and questions revolving around the TraceTogether mobile application that was…