data leak
Indonesian Tax Data Breach: 100,000 NPWP Records Dumped Online by K3LLLEAKERS, Is Anyone Safe?
> By Haider | Aug 30, 2026 | 7 min read
An alarming Indonesian Tax Data Breach has surfaced on the cyber underground after hacktivist threat group K3LLLEAKERS publicly dumped a massive database containing over 100,000 detailed records allegedly exfiltrated from Indonesia’s Directorate General of Taxes (Direktorat Jenderal Pajak (pajak.go.id)). The exposed archive contains deeply sensitive personal and financial identifiers, including national tax numbers (NPWP), full citizen names, complete residential street addresses, personal telephone numbers, email addresses, professional occupations, and real-time tax compliance statuses across all major Indonesian provinces.

> TABLE_OF_CONTENTS [toggle]
- > The Anatomy of the Indonesian Tax Data Breach
- > Exposed Intelligence Fields: 100,000 Verified Citizen Records
- > Forensic Impact: Identity Theft, Corporate Phishing, and Smishing Risks
- > Threat Actor Profile: The Emergence of K3LLLEAKERS
- > Actionable Defense: Emergency Mitigations for Taxpayers and DJP
- > Frequently Asked Questions
The Anatomy of the Indonesian Tax Data Breach
The leak was broadcast via the threat actor’s official Telegram dispatch channel, where K3LLLEAKERS posted direct download mirrors hosting a 100,002-line CSV file titled DATABASE_www.pajak.go.id.csv. Unlike typical low-level scrapes that only aggregate publicly visible forum usernames, this Indonesian Tax Data Breach presents structured government-tier database exports containing authenticated administrative tax parameters.
CyberAsia researchers inspected raw sample fragments from the 100,000-line database dump. The schema structure indicates that the data was extracted from a consolidated internal taxpayer registry or regional tax service office (Kantor Pelayanan Pajak: KPP) management cluster, containing both individual taxpayers (Orang Pribadi) and corporate entity accounts (Badan). The revelation of this Indonesian Tax Data Breach highlights persistent perimeter vulnerabilities in central financial repositories.

Exposed Intelligence Fields: 100,000 Verified Citizen Records
A comprehensive forensic audit of the compromised dataset confirms the unprecedented scope of this Indonesian Tax Data Breach across a 13-column relational database architecture. Every single row in the 100,000-line repository captures granular personally identifiable information (PII) and institutional tax profiling data:
- Tax Identification Numbers (NPWP): Unique 15-to-16 digit national taxpayer identification numbers required for all banking, corporate, and civil transactions in Indonesia.
- Full Legal Names (NAMA_WAJIB_PAJAK): Complete legal identities of individual citizens, business owners, and corporate representatives.
- Demographic & Classification Data: Gender markers, taxpayer entity classifications (Badan / Orang Pribadi), and active taxpayer status flags (Aktif / Tidak Aktif).
- Complete Residential Addresses (ALAMAT): Highly granular home addresses specifying exact street numbers, neighborhood association codes (RT/RW), sub-districts, and postal zones.
- Geographic Distribution (KOTA & PROVINSI): Nationwide coverage spanning DKI Jakarta, Gowa, Waingapu, Timika, Balikpapan, Sukabumi, Bengkulu, Papua Pegunungan, and Riau.
- Professional Occupations (PEKERJAAN): Job classifications including Teachers (Guru), Technicians (Teknisi), Business Owners (Pengusaha), Traders (Pedagang), Consultants (Konsultan), Private Employees (Karyawan Swasta), and Programmers.
- Annual Tax Filing Status (STATUS_PAJAK): Compliance audit markers revealing whether taxpayers are Registered (Terdaftar), Have Filed (Sudah Lapor), or Have Not Filed (Belum Lapor).
- Direct Contact Channels (EMAIL & TELEPON): Personal email addresses and mobile telephone numbers linked to taxpayer accounts.
The geographic spread of this Indonesian Tax Data Breach confirms that the exfiltration is not restricted to a single municipality. Records encompass taxpayers from major commercial hubs like Jakarta and Surabaya, industrial centers in Kalimantan and Sumatra, and eastern territories across Papua and East Nusa Tenggara.

Forensic Impact: Identity Theft, Corporate Phishing, and Smishing Risks
The exposure of combined NPWP identifiers, residential addresses, and tax compliance data creates a severe threat matrix for Indonesian citizens. In modern financial and legal ecosystems, the NPWP serves as a primary identity anchor required for opening bank accounts, taking out commercial loans, applying for mortgages, and verifying business contracts. Consequently, the Indonesian Tax Data Breach threatens the integrity of domestic banking verification pipelines.
[CTI ANALYST INSIGHT] “When cybercriminals obtain an individual’s exact NPWP number, home address, phone number, and tax filing status, they can construct highly deceptive spear-phishing and social engineering attacks masquerading as official Direktorat Jenderal Pajak audit summonses.”
Threat actors and underground fraud syndicates will likely weaponize this Indonesian Tax Data Breach across three major cybercrime attack vectors:
1. Hyper-Targeted DJP Smishing and APK Malware Campaigns: Fraudsters frequently distribute malicious Android package files (APK malware) disguised as official tax notifications via WhatsApp and SMS. With access to real taxpayer names, addresses, and compliance statuses, criminals can personalize extortion messages, tricking victims into installing banking trojans that drain accounts.
2. Corporate Impersonation and Vendor Fraud: Because the dataset includes corporate entities (Badan) alongside consultant and executive contacts, adversaries exploiting this Indonesian Tax Data Breach can execute Business Email Compromise (BEC) and fake tax refund schemes against businesses.
3. Synthetic Identity Creation and Illegal Loan Origination: Unregulated peer-to-peer lending applications in the region often require minimal verification beyond an NPWP and national ID. Criminal syndicates routinely use dumped tax registries from this Indonesian Tax Data Breach to register fraudulent online loans in victims’ names.
Threat Actor Profile: The Emergence of K3LLLEAKERS
The threat group responsible for this incident, K3LLLEAKERS, represents an emerging data broker and hacktivist syndicate operating across dark web leak channels and underground Telegram hubs. Adopting Anonymous-inspired imagery with Guy Fawkes insignia and the motto “We Are Legion, We Do Not Forgive, We Do Not Forget,” the collective specializes in publicizing mass exfiltrations from government infrastructure to build notoriety.
Similar to previous CyberAsia investigations into regional data breach epidemics, groups like K3LLLEAKERS frequently leverage compromised administrative credentials, misconfigured API endpoints, or exposed database backup servers to orchestrate a major Indonesian Tax Data Breach without deploying destructive ransomware payloads.
Threat intelligence analysts map the adversary’s techniques against MITRE ATT&CK T1566 (Phishing), MITRE ATT&CK T1552 (Unsecured Credentials), and MITRE ATT&CK T1567 (Exfiltration Over Web Service).
Actionable Defense: Emergency Mitigations for Taxpayers and DJP
To mitigate the immediate risks stemming from this massive Indonesian Tax Data Breach, organizations and citizens must execute prioritized defensive countermeasures:
For Affected Citizens and Taxpayers:
- Treat All Tax-Related WhatsApp or SMS Messages as Hostile: The Directorate General of Taxes (DJP) never sends official tax notices containing downloadable Android application (.APK) files or direct payment links via WhatsApp. Always verify audit communications by logging into official portals (
djponline.pajak.go.id) directly following this Indonesian Tax Data Breach. - Monitor Credit Bureau Reports (SLIK OJK): Regularly check your financial information service records via Otoritas Jasa Keuangan (OJK) to detect unauthorized credit checks or synthetic loans registered under your NPWP.
- Implement Two-Factor Authentication (2FA): Enable multi-factor authentication across all banking, email, and government digital accounts using hardware keys or authenticator applications rather than SMS-based OTPs.
- Rotate Associated Email Passwords: If your email address is linked to your tax profile, immediately update the password and revoke active sessions.
For Government Agency Security Teams (DJP & BSSN):
- Conduct Comprehensive Database Access Audits: Audit all database access logs, administrative session tokens, and automated backup exports to identify unauthorized data staging and exfiltration channels linked to the Indonesian Tax Data Breach.
- Enforce Strict Zero Trust and Column-Level Encryption: Ensure taxpayer identifiers, contact information, and financial records are encrypted at rest using AES-256 with strict hardware security module (HSM) key management.
- Monitor Dark Web Repositories and File Hosting Services: Coordinate with national CSIRT units and cloud storage providers to issue takedown notices for exfiltrated database archives.
Frequently Asked Questions
Q1: What specific information was exposed in the Indonesian Tax Data Breach?
The breached database contains 100,000 verified records comprising NPWP numbers, full taxpayer names, complete home addresses with RT/RW codes, city and province designations, phone numbers, email addresses, professional occupations, and annual tax compliance filing statuses.
Q2: Who is responsible for the pajak.go.id database leak?
The leak was claimed and published by the cyber threat group K3LLLEAKERS, who dumped the full CSV file via cloud storage mirrors and underground Telegram channels.
Q3: How can Indonesian citizens protect themselves from identity fraud following this breach?
Citizens should remain hyper-vigilant against WhatsApp messages claiming to be tax audit notices, avoid installing APK files, monitor their credit history via OJK SLIK, and enable robust two-factor authentication on all banking services following the Indonesian Tax Data Breach.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Indonesian Tax Data Breach: 100,000 NPWP Records Dumped Online by K3LLLEAKERS, Is Anyone Safe? is part of the CyberAsia public archive. For organizations requiring breach validation schemas, credential exposure auditing, and PII containment protocols for data leak events, please refer to our Secure Drop or contact the research desk.