Photo: Indonesia's Ministry of Communication and Digital Affairs.
- Calling Data Old Does Not Remove the Risk
- Personal Data Sales Websites Become Enforcement Targets
- The Government Traces the Sources and Distribution Channels
- Police and BSSN Have Different Roles
- Leaked Information Remains Personal Data
- Blocking Websites Does Not Explain the Original Breach
- The Investigation Must Lead to Accountability
JAKARTA, folitimes.id – Suspected personal data trading is back in the spotlight after old datasets circulated online. The Ministry of Communication and Digital Affairs is working with the Indonesian National Police and the National Cyber and Crypto Agency to trace the distribution.
Komdigi Director General of Digital Space Supervision Alexander Sabar, speaking in Central Jakarta on Friday (2 October 2026), said information from BSSN indicated that the widely discussed material came from old data.
"According to BSSN's explanation, the data breach currently being widely discussed involves old data that has been brought back into the spotlight," Alexander said.
"Even so, Komdigi is continuing to follow up through investigation and enforcement," he added.
Data source: Ministry of Communication and Digital Affairs.
Calling Data Old Does Not Remove the Risk
The age of a dataset does not automatically make the information in it lose its value. Phone numbers, email addresses, identity details and other personal information may remain in use for a long time.
The fact that the material came from an old breach therefore explains when the incident occurred. It does not automatically explain the level of risk when the data circulates again.
Personal Data Sales Websites Become Enforcement Targets
Alexander said Komdigi is coordinating with police over websites found to be buying and selling personal data.
Websites identified as being used for those activities are being addressed within the authorities' powers, including by blocking access.
The Government Traces the Sources and Distribution Channels
Komdigi says the investigation aims to identify the sources of distribution, the channels used and the parties involved.
Folitimes.id's review of Komdigi's official statement found no public explanation identifying the original system behind the dataset now circulating again. The editorial team therefore does not name a particular institution or company as the source of the breach.
Police and BSSN Have Different Roles
Komdigi is involving police in investigating suspected illegal trading. BSSN is involved because its duties and functions cover cybersecurity.
Coordination matters because the issue may involve both suspected data trading and the security of systems that were once the source of exposure.
Leaked Information Remains Personal Data
Alexander warned that information already on the internet does not automatically become freely usable information.
"Do not take part in spreading other people's personal data," Alexander said.
Komdigi refers to Law No. 27 of 2022 on Personal Data Protection in its explanation of distribution without a lawful basis.
Blocking Websites Does Not Explain the Original Breach
Removing data trading websites is an enforcement measure. However, the public's most important question is where the information first came from.
If the original source is known, system operators can be assessed on the improvements they have made.
The Investigation Must Lead to Accountability
Komdigi describes threats to data security as an evolving cross-border challenge. Previously exposed data can reappear through various channels.
Success should not be measured only by the number of websites blocked. The government needs to explain the sources of distribution, the parties involved and the preventive measures.














