NationalTech

Coretax Allegedly Hacked, Tax Office Denies Breach and Reveals Data Anomalies

JAKARTA — The Directorate General of Taxes (DJP) has denied reports of an alleged taxpayer data breach involving Coretax, Indonesia’s core tax administration system.

“Regarding information about an alleged data breach circulating on social media, DJP has conducted internal checks and validation, and the results show that the information is not true,” said Inge Diana Rismawanti, Director of Tax Counseling, Services and Public Relations at DJP, as quoted by CNBC Indonesia on Monday (September 21, 2026).

Inge said the conclusion was based on an examination of the structure of the data being circulated. According to her, certain attributes or fields found in the data had never been stored or managed within DJP’s database system.

“The sample data also shows user names and passwords in plain text. Clearly, this is not from the DJP database system,” she said.

DJP Says Taxpayer Data Is Protected

DJP emphasized that protecting the confidentiality and security of taxpayer data remains a priority for the tax authority.

“DJP’s information security management follows applicable information security standards and implements layered security measures,” Inge said.

DJP also urged taxpayers to remain calm, protect their personal information and activate multi-factor authentication on the Coretax DJP system.

Taxpayers are also advised to be cautious of links, messages or requests for information claiming to come from DJP.

Alleged Breach Circulated on Social Media

Reports of an alleged Coretax data breach previously surfaced on X through the @DailyDarkWeb account. In a post on Saturday (September 19, 2026), the account claimed that Indonesia’s tax authority database had allegedly been compromised.

“An alleged threat actor has uploaded what they claim to be a sample of a database related to the Directorate General of Taxes (DJP) Indonesia, a unit under the Ministry of Finance,” according to information cited by CNBC Indonesia on Monday (September 21, 2026).

The data allegedly included taxpayer identification numbers (NPWP), names and email addresses, phone numbers and physical addresses, passwords, user IDs, IP addresses, last login information, authentication tokens, “remember me” tokens, as well as account creation and update timestamps.

However, the account itself said it could not confirm whether the sample data actually originated from Indonesia’s tax infrastructure.

It also could not confirm the number of affected accounts, the source system, password format, token validity, or whether the material originated from a direct compromise of Indonesia’s tax infrastructure.

Based on its internal examination and validation, DJP therefore stated that the circulating information regarding an alleged Coretax data breach was not true.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button