Saturday, November 16, 2024

Massive data breach hits civil service agency ahead of Independence Day

Reading Time: 2 minutes
Julian Isaac

Journalist

Editor

Interview

The Cyber Security Research Institute (CISSReC) has reported yet another significant data breach just before Indonesia’s 79th Independence Day celebration, this time targeting the National Civil Service Agency (BKN).

Pratama Persadha, Chairman of CISSReC and post-graduate study lecturer at the State Intelligence College (STIN), confirmed the breach on Sunday morning in Semarang, Central Java.

According to Pratama, the breach was first revealed in a post by an anonymous hacker known as TopiAx on Breachforums on Saturday, August 10, 2024.

The hacker claimed to have obtained a staggering 4,759,218 rows of data from BKN, containing sensitive information such as names, places and dates of birth, academic titles, dates of civil servant appointments, NIP (Civil Servant Identification Number), CPNS (Candidate Civil Servant) Recruitment Decree (SK) numbers, and PNS (Permanent Civil Servant) SK numbers.

Other data included ranks, job positions, institutions, addresses, identity numbers, phone numbers, email addresses, educational backgrounds, majors, and graduation years.

In addition to this, the stolen data also included both cleartext information and data processed through cryptographic methods.

The hacker reportedly offered the entire dataset for sale at a price of US$10,000 (Rp160 million).

Pratama revealed that the hacker shared a sample containing data on 128 civil servants from various agencies in Aceh.

CISSReC conducted a random verification of 13 names listed in the sample via WhatsApp, and the respondents confirmed that the data was accurate, although some noted minor errors in the final digits of the NIP and NIK fields.

As of Sunday morning, there has been no official response from BKN or other relevant authorities such as the National Cyber and Encryption Agency (BSSN) and the Ministry of Communication and Informatics regarding the suspected data breach.

It’s worth noting that BKN had signed a memorandum of understanding (MoU) with BSSN on October 3, 2022, to strengthen civil servant data protection and enhance the quality of electronic information and transaction security.

However, this MoU was only valid for one year and expired in October 2023. It remains unclear whether BKN has extended the MoU with BSSN.

This incident raises serious concerns about the state of cybersecurity within government institutions, especially in light of the sensitive nature of the compromised data and its potential implications.

Julian Isaac

Journalist

 

Editor

 

Interview

SUBSCRIBE NOW
We will provide you with an invoice for your reimbursable expenses.

Free

New to Indonesian market? Read our free articles before subscribing to the premium plan. If you already run your business in Indonesia, make sure to subscribe to the premium subscription so you won’t miss any intelligence & business opportunities.

Premium

$550 USD/Year

or

$45 USD/Month

Cancelation: you can cancel your subscription at any time, by sending us an email inquiry@ibp-media.com

Add keywords to your market watch and receive notification:
Schedule a free consultation with us:

We’ll contact you for confirmation.

FURTHER READING

The indigenous communities of Poco Leok in Manggarai Regency, East Nusa Tenggara, which include Gendang Mucu, Mocok, Mori, Nderu, Cako, Ncamar, Rebak, Jong, Tere, and Lungar, continue to resist the geothermal mining project led by PT PLN. This project, aimed at expanding the Ulumbu Geothermal Power Plant (PLTP) to Units 5 and 6, threatens to disrupt their ancestral lands and displace their traditional ways of life. Backed by Germany’s Kreditanstalt für Wiederaufbau (KfW), the project has been the subject of growing opposition from local residents, who demand that KfW withdraw its financial support and acknowledge the harm done to the community.
Deputy President Director of PT Bank Central Asia (BCA), Armand Hartono, emphasizes the importance of investment and business diversification as the main strategy to maintain business continuity, a principle he inherited from his father Robert Budi Hartono, who is also known as the boss of the Djarum Group.
The statement by Chairman of The Federal Reserve (The Feds), Jerome Powell, that the U.S. central bank will cut interest rates gradually and carefully in the next few months sends a positive signal for the Indonesian banking sector.
Danish pump and water technology manufacturer, Grundfos, inaugurated on Thursday, November 14, 2024 its US$2 million submersible pump factory in Jakarta, equipped with large-scale assembly and testing line, allowing for increased local content, accelerated production, and distribution.
The Ministry of Investment and Downstreaming/Investment Coordinating Board (BKPM) and the Indonesian Central Bank (BI) signed a Cooperation Agreement (PKS) on financial sector licensing in Jakarta on Wednesday, November 13,2024.
The shareholders’ meeting of State power utility PT PLN on Thursday, November 14, 2024, appointed four new Commissioners and extended the terms of two Directors − Darmawan Prasodjo as President Director and Sinthya Roesly as Finance Director.