Friday, December 20, 2024

Hacker claims to have breached Indonesia’s Ministry of Defense website, secret documents might be at risk

Reading Time: 2 minutes
Julian Isaac

Journalist

Mahinda Arkyasa

Editor

Interview

An anonymous hacker, known as “Two2,” has claimed to have successfully breached the website of the Ministry of Defense in Indonesia, kemhan.go.id. The hacker asserted gaining access to the website’s dashboard panel.

In a post on BreachForums, Two2 shared several screenshots from the kemhan.go.id dashboard. One of the screenshots revealed that the website had utilized 1.64 terabytes of storage out of 2 terabytes available.

Pratama Persadha, Chairman of Communication and Information System Security Research Center (CISSReC), noted that hackers typically aim to sell the data they obtain during a breach. In this case, the hacker offered accounts with access to the kemhan.go.id dashboard for sale.

While the shared documents were not classified, Pratama emphasized that it is possible for website users or employees to inadvertently store sensitive documents on the site, potentially compromising national security.

He also mentioned that the obtained accounts could be used to access other systems within the Ministry of Defense that contain important data and classified documents.

CISSReC conducted an investigation and found that kemhan.go.id had various vulnerabilities related to credentials, with 667 users and 37 employees experiencing data leaks. These leaks could be exploited for unauthorized access to the website.

In their examination, CISSReC also identified subdomain URLs from kemhan.go.id that could potentially serve as attack points against the Ministry of Defense’s website.

Pratama suggested that the cyberattack on kemhan.go.id was likely a “Stealer” malware attack. He explained that this type of malware is typically used to collect information that can be monetized by attackers.

Stealer malware’s standard form is to gather login information such as usernames and passwords, which are then sent to other systems through email or networks.

After successfully extracting sensitive data from the target device, hackers send this information to threat actors who may use it for extortion, ransom demands, or sell it on the dark web or forums as stolen goods.

Pratama highlighted that malware-based cyberattacks are favored by hackers because direct attacks on targeted systems from the outside are challenging due to multiple security measures in place. Thus, hackers exploit human error, which often represents the weakest point in cybersecurity.

Furthermore, Pratama explained the existence of “Malware as a Service” (MaaS), where cybercriminals provide various types of malware to users or customers who pay for the service. Customers of MaaS typically lack technical knowledge and skills to create malware themselves, so they can rent or purchase pre-made malware for launching attacks or other malicious activities.

The exact attack vector used by the hacker to access kemhan.go.id’s dashboard panel has not been determined yet. Pratama suggested that users are required to change the passwords of their accounts, both on the kemhan.go.id website and their personal accounts (email, social media, etc.).

It’s important to note that the Ministry of Defense’s website is now inaccessible, likely for investigative and system maintenance purposes, in an effort to prevent the use of leaked passwords for unauthorized access.

Julian Isaac

Journalist

Mahinda Arkyasa

Editor

 

Interview

SUBSCRIBE NOW
We will provide you with an invoice for your reimbursable expenses.

Free

New to Indonesian market? Read our free articles before subscribing to the premium plan. If you already run your business in Indonesia, make sure to subscribe to the premium subscription so you won’t miss any intelligence & business opportunities.

Premium

$550 USD/Year

or

$45 USD/Month

Cancelation: you can cancel your subscription at any time, by sending us an email inquiry@ibp-media.com

Add keywords to your market watch and receive notification:
Schedule a free consultation with us:

We’ll contact you for confirmation.

FURTHER READING

PT Hero Global Investment (HGII), a holding company focused on the renewable energy industry in Indonesia, is set to form a strategic partnership with Shikoku Electric Power Company, Inc. (Yonden), a Tokyo Stock Exchange-listed company.
Greenpeace Indonesia has raised concerns over the President Prabowo Subianto administration’s commitment to addressing climate and environmental issues, citing its lack of concrete action despite public statements at international forums.
PT PGN LNG Indonesia, as part of Pertamina’s Gas Subholding, has joined the development of a gasification project in North Papua, intended to strengthen the gas supply chain through the development of LNG infrastructure for power plants in the region.
The government must accelerate the process of converting kerosene to 3 kg Liquefied Petroleum Gas (LPG) for people in East Nusa Tenggara (NTT) province, in particular West Flores regency, for the sake of sustainable livelihood of the people and the government’s green energy target, an energy observer says.
Minister of Investment and Downstreaming/Head of the Investment Coordinating Board (BKPM) Rosan Perkasa Roeslani met with a number of giant Chinese companies within the electric vehicle (EV) ecosystem production chain during his visit to China on December 16-17, 2024.
The solo paintings exhibition entitled “Kebangkitan: Tanah Untuk Kedaulatan Pangan” (Resurrection: Land for Food Sovereignty) which was planned to be held at the National Gallery from December 20 to January 19, 2025, has finally been canceled.