Wednesday, January 22, 2025

Massive data breach hits civil service agency ahead of Independence Day

Reading Time: 2 minutes
Julian Isaac

Journalist

Editor

Interview

The Cyber Security Research Institute (CISSReC) has reported yet another significant data breach just before Indonesia’s 79th Independence Day celebration, this time targeting the National Civil Service Agency (BKN).

Pratama Persadha, Chairman of CISSReC and post-graduate study lecturer at the State Intelligence College (STIN), confirmed the breach on Sunday morning in Semarang, Central Java.

According to Pratama, the breach was first revealed in a post by an anonymous hacker known as TopiAx on Breachforums on Saturday, August 10, 2024.

The hacker claimed to have obtained a staggering 4,759,218 rows of data from BKN, containing sensitive information such as names, places and dates of birth, academic titles, dates of civil servant appointments, NIP (Civil Servant Identification Number), CPNS (Candidate Civil Servant) Recruitment Decree (SK) numbers, and PNS (Permanent Civil Servant) SK numbers.

Other data included ranks, job positions, institutions, addresses, identity numbers, phone numbers, email addresses, educational backgrounds, majors, and graduation years.

In addition to this, the stolen data also included both cleartext information and data processed through cryptographic methods.

The hacker reportedly offered the entire dataset for sale at a price of US$10,000 (Rp160 million).

Pratama revealed that the hacker shared a sample containing data on 128 civil servants from various agencies in Aceh.

CISSReC conducted a random verification of 13 names listed in the sample via WhatsApp, and the respondents confirmed that the data was accurate, although some noted minor errors in the final digits of the NIP and NIK fields.

As of Sunday morning, there has been no official response from BKN or other relevant authorities such as the National Cyber and Encryption Agency (BSSN) and the Ministry of Communication and Informatics regarding the suspected data breach.

It’s worth noting that BKN had signed a memorandum of understanding (MoU) with BSSN on October 3, 2022, to strengthen civil servant data protection and enhance the quality of electronic information and transaction security.

However, this MoU was only valid for one year and expired in October 2023. It remains unclear whether BKN has extended the MoU with BSSN.

This incident raises serious concerns about the state of cybersecurity within government institutions, especially in light of the sensitive nature of the compromised data and its potential implications.

Julian Isaac

Journalist

 

Editor

 

Interview

SUBSCRIBE NOW
We will provide you with an invoice for your reimbursable expenses.

Free

New to Indonesian market? Read our free articles before subscribing to the premium plan. If you already run your business in Indonesia, make sure to subscribe to the premium subscription so you won’t miss any intelligence & business opportunities.

Premium

$550 USD/Year

or

$45 USD/Month

Cancelation: you can cancel your subscription at any time, by sending us an email inquiry@ibp-media.com

Add keywords to your market watch and receive notification:
Schedule a free consultation with us:

We’ll contact you for confirmation.

FURTHER READING

The Center of Economic and Law Studies (CELIOS) sheds light on the funding sources for the free nutritious meal (MBG) program, which continues to be in the spotlight due to the potential for redirecting additional funds from other location posts.
Coordinating Minister for the Economy, Airlangga Hartarto, has revealed the government’s decision to revise the regulation regarding Foreign Exchange from Natural Resource Exports (DHE SDA) as part of the instrument to overcome the weakening rupiah exchange rate.
President Prabowo Subianto has set the development of the (IKN for the next five years, approving a total budget of Rp48.8 trillion (US$ 3 billion). The majority of the budget is used for the construction of parliamentary buildings and judicial institutions along with supporting infrastructure.
Indonesia officially opened its carbon exchange to international buyers on Monday, January 20, 2025, a move expected to raise funds to help meet the country’s ambitious domestic climate targets.
State power utility PT PLN is studying the implementation of carbon capture and storage (CCS) technology for steam-fired power plants (PLTU) to maintain the reliability of the national electricity system although the cost of its implementation is relatively high at US$40 per ton.
The implementation of Carbon Capture and Storage (CCS) and Carbon Capture, Utilization, and Storage (CCUS) technologies is relevant to support energy transition in Indonesia although the cost of this technology is relatively high, especially for power plants, said a top PLN engineering unit head.