Red Hot Cyber

Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search

Potential Data Breach: Sensitive Indonesian Data for Sale on Dark Web

Alessio Stefan : 4 July 2024 16:44

A recent alert in information security landscape has been issued: a threat actor has announced the sale of the Attorney General’s Office of the Republic of Indonesia (Kejaksaan Agung Republik Indonesia) database on a well-known dark web forum.

The Attorney General’s Office of the Republic of Indonesia (Kejaksaan Agung Republik Indonesia) is the chief prosecutor’s office of Indonesia, responsible for overseeing criminal investigations, legal actions, and law enforcement in Indonesia. This agency plays a crucial role in the Indonesian judicial system, ensuring that crimes are prosecuted and that the law is upheld.

The Kejaksaan Agung database is a critical resource for managing the information and operations of the Attorney General’s Office. It encompasses data on court cases, suspects and convicts, and human resources.

SELLING METHODS

The announcement, with correlated sample, state:

“TODAY I HAVE UPLOAD THE KEJAKSAAN AGUNG REPUBLIK INDONESIA for you to download (sample file) And selling for full data of all this Readin and enjoy………

NOTE: i want to selling data user all country of indonesian ALL USERS AND DATABASE SINCE 2020-2024 FOR PRICE $100.000 If you interested buying for full data contact me acc payment, only using crypto”

The threat actor claims to possess the personal data of all Indonesian citizens from 2020 to 2024, offering it for sale at a price of $100,000. They are only accepting cryptocurrency payments to ensure the anonymity of transactions. The high price suggests a significant data breach. The sale is being conducted without any intermediaries or escrow.

The threat actor further clarifies that the database contains sensitive information such as user data, emails, passwords,phone numbers, and more. Once purchased, the data will be delivered in .gz, .csv, or .sql files.

Beneath the second image in the post, there’s a URL that leads to “Hizliresim,” a Turkish online platform for uploading and sharing images. The name “Hizliresim” translates to “quick image” in English, which accurately reflects the site’s primary purpose: providing a fast and easy service for uploading and sharing images.

CONCLUSION

The Kejaksaan Agung Republik Indonesia (Attorney General’s Office of the Republic of Indonesia) and its database stand as pivotal elements within Indonesia’s judicial system, playing a paramount role in combating crime and upholding justice across the nation. The effective and secure management of this information is paramount for the proper functioning of the Attorney General’s Office and for maintaining public trust in the legal system.

The recent threat to sell sensitive Indonesian citizen data highlights the vulnerabilities of cyber systems and the importance of adopting advanced security measures to prevent similar incidents. Additionally, the use of cryptocurrencies by cybercriminals to ensure transaction anonymity underscores the need to better regulate these forms of payment to prevent their abuse.

Alessio Stefan
Member of the Dark Lab group. Master's student of AI & Cybersecurity and CTF player with a passion for ethical hacking that has been with him since a young age. He spends his days immersed in studying and discovering new methods of attack with just the right amount of practice. Convinced that hacking is a culture he applies its principles not only in the digital world but also to daily life while waiting of turning his dedication into a career.