Insights
Digital BusinessSeptember 4, 20263 min read

The State of Data Privacy: 5 Major Cyber Breaches Shaking Indonesia (2023-2024)

In the modern digital era, data has evolved into one of the most valuable assets for individuals, corporations, and government organizations alike. Often referred to as the 'new oil,' this data fuels our digital economy, but it also paints a giant target on our backs. Lately, we have seen a worrying trend where personal and corporate information is increasingly under threat, as cyber criminals find new cracks in our digital defenses to exploit.

According to Bruce Hanadi, a cybersecurity expert and Chief Information Security Officer (CISO) at snc.id, the surge in cyberattacks isn't just a coincidence. Speaking in August 2023, Bruce noted that the past few years have seen a massive spike in targeted attacks aimed at stealing sensitive customer data. Once stolen, this information becomes a weapon for fraud, extortion, or a commodity to be auctioned off in the dark corners of the web. To survive this, companies must adopt rigorous strategies to anticipate and mitigate these inevitable leaks.

The Growing Threat Landscape

Data leaks are rarely the result of a single failure. They are often a 'perfect storm' of sophisticated external attacks, internal negligence, a simple lack of caution, or unpatched vulnerabilities in the software we use every day. The scale of the problem in Indonesia is staggering. Data from csirt.or.id reveals that in 2023 alone, the country recorded over 350 million cyberattack incidents. These aren't just numbers on a screen; they represent a total financial loss of at least $1 million USD (roughly Rp 15.9 billion).

To understand the gravity of the situation, let’s dive into the five most high-profile data breaches that have hit Indonesia between 2023 and 2024.

1. The Dukcapil Mega-Leak

In July 2023, the nation was shocked when the population data from the Directorate General of Population and Civil Registration (Dukcapil) under the Ministry of Home Affairs was reportedly leaked. An anonymous hacker using the handle 'RRR' posted the data on BreachForums, a notorious English-language underground forum for trading stolen information.

Cybersecurity consultant and founder of Ethical Hacker Indonesia, Teguh Aprianto, was the first to sound the alarm on X (formerly Twitter). He estimated that a staggering 337 million records were exposed. The sensitivity of this data cannot be overstated—it included full names, Family Card (KK) numbers, dates of birth, addresses, parents' names, and even marriage or birth certificate numbers. Teguh emphasized that while the public bears the brunt of the risk, there has been a lack of accountability and concrete recommendations from the Ministry of Communication and Informatics and the National Cyber and Crypto Agency (BSSN).

2. Bank Syariah Indonesia (BSI) Ransomware Attack

In May 2023, Bank Syariah Indonesia (BSI) fell victim to a massive breach orchestrated by the LockBit ransomware group. After negotiations reportedly failed, the hackers leaked the data of 15 million customers and employees on the dark web, including 1.5 terabytes of internal documentation.

Teguh Aprianto noted that over 8,000 internal files were exposed, revealing the personal details of 24,437 employees and sensitive customer loan information. LockBit demanded a ransom of $20 million (around Rp 296 billion) and even went as far as advising customers to stop using BSI’s services. However, BSI Corporate Secretary Gunawan A. Hartoyo reassured the public that customer funds and data remained secure and that services continued to operate normally through cooperation with the relevant authorities.

3. The 6 Million NPWP and Taxpayer Data Leak

Fast forward to the period between August and September 2024, and the headlines were dominated by the sale of 6 million Taxpayer Identification Numbers (NPWP). These records were reportedly being sold for Rp 150 million on the dark web.

The infamous hacker 'Bjorka' was suspected to be the mastermind behind this. What made this case particularly sensational was the profile of the victims. The leak allegedly included the personal data of President Joko Widodo, his sons Gibran Rakabuming Raka and Kaesang Pangarep, as well as high-ranking officials like Finance Minister Sri Mulyani and Coordinating Minister for Economic Affairs Airlangga Hartarto. A sample of 25 high-profile records was shared publicly to prove the authenticity of the hack, putting the privacy of the nation's top leaders under a glaring spotlight.

// SaaS Solutions

Less busywork, more real work.

We build robust internal tools and scalable SaaS platforms so your team can stop drowning in spreadsheets and start focusing on growth.

4. The PDNS 2 Surabaya Disaster

On June 17, 2024, one of the most critical pieces of Indonesia’s digital infrastructure—the Temporary National Data Center 2 (PDNS 2) in Surabaya—was crippled by the LockBit 3.0 Brain Cipher ransomware. This attack didn't just leak data; it encrypted systems across multiple government agencies, bringing services to a standstill.

The hackers demanded an $8 million ransom, which the government refused to pay. Consequently, on July 3, the hackers released the encryption key for free, but the damage was done. Herlan Wijanarko, Director of Network and IT Solutions at PT Telkom, admitted that the data stored at PDNS 2 was unrecoverable. While the data was isolated and remains encrypted (theoretically preventing hackers from using it for malicious purposes), the loss of access to critical government records sent shockwaves through the administrative sector.

5. The DPR YouTube Channel Hijack

Cyberattacks aren't always about stealing databases; sometimes, they are about reputation and disruption. On September 6, 2023, the official YouTube channel of the Indonesian House of Representatives (DPR RI) was hijacked. Instead of legislative sessions, the channel broadcasted live online gambling content for several hours.

This incident resulted in the loss of over 2 million subscribers and forced Google to temporarily deactivate the channel for recovery. Beyond the technical loss, the attack was a significant blow to the DPR’s reputation and eroded public trust, proving that even a social media presence can be a critical vulnerability for national institutions.

Discussion (0)