Indonesia won't pay $8M ransom after cyberattack hits data center

Indonesia won’t pay $8M ransom after cyberattack hits nat’l data center

/ 04:02 PM June 25, 2024
FILE – Officers check the passports of passengers leaving for Singapore at the immigration checkpoint of the Bandar Bentan Telani ferry terminal on Bintan Island, Indonesia, Wednesday, May 15, 2024. Indonesian authorities said Monday that the country’s national data center was compromised by a cyber attack, disrupting public services including the immigration check points and asked for an $8 million ransom. (AP Photo/Dita Alangkara, File)

JAKARTA, Indonesia — Indonesia’s national data center has been compromised by a hacking group asking for a $8 million ransom that the government says it won’t pay.

The cyberattack has disrupted services of more than 200 government agencies at both the national and regional levels since last Thursday, said Samuel Abrijani Pangerapan, the director general of informatics applications with the Communications and Informatics Ministry.

READ: Car dealers in US revert to pens, paper after cyberattacks on software provider

Some government services have returned — immigration services at airports and elsewhere are now functional — but efforts continue at restoring other services such as investment licensing, Pangerapan told reporters Monday.

FEATURED STORIES

The attackers have held data hostage and offered a key for access in return for the $8 million ransom, said PT Telkom Indonesia’s director of network & IT solutions, Herlan Wijanarko, without giving further details.

Wijanarko said the company, in collaboration with authorities at home and abroad, is investigating and trying to break the encryption that made data inaccessible.

Communication and Informatics Minister Budi Arie Setiadi told journalists that the government won’t pay the ransom.

“We have tried our best to carry out recovery while the (National Cyber and Crypto Agency) is currently carrying out forensics,” Setiadi added.

ADVERTISEMENT

The head of that agency, Hinsa Siburian, said they had detected samples of the Lockbit 3.0 ransomware.

READ: Hackers gain access to sensitive DOST data

ADVERTISEMENT

Pratama Persadha, Indonesia’s Cybersecurity Research Institute chairman, said the current cyberattack was the most severe in a series of ransomware attacks that have hit Indonesian government agencies and companies since 2017.

“The disruption to the national data center and days-long needed to recover the system means this ransomware attack was extraordinary,” Persadha said. “It shows that our cyber infrastructure and its server systems were not being handled well.”

He said a ransomware attack would be meaningless if the government had a good backup that could automatically take over the main server of the national data center during a cyberattack.

Indonesia’s central bank was attacked by ransomware in 2022 but public services were not affected. The health ministry’s COVID-19 app was hacked in 2021, exposing the personal data and health status of 1.3 million people.

Your subscription could not be saved. Please try again.
Your subscription has been successful.

Subscribe to our daily newsletter

By providing an email address. I agree to the Terms of Use and acknowledge that I have read the Privacy Policy.

Last year, an intelligence platform that monitors malicious activities in cyberspace, Dark Tracer, revealed that a hacker group known as the LockBit ransomware had claimed to have stolen 1.5 terabytes of data managed by Indonesia’s largest Islamic bank, Bank Syariah Indonesia.

TOPICS: cyberattacks, Indonesia, technology
TAGS: cyberattacks, Indonesia, technology

© Copyright 1997-2024 INQUIRER.net | All Rights Reserved

We use cookies to ensure you get the best experience on our website. By continuing, you are agreeing to our use of cookies. To find out more, please click this link.