Indonesia Faces Major Cybersecurity Breach 2024: Over 100 Government Institutions Affected

Updated: Jul 5

In a significant cybersecurity incident, Indonesia faces major Cybersecurity Breach 2024, especially in the National Data Center of Indonesia (PDN). As a result of the ransomware, 282 government institutions were seized with just 2% of data backed up(44 institutions). The hackers demanded a ransom of $8 million (approximately 131 billion rupiah) to restore access to the compromised systems. A few of the systems hacked are Indonesia’s National Data Centre (PDN), and Immigration System. This incident underscores the growing threat of ransomware and the critical importance of robust cybersecurity measures.

The attack was first detected on June 17th, 2024, when attempts were made to disable security features using Windows Defender. By June 20th 2024, the malicious activities escalated, including the installation of malicious files, deletion of crucial system files, and deactivation of essential services. The ransomware used in this attack, identified as Brain Cipher, is a sophisticated variant of the notorious LockBit 3.0 ransomware.

The attackers not only encrypted the data but also stole sensitive information, threatening to release it publicly if the ransom was not paid. This combined threat has complicated recovery efforts and underscores the urgent need for advanced cybersecurity defences and response strategies.

In a surprising turn of events, the suspected hacker responsible for the recent attack on Indonesia’s National Data Center (PDN) has issued a public apology to the nation. In an unprecedented move, the hacker has pledged to provide the decryption keys needed to restore the compromised data for free on Wed, 3rd of July 2024. This development comes as a surprise to Indonesian people. Until this blog is written (Friday, 5th of July 2024), Indonesia’s government has given the public an update that the keys were able to open 6 data sets.

The recent ransomware attack on Indonesia’s National Data Center serves as a stark reminder of the critical need for robust cybersecurity measures. Such incidents highlight the vulnerabilities businesses face and the severe consequences of inadequate protection. To help you safeguard your business from similar threats, we’ve outlined a step-by-step guide to prevent ransomware and cyberattacks.

  1. Educate your team: Conduct regular cybersecurity training for all employees to ensure they are aware of the latest threats and how to avoid them. Teaching staff to recognize phishing attempts(explore more about our eLearning & Phishing Simulation here), suspicious emails, and other common tactics used by cybercriminals can significantly reduce the risk of a successful attack. eLearning with Phishing Simulation here

  2. Regularly Update and Patch Systems: Keeping your operating systems, software, and applications up to date is crucial. Applying security patches promptly helps fix vulnerabilities that cybercriminals could exploit. This simple step is one of the most effective ways to protect your business from attacks.

  3. Back-Up Your Data: Perform regular backups of all critical data and store them in a secure, offsite location. Regularly testing these backups ensures they can be restored in the event of a ransomware attack or data loss incident, minimizing downtime and data loss.

  4. Develop an Incident Response Plan & Monitor Network Activity: Developing a robust cybersecurity strategy involves creating a detailed incident response plan to swiftly address cyberattacks. This plan should be regularly tested and updated to ensure all team members understand their roles and stay effective against evolving threats. Simultaneously, continuous monitoring of network activity using advanced threat detection tools enables early identification of suspicious activities, allowing prompt responses to prevent or minimize potential damage.

  5. Engage with Cybersecurity Experts: Partnering with cybersecurity professionals, like Complete Cyber, can provide your business with the expertise needed to assess and strengthen your defenses. Our experts’s advice can help you implement best practices and tailor your cybersecurity strategy to address your specific needs and threats. 

Together, these proactive measures form a solid foundation for safeguarding your organization against cyber threats, ensuring swift response and mitigation to protect critical assets and operations.

