Cyber Attack Fallout from PDN: Questioning Government Cybersecurity Priorities

Author: Ayom Mratita Purbandani
Editor: M Perdana Karim

A total of 60,000 passports were delayed, and 431 immigration points were closed, slowing down the cross-border arrival and departure processes. Furthermore, 47 Ministry of Education and Culture and Ministry of Research, Technology, and Higher Education service domains or applications were temporarily paralyzed, which led to the loss of 800,000 KIP-K student registration data, delays in KIP-K disbursements for 16,316 students, and a postponement of Beasiswa Pendidikan Indonesia (BPI) registrations. There was a complete halt to the issuance of e-KTP cards, suspension of the registration of foreigners for taxpayer identification numbers (NPWPs), as well as various other disruptions of public services.1 A very brief period of unfortunate events occurred due to the Brain Cipher cyber hacker syndicate using LockBit 3.0 ransomware hacking the temporary National Data Center (PDNs).

According to reports, the attack has locked and held data from at least 282 ministries and local government agencies.2 During this time, only 2% were backed up. Indonesians have been burdened with the systemic and highly significant effects of the operational paralysis of electronic systems for public services for days after losing access to national data spanning crucial sectors. In spite of this, the Ministry of Communication and Information Technology (Kominfo), the National Cyber and Crypto Agency (BSSN), and the Indonesian National Police (Polri) did not fully meet their responsibilities as data custodians. It was confirmed by Kominfo that no data involved in the attack could be recovered after recovery efforts by these bodies failed.3

The cascading impact not only disrupted critical social activities but also compromised national cybersecurity. In light of this incident, there has been a public outcry to hold those responsible accountable.4 Should we be justified in feeling hopeless about the security of our digital lives?

A data breach leaves citizens unprotected and helpless 

Our privacy may no longer exist. There is such a high frequency of data breaches in Indonesia that none of the data custodians seem to be learning from their errors. It underscores a gross misunderstanding of personal data security when Kominfo and BSSBN claim that national data “hasn’t leaked, [as] it was encrypted.” It condescends to the risk of massive data leaks in vital infrastructure.5 As well, Lawrence Abrams, BleepingComputer’s editor-in-chief, provides an explanation of Brain Cipher’s ransom note mentioning the ownership of The Onion Router (Tor network) on which stolen information is published.6 The non-fulfillment of promises to delete the data allows for double extortion schemes-sold to the highest bidder without knowing who bought it.

It was previously reported that a BreachForums thread offered Kominfo data for USD 121,000 or IDR 1.9 billion.7 Among the data included were National Identity Numbers (NIKs), bank account numbers, and bank details of Kominfo personnel. Kominfo responded that the claims could not be validated because they might be unilateral claims based on other leaked data. In spite of the fact that the thread was later deleted, there were still concerns about potential leaks of data, as double extortion scenarios are still possible. Moreover, Kominfo’s logic has been questioned by the public following the blocking of BreachForums.

After nearly two weeks of being hacked, the Indonesian government failed to ensure information security and sovereignty, as well as realize the urgency of Indonesian citizens’ personal information. Ultimately, citizens must swallow the bitter pill that their personal data has fallen into the hands of hackers. It is also conditioned on them to speculate on the doom they may suffer as a result of possible PDN data leaks. As Ridho Rahman Hariadi, a cybersecurity expert at ITSga’s Smart City and Cybersecurity Laboratory, warns, data breaches can lead to identity theft and account hacks.8 In addition to material losses, victims of data breaches also suffer non-material losses.

A more heartbreaking issue than the PDN hacking case is how the government handled it. It is easy to imagine how chaotic this impact would have been, disrupting individuals’ lives at a crucial time. As an implementation of ISO 27001, the Personal Data Protection (PDP) Law has become a mandatory digital security standard for companies.9 However, the PDN cyber disaster indicates that Kominfo, as the data custodian, did not implement these standards. Mitigation deployments failed to ensure the protection and recovery of affected citizens or victims. In the meantime, data owners have the right to know what happened to their data, so they can plan accordingly.

Systemic failure, public discontent 

PDN’s cyber disaster highlights the government’s unpreparedness for cyberattacks. In the wake of the PDN breach, no effective mitigation or recovery solutions were applied. Although public criticism was leveled at officials in the most responsible positions in such a large-scale case, none resigned. In the aftermath of a cyberattack, Yudhistira Nugraha, Head of the North Jakarta Kominfotik, emphasized two crucial components: backup and disaster recovery.10 By implementing these strategies, downtime could be minimized and operational systems could be restored. However, these strategies were not implemented by the government, which only backed up 2% of data and kept the system down for days. According to PDN’s Service Level Agreement (SLA), the Tier 3 data center has 99.982% availability with 1.6 hours of scheduled downtime per year maximum.

A lack of effective mitigation strategies following a data breach has generated public resentment. In addition to the scattered personal data of the public, the government tends to be non-transparent in communicating information. Kominfo reported on June 20, 2024, that PDN had been attacked by LockBit ransomware.11 However, a reverse engineer, Yohannes Nugroho, believes the PDN breach involved Lockbit and Babuk ransomware types.12 The two originated from the same group: Brain Cipher. After many public services were halted, even the first conference failed to explain the CVEs, port vulnerabilities, and attack modes of the catalogue of information system security vulnerabilities. The public finds it difficult to view this disaster as a “learning experience.”

In light of the fact that the data takeover process began approximately three months ago, it is reasonable for the public to unsympathize with this cyber disaster. Ransomware was only activated after all data was taken over. Because of this, there is great concern that, despite Brain Cipher’s promise to provide the encryption keys to PDN as a teaching tool, the data may be misused by third parties.

Misuse of data can have serious legal consequences. For non-compliance, parties affected by data misuse as well as regulatory bodies may bring legal action. Settlements, fines, and penalties may be imposed as a result of legal action. The problem arises, however, when the regulatory body—the government that is the data custodian—causes negligence. It is hard to imagine that the government could be subjected to such legal consequences as both data custodian and regulatory bodies.The PDN hacking case illustrates how the government, as the custodian of data, should always be vigilant against cyberattacks. To ensure vigilantism, disaster response teams need to be competent, recovery procedures should be well documented, and an IT infrastructure that can address and restore electronic systems and data quickly is needed. As for the case, full transparency is required to address it. As the custodian of data, the government should provide support services such as credit monitoring, fraud detection, and detailed guidance on how to protect personal information. The SAFENet has launched a complaint post to collect preliminary data, analyze, and share it with affected individuals. In order to help SAFENet, affected individuals can complete the following link.


  1. Dampak yang Ditimbulkan dari Peretasan Data Nasional oleh Ransomware 3.0 Tahun 2024,” Info dan Berita Fakultas Hukum UMSU, June 30, 2024, https://fahum.umsu.ac.id/blog/dampak-yang-ditimbulkan-dari-peretasan-data-nasional-oleh-ransomware-3-0-tahun-2024/. ↩︎
  2. Data di 282 Layanan Kementerian/Lembaga Hilang Imbas Peretasan, PDN, Kompas, June 27, 2024, https://nasional.kompas.com/read/2024/06/27/08173611/data-di-282-layanan-kementerian-lembaga-hilang-imbas-peretasan-pdn-hanya-44. ↩︎
  3. Data PDNS Gagal Pulih Karena Ransomware: Siapa Bertanggung Jawab? Bagian I.” Kompas, 29 June 2024. Accessed July 1, 2024. https://nasional.kompas.com/read/2024/06/29/06000081/data-pdns-gagal-pulih-karena-ransomware-siapa-bertanggung-jawab-bagian-i?page=all. ↩︎
  4. “PDNS Kena Ransomware, Menteri Kominfo Budi Arie Setiadi Harus Mundur! – Tandatangani Petisi!” Change.org (2024, June). Accessed July 1, 2024. https://chng.it/vDSN49mvMX. ↩︎
  5. “PDN Dibobol, Penjelasan Kominfo dan BSSN Dinilai Tak Masuk Akal,” (June 2024). Metro TV News. https://www.metrotvnews.com/read/NQACqxlG-pdn-dibobol-penjelasan-kominfo-dan-bssn-dinilai-tak-masuk-akal. ↩︎
  6. BleepingComputer. (2024, June). Meet Brain Cipher, the new ransomware behind Indonesia data center attack. Retrieved July 1, 2024, from https://www.bleepingcomputer.com/news/security/meet-brain-cipher-the-new-ransomware-behind-indonesia-data-center-attack/ ↩︎
  7. Data Diklaim dari PDN 2021-2024 Dijual Rp198 M di Forum Gelap. (2024, July 2). *CNN Indonesia*. Retrieved from https://www.cnnindonesia.com/teknologi/20240702104538-192-1116574/data-diklaim-dari-pdn-2021-2024-dijual-rp198-m-di-forum-gelap ↩︎
  8. “Ransomware Serang PDN, Pakar ITS Tekankan Pentingnya Keamanan Siber,” Institut Teknologi Sepuluh Nopember (ITS) News, June 28, 2024, https://www.its.ac.id/news/2024/06/28/ransomware-serang-pdn-pakar-its-tekankan-pentingnya-keamanan-siber/. ↩︎
  9. “UU Nomor 27 Tahun 2022,” Government of Indonesia, Ministry of Law and Human Rights, accessed July 2, 2024, https://jdih.setkab.go.id/PUUdoc/176837/Salinan_UU_Nomor_27_Tahun_2022.pdf. ↩︎
  10. Ransomware pada PDN: Pentingnya Backup dan Disaster Recovery. Kompas. (2024, June 25). Kompas Tekno. https://tekno.kompas.com/read/2024/06/25/15310227/ransomware-pada-pdn-pentingnya-backup-dan-disaster-recovery?page=3 ↩︎
  11. “Budi Arie Beberkan Kronologi Serangan Siber ke PDN yang Bikin Layanan Lumpuh,” Kompas.com, June 27, 2024, https://nasional.kompas.com/read/2024/06/27/17585061/budi-arie-beberkan-kronologi-serangan-siber-ke-pdn-yang-bikin-layanan-lumpuh (accessed July 1, 2024). ↩︎
  12. “Dua Ransomware Serang PDN,” (2024, July) Cloud Computing Indonesia, https://www.cloudcomputing.id/berita/dua-ransomware-serang-pdn (accessed July 3, 2024). ↩︎