- 20/08/2024
- Category: Commentaries
Author: Tane Hadiyantono
Editor: Hafiz Noer
The recent LockBit ransomware attack on Indonesia’s Temporary National Data Center (PDNS) by the BrainChiper group might be a spillover effect of the global crackdown on digital attacks in Global North countries. This crackdown has again proven how Global South countries are excluded from the priorities and have become the most prone in this capitalist data-driven world.
To start, LockBit is an organized crime that has been a major thorn in Global North countries’ cybersecurity; their ransomware has a record of targeting hospitals and healthcare companies.1 The group emerged in late 2019 and started as a ‘ransomware-as-a-service’ operation consisting of a core team that creates the malware tools, infrastructure and licenses its code to affiliates who launch attacks.2 The group has become a significant threat in this digital era by racking up billions of dollars from their extortion.
Earlier this year, Europol conducted an international sweep and investigation called ‘Operation Cronos,’ which took down 34 LockBit servers in the Netherlands, Germany, Finland, France, Switzerland, Australia, the United States, and the United Kingdom. The operation secured 1,000 decryption keys and indicted two Russian nationals.3 It also identified 14,000 rogue accounts responsible for exfiltration or maintaining the ransomware infrastructure. The UK’s National Crime Agency (NCA) led the task force, and Europol and Eurojust coordinated at the European level.
Data obtained from LockBit’s systems showed that between June 2022 and February 2024, more than 7,000 attacks were built using their services. The top five countries hit were the US, UK, France, Germany, and China.4 However, days after Europol announced the operation’s result, Sangfor Technology reported that the ransomware group resurfaced on the dark web days after the takedown.5 The actors behind LockBit now operate a new data leak portal on the Onion Router (TOR) network.
Against the backdrop of a growing cybersecurity enforcement agenda in Global North countries, Brain Chiper could be a smaller criminal cell or part of a larger group testing attacks in Global South countries. Developing countries have weaker cyber security because they store PDNS data in one location with minimal security. The lack of investment in cyber security technology and discipline in data security is also a big note which causes data leaks to become increasingly frequent.
Cybersecurity Threat Mapping
In the digital era, data is a valuable resource and needs to be managed with Big Data technology. The government, retail, banking, insurance, manufacturing, transportation and logistics, healthcare, and energy sectors are some of the strategic end users that use data and analytics in their daily activities. Indonesia itself has 123 data centers managed by 23 national and international companies.6
Initially, through Government Regulation No. 71 of 2019, all system operators operating in Indonesia had to store their data domestically.7 However, the law was amended, and the private sector can store their data abroad, while national government data are stored in a local integrated data center.8 The big data industry is dominated, run and patented by Global North companies such as Amazon, Google, Microsoft and IBM. In fact, the control of technology by the Global North countries regarding information and data centers creates a dependency that the North capitalizes on towards the Global South countries.9
The ransomware attack on PDNS Indonesia on June 20 this year raised questions regarding Indonesia’s data center infrastructure. The Indonesian government confirmed that Brain Chiper has links to a Russian ransomware group and uses the LockBit 3.0 software variant.10 The Indonesian people criticized the government on social media and mocked Microsoft’s built-in antivirus, Windows Defender, which protects PDNS infrastructure, as being too weak for the needs of a data center.
The government has not revealed how the ransomware entered the PDNS system but admitted to using an old version of the VMWare cloud service.11 US-based technology company Broadcom owns the company and has close ties to Chinese regulators. This connection can be seen from their merger plans in 2023, requiring approval from China’s State Administration for Market Regulation (SAMR) to acquire VMWare for US$61 billion.12
Through mapping the parties involved in the PDNS infrastructure, the role of the foreign technology sector is huge, yet there’s limited response or coordinated action post-attack. As a response to the attack, Microsoft stated the Windows Defender will be improved antivirus.13 Meanwhile, VMWare did not provide any statement.
Fortunately, on Tuesday (2/6) or 13 days after the attack, Brain Chiper announced plans to release the Indonesian PDN decryption key for free the next day. They emphasized the need for funding and cybersecurity specialists and apologized to Indonesia for the disruption.14 If promised, this will be the second time a ransomware group has apologized and released the decryption key for free. The first incident was when the ransomware group apologized for locking children’s hospital data.15
Brain Chiper’s message carries an altruistic message, but we must remain alert to future risks. Ransomware attacks may be an elaborate plan to encourage countries to implement stricter data protection regimes, a business conspiracy to get institutions to buy multi-million dollar antivirus software, or simply the mistake of careless torrent users.
Global South Countries as Technology Renters
The lack of accountability from the PDNS infrastructure provider gives the impression that there is no insurance or concrete follow-up from the data center technology owner. This should be criticized and become a note for the Indonesian government in choosing cloud technology, big data and cyber security service providers. However, in reality, it will be difficult for the Indonesian government and the public to switch from current technology providers because it will require enormous costs and energy.
This limitation may be the reason the Indonesian government has only been able to transfer PDNS for immigration data and not all data. The immigration data is transferred to the Amazon Web Service (AWS), which is a foreign player operating in Indonesia. This transfer again opens up room for criticism as to why the government did not use AWS services from the start if it was better.
The challenges of transitioning Indonesia’s cyber security technology are similar to the digital transformation problems undertaken by Global South countries in general. Ciurak and Ptashkina (2019) saw that Global South countries experience challenges when implementing digital convergence and technology leapfrogging because these parties are relatively technology renters who must follow agreements and contracts set by providers from the Global North. This condition can further create inequality in ownership and knowledge of digital technology and cyber security.
- National Crime Agency. (2024, May 7). LockBit leader unmasked and sanctioned. National Crime Agency. Retrieved July 17, 2024, from https://www.nationalcrimeagency.gov.uk/news/lockbit-leader-unmasked-and-sanctioned ↩︎
- Europol. (2024, February 20). Law enforcement disrupt world’s biggest ransomware operation | Europol. Europol. Retrieved July 17, 2024, from https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-disrupt-worlds-biggest-ransomware-operation ↩︎
- Searchlight Cyber Analysts. (2024, May 14). A Timeline of Events: Operation Cronos and LockBit › Searchlight Cyber. Searchlight Cyber. Retrieved July 17, 2024, from https://www.slcyber.io/a-timeline-of-events-operation-cronos-and-lockbit/ ↩︎
- Ibid. National Crime Agency. ↩︎
- Sangfor Technologies. (2024, February 20). LockBit Group Resurfaces After Its Recent Takedown by US and UK Law Enforcers. Sangfor Technologies. Retrieved July 17, 2024, from https://www.sangfor.com/blog/cybersecurity/lockbit-ransomware-group-taken-down-us-and-uk-enforcers-announce ↩︎
- Data Center Map. (n.d.). Indonesia Data Centers. Data Center Map. Retrieved July 17, 2024, from https://www.datacentermap.com/indonesia/ ↩︎
- Kementerian Komunikasi dan Informatika RI. (2019). JDIH Kemkominfo – Peraturan Pemerintah Nomor 71 Tahun 2019. JDIH Kominfo. Retrieved July 18, 2024, from https://jdih.kominfo.go.id/produk_hukum/view/id/695/t/peraturan+pemerintah+nomor+71+tahun+2019+tanggal+10+oktober+2019 ↩︎
- Anggraeni & Partners. (2023, May 31). Cloud-based processing and data protection laws in Indonesia. Lexology. Retrieved 7 17, 2027, from https://www.lexology.com/library/detail.aspx?g=a69d1317-7935-4de5-9653-0292094c1396 ↩︎
- Valente, J. C. L., & Grohmann, R. (2024). Critical data studies with Latin America: Theorizing beyond data colonialism. Big Data & Society, 11(1). https://doi.org/10.1177/20539517241227875 ↩︎
- Channel News Asia. (2024, July 1). Indonesia’s ‘giveaway’ minister faces growing pressure to resign after worst cyberattack in years. CNA. Retrieved July 17, 2024, from https://www.channelnewsasia.com/asia/indonesia-ransomware-cyberattack-petition-minister-budi-arie-resign-4448196 ↩︎
- Yesidora. (2024, June 27). TelkomSigma Klarifikasi Soal Penggunaan Windows Defender di PDN – Teknologi Katadata.co.id. Katadata. https://katadata.co.id/digital/teknologi/667e16d266f43/telkomsigma-klarifikasi-soal-penggunaan-windows-defender-di-pdn ↩︎
- Global Times. (2023, November 22). China approves US chipmaker’s $61b acquisition with restrictive conditions. Global Times. Retrieved July 17, 2024, from https://www.globaltimes.cn/page/202311/1302321.shtml ↩︎
- CNN Indonesia. (2024, June 28). Microsoft Buka Suara Soal Windows Defender Saat Ramai Kasus PDNS. CNN Indonesia. https://www.cnnindonesia.com/teknologi/20240628071747-192-1115147/microsoft-buka-suara-soal-windows-defender-saat-ramai-kasus-pdns ↩︎
- StealthMole. (2024, July 1). Fusion Intelligence Center @ StealthMole on X: “Ransomware gang Brain Cipher announced they’ll release decryption keys for free this Wednesday. They emphasized the need for cybersecurity funding and specialists. Apologies to Indonesia for the … X. Retrieved July 18, 2024, from https://x.com/stealthmole_int/status/1807919279519813698. ↩︎
- Abrams, L. (2023, January 1). Ransomware gang apologizes, gives SickKids hospital free decryptor. Bleeping Computer. https://www.bleepingcomputer.com/news/security/ransomware-gang-apologizes-gives-sickkids-hospital-free-decryptor/ ↩︎