Lupa Kata Sandi? Klik di Sini

atau Masuk melalui

Belum Memiliki Akun Daftar di Sini


atau Daftar melalui

Sudah Memiliki Akun Masuk di Sini

Konfirmasi Email

Kami telah mengirimkan link aktivasi melalui email ke rudihamdani@gmail.com.

Klik link aktivasi dan dapatkan akses membaca 2 artikel gratis non Laput di koran dan Majalah Tempo

Jika Anda tidak menerima email,
Kirimkan Lagi Sekarang

A Strike at the Heart of Our National Data

Editor

Laila Afifa

2 July 2024 20:40 WIB

TEMPO.CO, JakartaThe hacking of the National Data Center is a threat to the personal data of millions of people. The government fails to establish a digital security system.

The government’s confusion about how to deal with the collapse of the National Data Center after it was hacked is the result of a mistaken paradigm. Instead of granting the public the right to the protection of their personal information, the government has seen the Internet simply as a national security problem.

A virus penetrated the Temporary National Data Center (PDNS) in Surabaya, East Java, on Thursday, June 20. The government had no idea how to deal with this and only officially announced it four days later, after prevaricating by claiming the disruption was only a technical problem.

On the first day, ransomware brought down the services of 347 central and regional government institutions. The most serious disruption was at the Immigration Directorate-General. This resulted in long lines of airplane passengers at arrival and departure gates because immigration checks had to be done manually.

The Communication and Informatics Ministry, the manager of the PDNS, as well as the National Cyber and Encryption Agency (BSSN), did not have any crisis protocols in place when the attack occurred. The mutual accusations of blame for responsibility considerably slowed down their response to the attack. It also led to speculation about the cause: from negligence in maintaining the system to a counterattack by managers of online gambling websites.

The BSSN said that the attack on the PDNS was carried out by hacking the computer system and installing malware aimed at extortion. The hacker, who has not yet been publicly named, installed a newly developed ransomware named Brain Cipher (Brain 3.0 ) and asked for a payment of Rp131 billion.

At the same time as the PDNS was paralyzed, the National Police Automatic Finger Identification System and the Indonesian Military Strategic Intelligence Agency were also hacked. Important data belonging to the two institutions was then offered for sale on an Internet site not accessible by ordinary search engines or browsers. The motive was the same as that of the hacker named Bjorka, who offered the data of 34 million Indonesian passport holders for sale.

The poor coordination between the Communication and Informatics Ministry and the BSSN was one of the triggers for this attack. The BSSN claims that they already gave a warning of potential hacking, referring to similar incidents in many other countries to the Communication Ministry. However, this warning was not responded seriously. On June 17, the BSSN found an attempt to deactivate the PDNS security features that made it vulnerable to virus attacks.

Unfortunately, the Communication Ministry did not manage the PDNS well. It turns out that only two percent of the data was backed up, making it difficult to quickly recover the hacked data. This is strange because in 2022, the Ministry issued a tender for backing up the data, which was won by Energi Jaring Komunikasi. This means that it is fair to suspect that the tender winner did not do its job.

The lack of readiness of the government in its response to this digital attack might be a violation of Law No. 27/2022 on Personal Data Protection. Article 46 clearly states that if there is a failure to protect personal data, the manager of this data must report in writing to the individuals and the personal data protection agency within 72 hours.

Another indication is that the government’s lack of attention regarding the provision of security guarantees was apparent from the fact that no technical implementation regulation relating to the Personal Data Protection Law has been issued, despite this having been mandated by that law since 2022.

This is worrying at a time when Indonesia finds itself in a cybersecurity emergency. According to the BSSN, there were 279.8 million cyber attacks against Indonesia in 2023. The previous year there were 370 million, and it is estimated the total number will rise this year. Because of this, global cyber security company SEON ranks Indonesia’s digital security at number 62 of 93 nations, far below Malaysia and Singapore.

The failure of Joko Widodo’s administration to establish a digital security system should serve as a lesson for Prabowo Subianto, the president-elect. Aside from thinking about purchasing key military equipment, Prabowo should also strengthen our digital security system.

Read the Complete Story in Tempo English Magazine



Indonesian Ministry Says Brain Cipher's Decryption Keys Work on PDNS Specimen

2 jam lalu

Indonesian Ministry Says Brain Cipher's Decryption Keys Work on PDNS Specimen

The decryption key functions to open data previously encrypted by Brain Cipher.


PDNS Ransomware: House Member Claims 80 Foreign Companies to Audit Indonesian Branches

5 jam lalu

PDNS Ransomware: House Member Claims 80 Foreign Companies to Audit Indonesian Branches

The national data center was attacked by LockBit 3.0 ransomware on June 20, 2024.


Import Ban and Restriction Policy Causes Airlines to Limp

8 jam lalu

Import Ban and Restriction Policy Causes Airlines to Limp

A new regulation concerning the purchase of aircraft components gives rise to a new problem for airlines. The TKDN policy is being wrongly applied.


Kominfo Ministry Tests Decryption Key to Unlock Hacked Data Center

9 jam lalu

Kominfo Ministry Tests Decryption Key to Unlock Hacked Data Center

Kominfo confirmed that it has attempted to use the decryption key provided by the Brain Cipher ransomware group to unlock access to the hacked PDNS.


Kominfo's Aptika Director General Resigns After National Data Center Hack

11 jam lalu

Kominfo's Aptika Director General Resigns After National Data Center Hack

Kominfo Ministry's Director General Semuel Abrijani Pangerapan has stepped down in the wake of the Temporary National Data Center (PDNS) hack.


PDNS Decryption Key Offered, But Hackers Threaten Kominfo Data Release on Denial

16 jam lalu

PDNS Decryption Key Offered, But Hackers Threaten Kominfo Data Release on Denial

The Brain Cipher ransomware group followed through on their promise to provide the decryption key for PDNS to the Kominfo Ministry.


The Impacts of Karen Agustiawan's Sentence on the Business Decisions of SOE Directors

1 hari lalu

The Impacts of Karen Agustiawan's Sentence on the Business Decisions of SOE Directors

The guilty verdict for Karen Agustiawan shows that in Indonesia, even business decisions can easily lead to prosecution.


Brain Cipher Vows to Release PDNS Decryption Keys for Free, Expert: 'Don't Be Easily Fooled'

2 hari lalu

Brain Cipher Vows to Release PDNS Decryption Keys for Free, Expert: 'Don't Be Easily Fooled'

Brain Cipher advised the Indonesian government to consider the PDNS attack a lesson on the importance of financing the cybersecurity industry.


Cyber Consultant Shares 6 Tips to Avoid Ransomware Attacks

2 hari lalu

Cyber Consultant Shares 6 Tips to Avoid Ransomware Attacks

Cyber consultant Spentera highlights that ransomware recently targeted the Temporary National Data Center also threatens private and public sectors.


Indonesian Govt Targets to Resolve Ransomware Attack on National Data Center This Month

3 hari lalu

Indonesian Govt Targets to Resolve Ransomware Attack on National Data Center This Month

The government targets this month to resolve the ransomware attack as President Jokowi previously requested.