ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Data breach hits Indonesia’s National Civil Service Agency ahead of Independence Day

Linked InXFacebook
bookmark_borderSave to Library

Semarang, Central Java – Just days before Indonesia’s 79th Independence Day celebration, the National Civil Service Agency (BKN) has become the latest target of a significant data breach, as reported by the Cyber Security Research Institute (CISSReC). The breach, confirmed by Pratama Persadha, Chairman of CISSReC and lecturer at the State Intelligence College (STIN), was publicly revealed on Sunday morning.

 

The incident was first disclosed by an anonymous hacker known as TopiAx on Breachforums on Saturday, August 10, 2024. The hacker claimed to have accessed 4,759,218 rows of sensitive data from BKN, including names, birth dates, academic titles, civil servant appointment dates, and other personal information. The compromised data reportedly contains both cleartext and encrypted information.

 

TopiAx has allegedly offered the dataset for sale for US$10,000 (Rp160 million), further intensifying concerns about the security of government-held information. The hacker even shared a sample of the data, which included details of 128 civil servants from various agencies in Aceh. CISSReC conducted random verification through WhatsApp, confirming the accuracy of the data, though some respondents noted minor discrepancies in the final digits of certain identification numbers.

 

As of Sunday morning, there has been no official response from BKN or other relevant authorities, including the National Cyber and Encryption Agency (BSSN) and the Ministry of Communication and Informatics. This silence is particularly alarming, given the sensitive nature of the data and the potential risks it poses.

 

Adding to the gravity of the situation is that BKN had previously signed a memorandum of understanding (MoU) with BSSN on October 3, 2022, to bolster civil servant data protection and improve cybersecurity measures. However, this MoU expired in October 2023, and whether it has been renewed or extended remains unclear.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543