Indonesia's Cybersecurity Crisis: Unpacking the Massive PLN and IndiHome Data Leaks
It feels like a recurring nightmare that the Indonesian public simply cannot wake up from. Just as we begin to move past one cybersecurity scandal, another—often larger and more sensitive—surfaces. Recently, the spotlight has shifted back to state-owned enterprises and major telecommunications providers. From PLN to IndiHome, the digital safety of millions of Indonesians is once again under the microscope, leaving many to wonder: when will this cycle of vulnerability finally end?
The scale of the alleged breaches is, quite frankly, staggering. Initial reports suggest that approximately 17 million personal data records of PLN customers were put up for sale on the notorious Breach Forum. But the bleeding doesn't stop there. An even larger cache of data, totaling 347GB and allegedly belonging to over 21,000 companies—both local and international branches operating in Indonesia—has also surfaced on the dark web. This isn't just about names and phone numbers anymore; it’s about the foundational data of the nation's economy.
The PLN Breach: 17 Million Records on the Auction Block
The trouble for PLN began when a user going by the alias 'Loliyta' claimed to possess 17 million records of the utility giant's customers. This wasn't a vague claim; the post on Breach Forum included specific samples of the database. These samples contained highly sensitive information, including Customer IDs, names, addresses, and even detailed electricity consumption patterns.
Cybersecurity expert Pratama Persadha noted that the data appeared online late on a Thursday night. Upon closer inspection of the provided samples, the data points were incredibly granular. We are talking about fields like Idpel, Energy Type, Kwh usage, Meter No, and specific unit identifiers like Unit Upi and Unit Ap. When these ID numbers were cross-referenced with actual payment platforms, the names matched perfectly. This suggests a high probability that the data is indeed legitimate and current, contradicting any immediate dismissals of the incident.
A 347GB Corporate Goldmine
While the PLN leak affects individuals, another breach aims directly at the corporate sector. An account named 'Toshikana' posted a massive 347GB archive titled 'Confidential documents of 21.7K Indonesia Companies'. For a price tag of $50,000 (roughly IDR 743 million), the hacker offered a treasure trove of sensitive corporate intelligence.
The leaked documents reportedly include NPWP (tax IDs) for directors and commissioners, company tax records, shareholder family cards (KK), passports of executives, financial reports, profit and loss statements, bank statements, and even deed of incorporation documents. This level of exposure is a nightmare for business continuity and corporate security, providing everything a malicious actor would need for corporate espionage or advanced financial fraud.
The IndiHome and Bjorka Controversy
Parallel to these events, the telecommunications sector faced its own crisis. Data allegedly belonging to IndiHome customers appeared on a site managed by the now-infamous hacker 'Bjorka'. This leak purportedly involves 26 million records, including browsing histories, search keywords, and personal identifiers like email, gender, and NIK (National ID numbers).
Teguh Aprianto, the founder of Ethical Hacker Indonesia, highlighted the severe privacy implications of this leak via Twitter. He pointed out how browsing history, when tied to a specific NIK and name, could be used to identify and potentially shame individuals based on their private online activities. The ability to link a person's identity to their most private digital footprints is a bridge too far for many privacy advocates.
Less busywork, more real work.
We build robust internal tools and scalable SaaS platforms so your team can stop drowning in spreadsheets and start focusing on growth.
Official Responses: Investigation vs. Denial
The reaction from the authorities and the companies involved has been a mix of caution and flat-out denial. The Ministry of Communication and Information Technology (Kominfo) stated they are 'delving into' the 347GB corporate leak and the PLN situation. Meanwhile, the National Cyber and Crypto Agency (BSSN) is reportedly providing technical assistance to secure PLN’s data centers.
However, Telkom Group (the parent company of IndiHome) has taken a more defensive stance. Senior Vice President Ahmad Reza claimed that their initial findings suggest the data is 'hoax and invalid.' He argued that Telkom does not provide @telkom.co.id email addresses to IndiHome customers and that the NIK samples provided did not match their internal database. Telkom suggests that the browsing history might have been scraped from external sites or is perhaps outdated data from 2018. They even suggested that users might have been compromised by malware after visiting 'prohibited sites,' shifting some of the responsibility back onto the consumers.
The Urgent Need for Legal Protection
Regardless of which side is right, these incidents underscore a glaring hole in Indonesia's digital infrastructure. Pratama Persadha emphasizes that until the Personal Data Protection Law (UU PDP) is fully enacted and enforced, there is little pressure on agencies and corporations to adopt world-class security standards.
A robust legal framework would mandate improvements in IT infrastructure, human resources, and cybersecurity protocols. For now, the Indonesian public is left in a state of digital limbo, hoping that the next notification they receive isn't an alert that their private life is for sale to the highest bidder.