SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
34 stars 0 forks source link

[DataBreaches] It’s like a veritable fire sale on Indonesians’ personal data #2566

Closed github-actions[bot] closed 2 years ago

github-actions[bot] commented 2 years ago

Indonesia’s private data protection bill cleared another hurdle and could be voted into law this week.  As Bloomberg reports: Data operators could face up to five years in jail and a maximum fine of 5 billion rupiah ($337,000) for leaking or misusing private information, according to Indonesia’s new data privacy bill set to be passed by parliament this week. The law would go into effect in two years. Still, it is too late for millions of Indonesians who have already had their personal information hacked, leaked, or otherwise compromised. There has been a veritable fire sale of personal data of Indonesians in recent months. In July, DataBreaches reported that all the leaks and hacks threatened Indonesians’ privacy.  A subsequent article quoted one of the self-proclaimed hackers saying, ‘I think Indonesia’s cybersecurity is run by 14-year olds.’  Databases from schools, medical facilities, COVID databases, government agencies, corporations, and banks can all be found on publicly accessible forums and telegram channels.  Some specific examples and listings are in the earlier post by DataBreaches in July. Since then, there have been additional listings, such as DESORDEN’s attack on Indonesia’s biggest tollway operator that compromised employee data, their attack on BOGA Group that involved employee and restaurant customer data, and even more recently, their attack on Honda’s main dealer in Indonesia, HondaMugen, that resulted in the exfiltration of personal identifying information of those being recruited or considered by the dealer. DESORDEN posted links to images of national ID cards, driving licenses, resumes, transcripts, and CVs on a popular hacking-related forum. The HondaMugen.co.id website is currently “down for maintenance” and could not be reached to inquire whether they have notified those affected by DESORDEN’s attack.  But because there has been no legislation in place, it is unclear whether any notifications will be made or any public admission of any hack will be forthcoming. While DESORDEN continues its campaign of attacking big corporations and others leak or sell large databases with various kinds of personal information on Indonesian citizens (some of which can be found by open source searches), one individual or group known as “Bjorka” has been garnering a lot of public and media attention for advertising big databases like millions of SIM cards. Bjorka has also published the personal information of several government officials. Their in-your-face approach has brought some cheers but may also have put a target on their back as far as the government is concerned. While some of the personal information about government officials has been confirmed as accurate, some has been described as inaccurate.  [Other questions about Bjorka have been raised concerning the SIM card database and whether that was their hack or whether they had bought and resold data hacked by someone else. DataBreaches sent an inquiry to Bjorka about that claim, but no reply was immediately available]. In any event, the explosion of databases and leaks combined with increased media attention has resulted in a significant influx of new users to the Breached.to forum. In response, the forum’s owner temporarily suspended new registrations because they couldn’t handle the number of new signups. Meanwhile, on Telegram While much of the media and public attention centers on listings on Breached.to, there is also a lot of personal data on Indonesians being shared or sold on Telegram. Of particular note this week, a former member of RaidForums is selling 12 databases with what they claim is a total of 873.16 M of personal information on Indonesians. The 12 databases do not appear to be listed on any forum or website checked by DataBreaches. “The 12 data packages to be sold publicly include the income, housing address, disease, education level, job and more of Indonesians,”  DataBreaches was told. For each database, the seller provides screencaps with sample data.  As one example, the seller provides a sample of health-related data of individuals from a database (“kesehatanindividu”). Another table relates to specific disabilities individuals have, and yet other tables compiled data on other types of personal and demographic information. Asked about the data source, the seller told DataBreaches that they had invaded one government department. They would not reveal which one to DataBreaches, but said buyers will be given that information. They claim that in that department, they found 46 tables, 12 of which are now for sale. The other tables will be made available at some point in the future. According to the seller, the government department does not know it has been hacked. DataBreaches inquired whether the seller had tried, or intended to try, ransoming the data, but the seller indicated that was not the plan. However, they would not provide any more insight into their motivations. Curiously, at the end of the chat, the hacker asked DataBreaches to let the government know they should listen to one particular piece of music:  Boléro. DataBreaches has no clue as to why. The flood of personal data on forums and Telegram poses a significant challenge to Indonesia’s government: what will it do to protect citizenry who have already had their national identity information stolen or compromised? Can the country wait two years to put certain protections in place? What authentication or verification methods should be put in place promptly to detect the use of stolen or leaked information?

https://www.databreaches.net/its-like-a-veritable-fire-sale-on-indonesians-personal-data/

github-actions[bot] commented 2 years ago

This issue is stale because it has been open 1 day with no activity. Remove stale label or comment or this will be closed in 1 day.

github-actions[bot] commented 2 years ago

This issue was closed because it has been stale with no activity.