LockBit published 1.5TB of data stolen from Bank Syariah Indonesia

Organization
Bank Syariah Indonesia
Exploit
Ransomware
Industry
Banking

Bank Syariah Indonesia, the country's largest Islamic bank and a state-controlled institution, suffered a ransomware attack on May 8, 2023 that knocked out ATMs, branch transactions and mobile banking for several days.

The bank initially described the disruption to customers as technical work. LockBit publicly claimed the attack and accused the bank of misleading its customers and partners about the cause. The bank subsequently acknowledged indications of a cyberattack and said it had switched off several channels to protect its systems. Chief executive Hery Gunardi said on May 11 that services had been restored and that customer funds and data were safe.

LockBit said it had taken 1.5 terabytes of data across nine databases, covering roughly 15 million customers and employees. The group listed names, phone numbers, addresses, account and card details, transaction records, financial and legal documents, non-disclosure agreements and passwords for internal and external services among the stolen material.

The group demanded 20 million dollars and set a deadline of May 15. When no payment came it published the files on its leak site the following day. The bank did not confirm the volume or contents of the leak, so those figures rest on LockBit's own claims.

Indonesia's central bank assisted with restoring national payment and settlement connections, and Vice President Ma'ruf Amin publicly urged Indonesian banks to strengthen their systems.

Sources