Indonesia's Pusat Data Nasional crippled by Brain Cipher ransomware

Organization
Pusat Data Nasional (Indonesia National Data Center)
Exploit
Ransomware
Industry
Government

Indonesia's Pusat Data Nasional, the temporary national data centre run under the Ministry of Communication and Information Technology, was encrypted by ransomware beginning on 20 June 2024. The head of the National Cyber and Crypto Agency identified the malware as Brain Cipher, a strain closely resembling code produced by the leaked LockBit 3.0 builder.

The outage reached roughly 210 central and local government agencies. Immigration systems were among the worst affected, taking down visa, passport and residence permit processing and slowing checkpoints at major airports and ports. Licensing services, public procurement platforms and, in some regions, student registration were also disrupted.

The attackers demanded 131 billion rupiah, about 8 million US dollars, and threatened to sell the stolen data on the dark web. Indonesia's leadership publicly refused to pay. The Directorate of Immigration moved its data to a private cloud provider and had immigration services running again by 22 and 23 June, while other agencies faced a longer rebuild.

Officials said the episode showed the need for a stronger national cybersecurity strategy and closer coordination between government bodies and private providers. As of late June the government had set no timeline for full restoration and had given no indication it would negotiate with the attackers.

Sources