Special Features

Malware Month

Ransomware scum who hit Indonesian government apologizes, hands over encryption key

Brain Cipher was never getting the $8 million it demanded anyway


Brain Cipher, the group responsible for hacking into Indonesia's Temporary National Data Center (PDNS) and disrupting the country's services, has seemingly apologized for its actions and released an encryption key to the government.

That key was in the form of an 54 kb ESXi file. Its efficacy has not yet been confirmed.

"Citizens of Indonesia, we apologize for the fact that it affected everyone," the team wrote in a statement shared by Singapore-based dark web intelligence outfit Stealth Mole.

In the statement, Brain Cipher detailed that it was releasing the decryptor of its own accord, without prodding by law enforcement or other agencies. It did, however, ask for public gratitude for its magnanimous behavior – and even provided an account at which it could receive donations. Good luck with that.

The team also provided a motive – that it was acting as a penetration tester of sorts, and that talks with the government had become deadlocked.

The cyber criminals had demanded a ransom of 131 billion Rupiah ($8 million) to release data it ransomwared June 20, but the Indonesian government refused to pay up.

"We hope that our attack made it clear to you how important it is to finance the industry and recruit qualified specialists," the hackers lectured.

"In this case, the attack was so easy that it took us very little time to unload the data and encrypt several thousand terabytes of information," the group boasted.

The statement concludes: "We're not haggling."

We have asked Stealth Mole to provide us with evidence of the statement's authenticity.

Brain Cipher clarified that while the Indonesian government might receive its data back for free, not all victims would get the same treatment.

"Honestly, this is very embarrassing for Kominfo and also us as Indonesian citizens," shared one cyber security influencer in Indonesian Bahasa.

"Imagine, with a budget of Rp 700 billion to secure Indonesian data, you (BSSN et al) only rely on a security system with Windows Defender," he added.

A certain degree of panic has rocked the government – particularly as it was found that backups were optional among the hit agencies. Indonesia's president Joko Widodo subsequently ordered an audit of government datacenters.

Politicians and the public alike appear on the hunt for a scapegoat – a petition demanding the resignation of communications and informatics minister Budi Arie Setiadi over the matter garnered more than 18,000 signatures. ®

Send us news
35 Comments

Would banning ransomware insurance stop the scourge?

White House official makes case for ending extortion reimbursements

Akira ransomware is encrypting victims again following pure extortion fling

Crooks revert to old ways for greater efficiency

Microsoft says more ransomware stopped before reaching encryption

Volume of attacks still surging though, according to Digital Defense Report

Ransomware's ripple effect felt across ERs as patient care suffers

389 US healthcare orgs infected this year alone

INC ransomware rebrands to Lynx – same code, new name, still up to no good

Researchers point to evidence that scumbags visited the strategy boutique

Penn State pays DoJ $1.25M to settle cybersecurity compliance case

Fight On, State? Not this time

Microsoft says tougher punishments needed for state-sponsored cybercriminals

Although it also reaffirmed commitment to secure-by-design initiatives

Tech firms to pay millions in SEC penalties for misleading SolarWinds disclosures

Unisys, Avaya, Check Point, and Mimecast settled with the agency without admitting or denying wrongdoing

Here's a NIS2 compliance checklist since no one cares about deadlines anymore

Only two EU members have completed the transposition into domestic law

ESET denies it was compromised as Israeli orgs targeted with 'ESET-branded' wipers

Says 'limited' incident isolated to 'partner company'

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites

Also, new EU cyber reporting rules are live, exploiters hit the gas pedal, free PDNS for UK schools, and more

Volkswagen monitoring data dump threat from 8Base ransomware crew

The German car giant appears to be unconcerned
  翻译: