Special Features

Malware Month

Ransomware scum who hit Indonesian government apologizes, hands over encryption key

Brain Cipher was never getting the $8 million it demanded anyway


Brain Cipher, the group responsible for hacking into Indonesia's Temporary National Data Center (PDNS) and disrupting the country's services, has seemingly apologized for its actions and released an encryption key to the government.

That key was in the form of an 54 kb ESXi file. Its efficacy has not yet been confirmed.

"Citizens of Indonesia, we apologize for the fact that it affected everyone," the team wrote in a statement shared by Singapore-based dark web intelligence outfit Stealth Mole.

In the statement, Brain Cipher detailed that it was releasing the decryptor of its own accord, without prodding by law enforcement or other agencies. It did, however, ask for public gratitude for its magnanimous behavior – and even provided an account at which it could receive donations. Good luck with that.

The team also provided a motive – that it was acting as a penetration tester of sorts, and that talks with the government had become deadlocked.

The cyber criminals had demanded a ransom of 131 billion Rupiah ($8 million) to release data it ransomwared June 20, but the Indonesian government refused to pay up.

"We hope that our attack made it clear to you how important it is to finance the industry and recruit qualified specialists," the hackers lectured.

"In this case, the attack was so easy that it took us very little time to unload the data and encrypt several thousand terabytes of information," the group boasted.

The statement concludes: "We're not haggling."

We have asked Stealth Mole to provide us with evidence of the statement's authenticity.

Brain Cipher clarified that while the Indonesian government might receive its data back for free, not all victims would get the same treatment.

"Honestly, this is very embarrassing for Kominfo and also us as Indonesian citizens," shared one cyber security influencer in Indonesian Bahasa.

"Imagine, with a budget of Rp 700 billion to secure Indonesian data, you (BSSN et al) only rely on a security system with Windows Defender," he added.

A certain degree of panic has rocked the government – particularly as it was found that backups were optional among the hit agencies. Indonesia's president Joko Widodo subsequently ordered an audit of government datacenters.

Politicians and the public alike appear on the hunt for a scapegoat – a petition demanding the resignation of communications and informatics minister Budi Arie Setiadi over the matter garnered more than 18,000 signatures. ®

Send us news
35 Comments

Ransomware batters critical industries, but takedowns hint at relief

Whether attack slowdown continues downward trend is the million dollar question that security researchers can't answer

Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

Researchers find many similarities, and nasty new customizations such as embedded compromised user credentials

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

French police reckon financial system targeted during Summer Games

RansomHub hits 210 victims in just 6 months

The ransomware gang recruits high-profile affiliates from LockBit and ALPHV

RansomHub-linked EDR-killing malware spotted in the wild

Also: Your external-facing NetSuite sites need a review; five popular malware varieties for Q2, and more

US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

Rap sheet spells out major no-nos after disgruntled staff blow whistle

Alleged Karakut ransomware scumbag charged in US

Plus: Microsoft issues workaround for dual-boot crashes; ARRL cops to ransom payment, and more

Check your IP cameras: There's a new Mirai botnet on the rise

Also, US offering $2.5M for Belarusian hacker, Backpage kingpins jailed, additional MOVEit victims, and more

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

Infosec hounds say they spotted vulnerability during routine travel in the US

US govt halts medical study into Havana Syndrome, cites 'coercion' of participants

What was screwing with minds of US diplomats – wait, is that a black helicopt...

The fingerpointing starts as cyber incident at London transport body continues

Network admins take a ride on the Fright Bus

Deadline looms: Google Workspace mandates OAuth by September 30

27 days to get your users' third-party apps on Google’s sign-in