Thousands of data points, ranging from tax information to prospective civil servant (CPNS) applicants, from Indonesian government websites, are suspected to have leaked due to a malicious program infection, or malware.
The alleged data breach was reported by a data breach monitoring account, Dark Tracer, on Twitter earlier this month.
The account, @darktracer_int, stated that 878,319 credentials or confidential data from 34,714 government websites had been leaked. Several government websites were listed as victims of the malware.
The Prakerja website is listed as the Indonesian government website that experienced the most significant data breach, with 17,331 leaked credentials from *dashboard.prakerja.go.id*.
Next, 15,729 and 10,761 credentials were leaked from the Ministry of Education and Culture websites, *datadik.kemedikbud.go.id* and *info.gtk.kemdikbud.go.id*, respectively. Additionally, 10,409 credentials were leaked from the Directorate General of Taxes website, *djponline.pajak.go.id*.
Alfons Tanujaya, a digital security expert from Vaksincom, stated that data breaches should not be taken lightly, especially at the government institutional level.
“Leaked data can be used as a bridge to obtain other more important and sensitive information,” said Alfons, as quoted from a press release on Wednesday, April 27, 2022.
The following are the 10 government websites suspected of experiencing data breaches, according to Dark Tracer's report:
1. Prakerja (*dashboard.prakerja.go.id*) - 17,331 credentials
2. Kemdikbud (*ssso.datadik.kemdikbud.go.id*) - 15,729 credentials
3. Kemdikbud (*info.gtk.kemdikbud.go.id*) – 10,761 credentials
4. Directorate General of Taxes (*djponline.go.id*) – 10,409 credentials
5. BKN (*mysapk.bkn.go.id*) – 7,027 credentials
6. BKN (*daftar-sscasn.bkn.go.id*) – 6,770 credentials
7. Tax (*ereg.pajak.go.id*) – 5,083 credentials
8. Kemdikbud (*paspor-gtk.belajar.kemdikbud.go.id*) - 5,042 credentials
9. BKN (*sscndaftar.bkn.go.id*) – 4,715 credentials
10. Kemdikbud (*sso.data.kemdikbud.go.id*) – 4,042 credentials