Cybersecurity incident in Indonesia: the PDN(S) incident

Budi Rahardjo on the road
30 Jun 202407:46

Summary

TLDRBudhar discusses the recent ransomware attack on Indonesia's National Data Center, possibly due to a variant of LockBit called 'Brain Chipper.' The incident on June 20th disrupted immigration servers and affected government services hosted by the center, causing inconvenience and raising concerns about Indonesia's cybersecurity. Budhar, who runs a cybersecurity company and teaches incident response, seeks to understand the scale of the issue and the lessons to be learned from it.

Takeaways

  • 🌐 The speaker, Budhar, is currently in Shanghai and is posting a video on a secondary channel due to issues with two-factor authentication on his main channel.
  • πŸ’» Budhar discusses a recent incident involving Indonesia's National Data Center (PDN), which was reportedly attacked by a variant of the Locky ransomware called 'Brain Chipper'.
  • πŸ“… The incident is believed to have occurred on June 20th, causing issues with the Indonesian immigration server and affecting the integrated services at the airports.
  • πŸ›‚ The disruption led to the inability to access applications necessary for electronic gate operations, which are part of the virtual machines hosted by the PDN.
  • 🏒 The PDN is hosted by a company called Talom Sigma, which also hosts other companies' services, indicating the widespread impact of the attack.
  • πŸ”’ The ransomware attack targeted the main virtual machine, causing a denial of service for all dependent Indonesian government organizations.
  • πŸ”„ Despite having a disaster recovery center, the PDN's backup site was not operational for an unknown reason, exacerbating the situation.
  • 🚨 Several services were disrupted, and it took several days for some to be restored, highlighting the severity of the incident.
  • πŸ€” Budhar expresses confusion over how the incident occurred and the lack of public information, which limits understanding of the situation.
  • πŸ›οΈ As a professional in cybersecurity and an educator, Budhar feels the need to understand the incident to learn lessons and improve response strategies.
  • 🌍 Budhar compares Indonesia's cybersecurity situation to other countries, noting that the scale of impact is significantly larger due to the country's large population.

Q & A

  • What is the main topic discussed in Budhar's video transcript?

    -The main topic discussed in the video transcript is the ransomware attack on the National Data Center in Indonesia, also known as Pat Data National, and its impact on various services.

  • Why is Budhar unable to access his normal channel?

    -Budhar is unable to access his normal channel due to a two-factor authentication issue that he cannot resolve while traveling.

  • What was the ransomware variant involved in the attack on the National Data Center?

    -The ransomware variant involved in the attack is mentioned as something similar to Locky, possibly called 'brain chipper,' though Budhar is not entirely sure of the exact name.

  • When did the incident with the Indonesian immigration server occur?

    -The incident with the Indonesian immigration server occurred on the 20th of June.

  • What was the immediate impact of the ransomware attack on the Indonesian immigration server?

    -The immediate impact was that the applications and integrated services required for electronic gates at the airports could not be accessed, causing disruptions in immigration processes.

  • Who is hosting the Pat Data National's data center?

    -The data center is hosted by a company referred to as 'talom talcom Sigma,' which is likely a misspelling or mispronunciation of the actual company name.

  • What other services were affected besides the Indonesian government's?

    -Besides the government services, other companies hosted in the same data center were also affected, although the specific companies are not mentioned.

  • What is the role of the Pat Data National in hosting services?

    -The Pat Data National is responsible for hosting more than 200 government services, indicating its critical role in the country's digital infrastructure.

  • Does Budhar have any information about the disaster recovery center's status?

    -Budhar is unsure about the status of the disaster recovery center, as he mentions that it might not be working for some unknown reason.

  • What is Budhar's professional interest in this incident?

    -Budhar is interested in the incident as he runs an Indonesia computer emergency response team, a cybersecurity company, and teaches incident handling at a university, making it crucial for him to understand and learn from this incident.

  • How does Budhar view the cybersecurity situation in Indonesia compared to other countries?

    -Budhar views the cybersecurity situation in Indonesia as similar to other countries, with the main difference being the scale of impact due to Indonesia's large population and internet user base.

  • What is Budhar's final note on the situation?

    -Budhar's final note is that while the incident is a big disaster, it has not created a significant economic disruption in Indonesia, although it has caused inconvenience.

Outlines

00:00

πŸ˜• Ransomware Attack on Indonesia's National Data Center

Budhar discusses a recent ransomware incident at Indonesia's National Data Center, known as Pat Data National, which affected the Indonesian immigration server on June 20th. The attack, possibly involving a variant of Locky called 'brain chipper,' led to inaccessibility of applications and services at airports, causing a significant disruption. The data center, hosted by Talom Sigma in Suaya, supports not only government services but also other companies. The scale of the impact is substantial due to the number of services hosted, which exceeds 200. Budhar mentions a potential issue with the disaster recovery center, which may not be functioning correctly. The incident is a cause for concern for Budhar, who is involved in cybersecurity and incident response, and he is seeking to understand and learn from this event.

05:00

🌐 Reflections on Indonesia's Cybersecurity Situation

In the second paragraph, Budhar addresses the state of cybersecurity in Indonesia, comparing it to other countries but emphasizing the unique challenges posed by Indonesia's large internet-using population, which is over 200 million. He suggests that while the situation is not unique to Indonesia, the scale of any incident can be significantly larger due to the country's size. Budhar mentions that while the recent ransomware attack is a disaster, it has not caused a major economic disruption, though it has inconvenienced many. He expresses his intention to continue updating on the situation and ends with well-wishes for his audience, reminding them to stay safe and healthy.

Mindmap

Keywords

πŸ’‘Changi

Changi refers to Changi Airport in Singapore, which is a major aviation hub in Asia. In the video, the speaker mentions being at Changi while recording the video, indicating the location from which the information is being shared and providing a personal context to the narrative.

πŸ’‘Two-Factor Authentication

Two-Factor Authentication is a security process in which a user provides two different authentication factors to verify themselves. The speaker mentions an issue with two-factor authentication preventing access to a channel, which is a common security measure but can sometimes create access problems, as illustrated in the script.

πŸ’‘National Data Center

A National Data Center is a large-scale facility that houses data, applications, and services for a country's government or other entities. The script discusses an incident at the National Data Center in Indonesia, emphasizing its importance in hosting critical services and the impact of the security breach.

πŸ’‘Ransomware

Ransomware is a type of malicious software that encrypts a user's data and demands payment to restore access. The script mentions a ransomware attack, specifically a variant called 'brain chipper,' as the cause of the incident at the Indonesian National Data Center, highlighting the threat ransomware poses to data security.

πŸ’‘Locky

Locky is a notorious ransomware family known for encrypting files and demanding a ransom in Bitcoin. Although the speaker is unsure of the exact variant, the mention of 'brain chipper' could be a reference to Locky or a similar ransomware, indicating the severity of the attack on the National Data Center.

πŸ’‘Indonesian Immigration Server

The Indonesian Immigration Server is part of the country's infrastructure for managing immigration-related data and processes. The script describes an issue with this server, which could not be accessed, leading to disruptions in immigration services and highlighting the reliance on data centers for such critical functions.

πŸ’‘Virtual Machines

Virtual Machines are software emulations of physical computers that allow for multiple operating systems to run on a single physical machine. The script explains that the servers affected were part of virtual machines hosted by the National Data Center, emphasizing the interconnected nature of digital infrastructure.

πŸ’‘Hypervisor

A Hypervisor is a piece of software that creates and manages virtual machines. The script suggests that the hypervisor was compromised by the ransomware, affecting all virtual machines hosted on it, which is a critical point in understanding the scope of the attack.

πŸ’‘Denial of Service

Denial of Service (DoS) is a type of cyberattack that aims to make a service unavailable to its intended users. The script describes the effect of the ransomware attack as a form of DoS, as it rendered the government's virtual machines inaccessible.

πŸ’‘Disaster Recovery Center

A Disaster Recovery Center is a facility that provides backup infrastructure and services to ensure business continuity in the event of a disaster. The script mentions that the National Data Center has a DRC, but it was not functioning as expected, which is a critical point in understanding the severity of the incident.

πŸ’‘Cybersecurity

Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks. The speaker discusses the state of cybersecurity in Indonesia, comparing it to other countries and emphasizing the scale of the population and internet users as a factor in the impact of cyberattacks.

πŸ’‘Incident Response

Incident Response is a process that organizations follow to prepare for and respond to cybersecurity incidents. The speaker mentions teaching incident response, indicating the importance of having protocols in place to handle such situations and the relevance of this topic to the video's content.

Highlights

Budhar is currently in Shanghai and is unable to access his usual channel due to two-factor authentication complications.

A new channel was created for Budhar's travel session.

The National Data Center (PDN) in Indonesia experienced a significant incident involving ransomware, possibly a variant of LockBit called 'Brain Chipper'.

The incident occurred on June 20th, affecting the Indonesian immigration server and integrated services.

Servers are part of virtual machines hosted by PDN, which is temporarily located in Suaya by Talom Sigma.

Many services, not just government-related, are hosted in the data center, indicating a broad impact.

The hyper-visor of the main virtual machine was compromised, affecting all government organization virtual machines.

The incident led to a denial of service attack, causing significant disruption.

PDN hosts more than 200 government services, and the incident affected many of them.

A disaster recovery center (DRC) exists, but it was not operational for unknown reasons during the incident.

Several services were disrupted for several days, with some now operational but still experiencing issues.

Budhar is seeking to understand the incident's cause for professional reasons, as he runs an incident response team and a cybersecurity company.

The security situation in Indonesia is comparable to other countries, with scale being the main difference due to the large population.

The scale of the incident's impact is significantly larger due to Indonesia's large internet user base.

Budhar emphasizes that while the incident is a disaster, it has not caused a significant economic disruption in Indonesia.

The main issue is the inconvenience caused to the public, rather than economic impact.

Budhar plans to update on the situation as time and resources allow, currently posting from Changi Airport.

Transcripts

play00:01

good morning this is budhar from

play00:04

bu uh on the root version I'm doing it

play00:09

I'm doing this while I'm in shangi

play00:13

actually so um this is one of those

play00:17

things that I have to uh post my video

play00:21

on my other channel actually Channel

play00:23

that I created just for this uh

play00:26

traveling session because I could not

play00:28

access my normal Channel because there's

play00:32

uh some kind of uh two Factor

play00:36

authentication that I need to do which I

play00:39

could not

play00:40

do complicated anyway so I'm here at uh

play00:43

Changi and people ask me uh about the uh

play00:48

the National Data Center the Fiasco in

play00:51

Indonesia Pat data National the national

play00:56

centralized data center so PDF uh was

play01:00

recently um attack or there was an

play01:04

incident um to our pad dat National or

play01:09

data

play01:10

center um uh to cut to cut the story

play01:13

short um uh I think it was because of a

play01:18

ransomware uh it's kind of a variations

play01:21

of lock bit I think called brain chipper

play01:25

or something like that I'm not really

play01:26

sure because I I'm still on my way back

play01:28

to Indonesia

play01:30

um I've been away

play01:32

for almost a week actually more than a

play01:35

week uh B to shansen yesterday so anyway

play01:38

going back to the the

play01:40

story how did it happen I think it

play01:43

happened on the 20th of June um there

play01:47

was an issue with uh Indonesian

play01:49

immigration server and uh they could not

play01:52

access the applications they could not

play01:54

access the uh the the uh integrated G uh

play01:57

Services you know one of those things

play01:59

that you have to go through the uh gate

play02:01

without going uh to get uh to electronic

play02:04

gate without going through um the normal

play02:07

conventional custom um the application

play02:10

um did not work so they investigated and

play02:13

they found out that their servers could

play02:15

not be uh they uh could not be accessed

play02:18

from um from the the airports um now

play02:22

these servers are part of virtual

play02:25

machines that are hosted by the uh Pat

play02:28

data National so that's that and

play02:30

apparently the pat dat national uh Sara

play02:34

Sara is it's kind of a crazy is s means

play02:39

temporar it is hosted in

play02:42

suaya by uh talom talcom Sigma I believe

play02:48

uh so they are the one who holding uh

play02:49

handling the the uh the data center and

play02:53

in this data center actually there are

play02:55

many services not just the government uh

play02:57

data center but they are hosting other

play02:59

uh companies and company other companies

play03:01

are are well except for this one um so I

play03:05

don't know what happened um but mainly

play03:09

the the I can say I guess the

play03:14

hyper hypervisor kind of the main

play03:17

virtual machine was got hit by the uh

play03:20

ransomware and all the virtual machines

play03:23

on top of that which are being used by

play03:25

Indonesian uh government uh

play03:28

organizations

play03:30

are basically collaps or dead or

play03:33

unaccessible or we can call it the

play03:35

denial of selfish

play03:37

attack because of that this is a big

play03:40

issue because of the uh scale of of of

play03:45

of this now U the pat data uh National

play03:49

the

play03:50

pdns uh is actually hosting more than

play03:53

200 uh

play03:56

comans uh so uh basically uh they're

play03:59

hosting all government services and they

play04:02

do have a a disaster recovery center I

play04:05

believe a backup site but for some

play04:08

reason it's not

play04:10

working I don't know whether the uh the

play04:12

DRC side also got hacked by this

play04:14

ransomware I'm I'm not sure um since I'm

play04:18

I'm I'm find I'm trying to find out the

play04:20

information but all the informations

play04:22

that I got are mainly from the internet

play04:25

on me from uh friends or uh chat groups

play04:29

so that's that's that's the story uh the

play04:33

service uh several Services got uh

play04:37

disrupted and I believe it took uh them

play04:41

for several days and some of the

play04:43

services are already up uh although

play04:46

there are issues now here's the thing

play04:50

that I don't understand is the the kind

play04:54

of how did this happen I don't know uh

play04:57

how that uh happened and probably the

play05:00

information is limited so it's not for

play05:03

public consumption so that's why we

play05:05

don't know anything about that but uh

play05:07

for my professional side I I need to

play05:09

find out what what it is because I'm

play05:12

also running Indonesia computer

play05:14

emergency response them and I also

play05:15

running a cyber security company and I'm

play05:18

also teaching

play05:20

incident uh response incident handling

play05:24

secure operation and incident handling

play05:26

at the University so I need to find out

play05:29

because there has to be a lesson a

play05:31

lesson or lessons learned from uh this

play05:36

incident so uh now uh questions um that

play05:40

many people ask me is that uh what is

play05:44

the the state or the situation of cyber

play05:47

security or the security situation in

play05:49

Indonesia in my opinion it is the same

play05:52

as other countries uh except that the

play05:54

scale is different what do you mean by

play05:57

scale you can imagine like the

play05:59

population of Indonesia on the internet

play06:02

I believe it's more than 200 millions

play06:05

and if you can see the population of

play06:07

other countries uh not not just the

play06:10

internet users in other countries but

play06:11

the population of other countries say

play06:13

Singapore probably only 5 million or 7

play06:16

Millions I'm not sure um Malaysia 75

play06:20

Millions I think so Millions is is

play06:22

actually a a very large number so if

play06:26

there is an issue uh or if there is a

play06:30

problem then the scale is probably 20 to

play06:33

50 times bigger than uh other countries

play06:36

because of the this the scale is what's

play06:39

What's um killing us uh other than that

play06:42

actually it's the same uh many countries

play06:44

got hit by

play06:46

ransomware I'm not trying to don'tplay

play06:48

this though but uh this is just the the

play06:52

uh the the situation of what it is okay

play06:56

so U uh what I'm trying to say here here

play06:59

is that uh it's not a big disaster big

play07:03

it is a big disaster but the scale is is

play07:07

we still uh uh don't know but it's not

play07:10

creating like a big hoopla in

play07:13

Indonesia um they're just many talks but

play07:17

in terms of economy I don't think

play07:18

there's a A disruption although

play07:21

convenience is the one that got us very

play07:25

bad anyway so so that's that I'm going

play07:29

to update if I have the time uh and

play07:31

resources to do I'm still on my way

play07:35

so and this I'm posting this from uh

play07:38

Changi Airport okay stay safe stay

play07:42

healthy and have a good one

Rate This
β˜…
β˜…
β˜…
β˜…
β˜…

5.0 / 5 (0 votes)

Related Tags
Ransomware AttackNational Data CenterIndonesiaCybersecurityIncident ResponseGovernment ServicesTravel VlogChangi AirportData BreachVirtual MachinesCybersecurity Education