@ainunnajib@AmirahWahdi Saatnya kita berdoa semoga terhindar dari kefanatikan golongan ini.
Semoga Indonesia bisa lepas dari kefanatikan ormas, aliran dan daerah
🇮🇩 INDONESIA BANYUMAS REGENCY (https://t.co/5MMjPd50ug) 75M+ RECORDS CLAIM
A threat actor claims a security incident involving Banyumas Regency government systems (https://t.co/FdvIbwNPDT), alleging exposure of more than 75 million records.
The underground listing alleges categories including:
* KTP (national ID) data
* Family records
* Employee / ASN–PNS civil-servant records
* Civil documents
* Social assistance data
⚠️ Analyst Note:
A 75M+ figure for a single regency may reflect multi-table dumps, historical archives, or inflated marketing versus unique residents. Exact systems, uniqueness, freshness, and whether Banyumas production infrastructure was breached remain unverified.
We assess this as an unverified threat-actor claim involving alleged Banyumas Regency government data, NOT confirmation of a compromise of https://t.co/FdvIbwNPDT.
If authentic and non-public, national-ID, family, and social-assistance fields could enable large-scale identity fraud and phishing against Indonesian residents.
#DDW #DarkWeb #Indonesia #Government #DataBreach #PII #ThreatIntelligence #CyberSecurity
🇮🇩 INDONESIAN TAX AUTHORITY DATABASE ALLEGEDLY COMPROMISED — PASSWORDS AND AUTH TOKENS CLAIMED
A threat actor has posted what they claim is a sample from a database associated with Indonesia’s Directorate General of Taxes (Pajak), part of the Ministry of Finance.
The allegedly exposed fields include:
* Taxpayer Identification Numbers (NPWP)
* Names and email addresses
* Phone numbers and physical addresses
* Passwords
* User IDs and account roles
* IP addresses
* Last-login information
* Authentication tokens
* Remember-me tokens
* Account creation and update timestamps
⚠️ Analyst Note:
The claimed exposure of authentication material is what makes this particularly important.
If authentic and current, passwords and session/authentication tokens could potentially create risks beyond disclosure of taxpayer PII, depending on how the credentials and tokens are stored and whether they remain valid.
However, the underground post is labeled as a “sample,” and we have not independently established the number of affected accounts, source system, password format, validity of the tokens or whether the material resulted from a direct compromise of Indonesia’s tax infrastructure.
Indonesia’s official tax authority website remains operational, and we found no corresponding official breach disclosure as of September 19.
Until technically validated, this should be treated as a significant Indonesian government data-leak claim — not confirmation that the country’s tax infrastructure has been compromised.
#DDW #Indonesia #Pajak #Government #DataLeak #ThreatIntelligence
btw, kita punya buku anak gratis yang membahas tentang Indonesia sebagai negara cincin api. Judulnya 'Hikayat Cincin Api'.
Penulisnya Isyami dan Ayesha Shopie (sekaligus iustrator). Ada panduan singkat menghadapi bencana juga. Karena ini buku jenjang C, informasinya sesuai umur pembaca, ya.
Mumpung gunung api sedang banyak dibicarakan, bisa banget ini dibacakan untuk anak-anak. Siapa tahu dari mereka nanti ada yang jadi ilmuwan pemrakarsa laboratorium bencana.
Linknya ini, ya:
https://t.co/1Tgzvfz8Nu
Kalau nggak bisa bisa ke sini: https://t.co/Ftp2D4EoO2
Sebuah utas
Buku cerita anak bergambar tema bencana. Gratis. Boleh diunduh. Boleh dicetak untuk kepentingan pribadi. TAPI TIDAK BOLEH DIJUAL.
Kecuali yang memang ada link pembeliannya. FYI, saya tidak affiliate.
Silakan disebarluaskan.
Dilarang mencuri konten ini tanpa izin. 😊
Save dan share. Utas akan makin panjang kalau saya nemu buku anak tentang bencana lagi.
1. Bola Tiwi
Ditulis oleh Lina Herlina. Kolaborasi dengan Ella Elviana sebagai ilustrator. Diterbitkan oleh BPBP Jakarta bekerja sama dengan beberapa pihak.
Cerita tentang Tiwi, seorang anak, teman tuli yang pergi ke stasiun bersama ibunya. Sampai di stasiun, bola Tiwi memantul jauh. Tiwi mengejarnya, tapi, tiba-tiba gempa. Tiwi harus bagaimana?
Buku ini dilengkapi petunjut singkat melindungi diri saat gempa dan sedikit pengenalan bahasa isyarat.
Link unduh: https://t.co/5ResZ7SaRk
Kalau tidak bisa, klik ini: https://t.co/spio3Z41by
Terima kasih kepada kawan-kawan yang telah mendukung kami untuk terus memproduksi konten jurnalistik independen.
“Tiket Sukarela” dapat dikirim melalui rekening Bank Mandiri 1850004410798 (Koperasi Ekspedisi Indonesia Baru) atau E-Wallet ShopeePay/Dana/OVO/GoPay 0823 2301 8859.
@rouppme@belajarlagiHQ Semua kontrak kerja menyatakan dan atau menyiratkan semua hasil kerja adalah milik perusahaan.
Kontrak kerja adl perjanjian pertukaran waktu, ide, dan hasil kerja pekerja dengan uang dan fasilitas dari pemberi kerja
🇮🇩 Threat actors are advertising an alleged “BCA Mobile Bank Access & Database” dataset targeting Indonesian banking customers.
According to the forum post, the seller claims:
• ~890,000 mobile banking “accesses”
• ~4.9 million database records
• Banking-related personal information
• Internal/account-related fields allegedly tied to customer data
The authenticity of the claims remains unverified at this stage.
What makes this concerning is not only the volume, but the wording “accesses,” which often implies:
• Account/session access
• Credential collections
• Infostealer logs
• Mobile banking takeover potential
• Compromised customer devices
If legitimate, the combination of financial data and potential account access could enable:
• Fraudulent transactions
• SIM swapping
• Social engineering campaigns
• Account takeover attacks
• Money mule operations
• Credential stuffing against other financial platforms
And honestly… underground forums have evolved from:
“Selling hacked Netflix accounts”
to
“Would you like 4.9 million banking records with that?”
Indonesia continues to experience growing cybercriminal interest due to:
• Rapid digital banking adoption
• Large mobile-first population
• Expanding fintech ecosystem
• Increasing online payment usage
Financial institutions should closely monitor for:
• Credential abuse spikes
• Suspicious login activity
• Large-scale phishing campaigns
• Mobile malware distribution
• Unauthorized API activity
• Anomalous customer behavior patterns
Users should:
• Change banking passwords immediately if concerned
• Enable MFA wherever possible
• Avoid SMS-only authentication
• Monitor accounts for unusual activity
• Be cautious of fake banking calls/messages
At this time, the claims should be treated as alleged until independently verified.
🇮🇩 #DDW #Intelligence #Indonesia #CyberSecurity #DarkWeb #ThreatIntelligence #DataLeak #Banking #Infosec
Besok, apapun keputusan dari Majelis Hakim, akan menentukan masa depan keluarga kami. Masa depan saya sebagai seorang istri bersama kedua anak kami.
Sebelum keputusan besok, perkenankan saya membagikan setidaknya dua fakta yang sudah terungkap di persidangan.
Satu fakta dari sidang bulan lalu, kesaksian di bawah sumpah bahwa aplikasi superapp tidak pernah dirancang atau diarahkan untuk hanya bisa jalan di Chromebook.
Saksi juga menyatakan, tujuan dari superapp ini adalah melayani sebanyak mungkin guru dan murid, jadi bisa jalan di Windows juga.
@kalistohenituse No 3 sepertinya kurang tepat perbandingannya.
Beda jokowi - prabowo saat keluar negeri
- Kita khawatir di luar negeri jkw ngomong yg bikin malu
- Kita khawatir setelah pulang dr luar negeri, prabowo ngomong yg bikin malu