Year2023 |
MonthOctober |
Reference number20231002 |
Impact areaShore |
Incident locationIndonesia |
Incident countryIndonesia |
Victim countryIndonesia |
Victim identityPeloindo |
Victim TypePort operation company |
MethodRansomware |
In October 2023, PT Pelabuhan Indonesia (Persero), trading as Pelindo, an Indonesian state-owned port operation company, experienced a data breach attributed to the BianLian ransomware group. The breach resulted in the exfiltration of 200GB of data, including SQL and ORACLE databases, source code APIs, internal technical documentation, and development information for ICT solutions. The BianLian group, which has shifted its focus from encrypting files to solely exfiltrating data for extortion, has breached multiple high-profile organizations since its appearance in July 2022. Despite Avast releasing a free decryptor in January 2023, BianLian continues to operate, listing 118 victim organizations on its extortion portal, with 71% being U.S.-based. The group leverages legal and regulatory risks to coerce victims into paying, promising not to leak stolen data if paid. The attack on Pelindo was reported by RedPacket Security, which clarified that they are not affiliated with the attackers and do not host any infringing content.