BianLian Ransomware Attack on PT Pelabuhan Indonesia (Persero)

Year

2023

Month

October

Reference number

20231002

Impact area

Shore

Incident location

Indonesia

Incident country

Indonesia

Victim country

Indonesia

Victim identity

Peloindo

Victim Type

Port operation company

Method

Ransomware

Summary:

In October 2023, PT Pelabuhan Indonesia (Persero), trading as Pelindo, an Indonesian state-owned port operation company, experienced a data breach attributed to the BianLian ransomware group. The breach resulted in the exfiltration of 200GB of data, including SQL and ORACLE databases, source code APIs, internal technical documentation, and development information for ICT solutions. The BianLian group, which has shifted its focus from encrypting files to solely exfiltrating data for extortion, has breached multiple high-profile organizations since its appearance in July 2022. Despite Avast releasing a free decryptor in January 2023, BianLian continues to operate, listing 118 victim organizations on its extortion portal, with 71% being U.S.-based. The group leverages legal and regulatory risks to coerce victims into paying, promising not to leak stolen data if paid. The attack on Pelindo was reported by RedPacket Security, which clarified that they are not affiliated with the attackers and do not host any infringing content.

Reference URL

https://www.breachsense.com/breaches/pelindo-data-breach/
https://www.bleepingcomputer.com/news/security/bianlian-ransomware-gang-shifts-focus-to-pure-data-extortion/
https://www.redpacketsecurity.com/bianlian-ransomware-victim-pelindo/