Ransomware Attack on PT Indika Energy by Hunters International

Incident Date:

July 9, 2024

World map

Overview

Title

Ransomware Attack on PT Indika Energy by Hunters International

Victim

PT Indika Energy

Attacker

Hunters International

Location

Jakarta Selatan, Indonesia

, Indonesia

First Reported

July 9, 2024

Ransomware Attack on PT Indika Energy by Hunters International

Overview of PT Indika Energy

PT Indika Energy Tbk, established in 2000, is a leading integrated energy company in Indonesia. The company operates primarily in the coal mining sector through its subsidiary, PT Kideco Jaya Agung, one of Indonesia’s top coal producers. Indika Energy also provides engineering, procurement, and construction (EPC) services via its subsidiary Tripatra, and ventures into power generation through PT Indika Energy Infrastructure. The company has diversified into renewable energy and logistics services, making it a significant player in Indonesia's energy sector.

Company Size and Industry Standing

Indika Energy boasts an estimated revenue of $3 billion and employs over 7,500 individuals. The company is known for its environmentally friendly mining practices and its integrated business model, which maximizes resource utilization. Indika Energy's commitment to sustainability and operational excellence sets it apart in the energy, utilities, and waste sector.

Details of the Ransomware Attack

Hunters International, a Ransomware-as-a-Service (RaaS) group, has claimed responsibility for a ransomware attack on PT Indika Energy. This incident is the second cyberattack on the company in 2023, following a previous breach by ALPHV Ransomware in February. Hunters International has reportedly gained access to sensitive data, posing significant threats to Indika Energy's operations and security infrastructure.

About Hunters International

Hunters International emerged in Q3 of 2023, shortly after the disruption of the Hive ransomware group. The group exhibits significant technical overlap with Hive, suggesting an evolution or offshoot of the dismantled operation. Hunters International focuses on data exfiltration and extortion, targeting victims across various regions without a specific industry focus. The group has potential ties to Nigeria but uses deceptive methods to conceal its true origins.

Penetration and Vulnerabilities

The exact method of penetration used by Hunters International remains unclear, but the group's tactics often involve exploiting vulnerabilities in network security and leveraging phishing attacks. Indika Energy's previous breach by ALPHV Ransomware indicates potential weaknesses in their cybersecurity defenses, making them a target for sophisticated ransomware groups like Hunters International.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.