Ransomware Attack on PT Indika Energy by Hunters International

Incident Date: Jul 09, 2024

Attack Overview
VICTIM
PT Indika Energy
INDUSTRY
Energy, Utilities & Waste
LOCATION
Indonesia
ATTACKER
Hunters International
FIRST REPORTED
July 9, 2024

Ransomware Attack on PT Indika Energy by Hunters International

Overview of PT Indika Energy

PT Indika Energy Tbk, established in 2000, is a leading integrated energy company in Indonesia. The company operates primarily in the coal mining sector through its subsidiary, PT Kideco Jaya Agung, one of Indonesia’s top coal producers. Indika Energy also provides engineering, procurement, and construction (EPC) services via its subsidiary Tripatra, and ventures into power generation through PT Indika Energy Infrastructure. The company has diversified into renewable energy and logistics services, making it a significant player in Indonesia's energy sector.

Company Size and Industry Standing

Indika Energy boasts an estimated revenue of $3 billion and employs over 7,500 individuals. The company is known for its environmentally friendly mining practices and its integrated business model, which maximizes resource utilization. Indika Energy's commitment to sustainability and operational excellence sets it apart in the energy, utilities, and waste sector.

Details of the Ransomware Attack

Hunters International, a Ransomware-as-a-Service (RaaS) group, has claimed responsibility for a ransomware attack on PT Indika Energy. This incident is the second cyberattack on the company in 2023, following a previous breach by ALPHV Ransomware in February. Hunters International has reportedly gained access to sensitive data, posing significant threats to Indika Energy's operations and security infrastructure.

About Hunters International

Hunters International emerged in Q3 of 2023, shortly after the disruption of the Hive ransomware group. The group exhibits significant technical overlap with Hive, suggesting an evolution or offshoot of the dismantled operation. Hunters International focuses on data exfiltration and extortion, targeting victims across various regions without a specific industry focus. The group has potential ties to Nigeria but uses deceptive methods to conceal its true origins.

Penetration and Vulnerabilities

The exact method of penetration used by Hunters International remains unclear, but the group's tactics often involve exploiting vulnerabilities in network security and leveraging phishing attacks. Indika Energy's previous breach by ALPHV Ransomware indicates potential weaknesses in their cybersecurity defenses, making them a target for sophisticated ransomware groups like Hunters International.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.