RansomHouse Claims Leak of More Than 6 GB of Pertamina Data
Cybercriminal group RansomHouse has claimed responsibility for a data breach involving Indonesian state-owned energy company Pertamina. The allegedly stolen files include internal corporate documents and information related to employees, retirees, contractors and business partners.

The incident came to light on September 17, 2026. According to ransomware monitoring services, the attackers claim the breach took place on August 21. Cybersecurity expert Alfons Tanujaya of Vaksincom reviewed samples of the published files and estimated that the leak may involve more than 6 GB of data and thousands of documents linked to at least nine departments and around 50 user accounts. The exposed materials reportedly include financial and HR records, as well as documents related to maintenance, refinery operations, pipelines, incident investigations, cybersecurity and risk analysis.
The range of files suggests that the attackers may have gained access to a centralized file server or shared network storage rather than a single employee device. The documents span multiple departments and different time periods. However, the exact source of the compromise and the initial attack vector have not yet been identified. The available files also suggest that the incident may have affected specific entities within the Pertamina group, including units linked to PT Kilang Pertamina Internasional and PHE Jambi Merang.
The exposed data may also affect people outside Pertamina’s current workforce. One pension fund file reportedly contained around 1,600 records with names, dates of birth and employee numbers. Other published materials included personal documents, information about employees of contractors and vendors, confidentiality agreements and records involving external partners. Such information could be used in targeted phishing, social engineering and other fraud schemes.
If the exposure of personal data is confirmed, the incident may fall under Indonesia’s Personal Data Protection Law No. 27 of 2022. The law requires data controllers to notify affected individuals and the relevant authority no later than 72 hours after becoming aware of a personal data protection failure.
The cause of the attack remains unknown. Open sources had previously reported compromised credentials and vulnerabilities associated with Pertamina’s infrastructure, but there is currently no direct evidence linking them to the RansomHouse incident.
The Pertamina incident highlights the risks associated with storing sensitive information from multiple departments in shared corporate repositories. If attackers gain access to such a resource, financial, HR, technical and other confidential data may be exposed simultaneously. Regular access rights reviews, the principle of least privilege and proper segmentation of critical data can help reduce the potential impact. Once an incident has occurred, investigation and reporting tools become especially important: they help security teams reconstruct the sequence of events, determine the scope of the compromise and the data affected, collect relevant evidence, and prepare report for management and regulators. This enables organizations to respond faster and minimize the consequences of the incident.
ABOUT SEARCHINFORM
SearchInform is an information security and risk management product vendor as well as an MSS provider. The company's clients are more than 4000 companies in 20+ countries. Today, the team has products and services for comprehensive protection against insider threats at all levels of corporate information systems: FileAuditor (the DCAP class solution); DLP system with extended functionality; Risk Monitor (advanced platform for internal threat mitigation); SIEM system, Information Security outsourcing service.