Threat Intelligence
~/ › Threat Intelligence › article
Massive OpSec Failure: Indonesian Hacktivists Dox Themselves via WhatsApp Links
> By Haider | Aug 04, 2026 | 3 min read
⚠️ THREAT INTELLIGENCE ADVISORY:
In what can only be described as a catastrophic operational security (OpSec) failure, two Indonesian hacktivist groups-Tegal Cyber Team and For Close System (F.C.S)-have inadvertently doxxed themselves. While attempting to project strength by announcing a new cyber alliance, the threat actors published direct WhatsApp group invite links, exposing the personal phone numbers of their administrators and members to law enforcement and threat researchers.

This incident underscores a recurring theme in the modern hacktivist landscape: a severe lack of fundamental security practices among politically motivated actors, often rendering them vulnerable to immediate de-anonymization.
Table of Contents
The “Invincible” Alliance Announcement
The incident began when the administrator of the “For Close System , F.C.S” Telegram channel, operating under the moniker “Mr puttzy,” published a highly stylized, AI-generated graphic. The image depicted two figures shaking hands-one in a Guy Fawkes mask, the other in a mafia-style fedora-under the banner: “ALIANSI: Bersatu Dalam Tujuan, Tak Terkalahkan Dalam Aksi” (Alliance: United in purpose, invincible in action).
The post officially announced the merger of the Tegal Cyber Team (a group originating from Central Java, Indonesia) and For Close System. However, their attempt at intimidating cyber-branding was immediately undermined by the text that followed.
The WhatsApp Trap: A Rookie OpSec Failure
In an effort to recruit followers or streamline communications, “Mr puttzy” included direct chat.whatsapp.com invite links for both the Tegal Cyber Team and the For Close System groups in the public Telegram post.
Unlike Telegram (which allows users to hide their phone numbers and communicate purely via usernames), WhatsApp intrinsically ties every user account to a physical, verified mobile phone number. By distributing these invite links publicly, the hacktivists committed a cardinal OpSec Failure:
- Instant De-anonymization: Any intelligence analyst, rival hacker, or law enforcement agent clicking the link can view the participant list of the group.
- Admin Exposure: Group creators and administrators are clearly labeled, immediately exposing the primary threat actors’ personal mobile numbers.
- Collateral Damage: Followers who join the group believing it to be a secure channel are instantly exposing their own identities to everyone else in the chat.
Implications for Law Enforcement
In Indonesia, SIM card registration requires the submission of a valid National Identity Number (NIK) and Family Card (KK). Therefore, a leaked Indonesian phone number is effectively a direct pipeline to the individual’s legal identity, home address, and familial connections.
By publishing these WhatsApp links, the Tegal Cyber Team and For Close System have essentially handed their dossiers directly to the Indonesian National Police (Polri) Cyber Crime division. Tracking these threat actors no longer requires complex digital forensics or ISP subpoenas; it only requires opening a chat app.
The Illusion of Anonymity
This incident serves as a stark reminder that many modern hacktivist collectives rely heavily on bravado and AI-generated imagery to project capability, while severely lacking the technical discipline required for long-term survival in the cyber underground.
An alliance cannot be “invincible in action” if its core members inadvertently surrender their identities before launching a single attack.
CyberAsia will continue to monitor the fallout of this massive OpSec failure. See CyberAsia updates for the latest threat intelligence.
> subscribe_to_intel
Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Massive OpSec Failure: Indonesian Hacktivists Dox Themselves via WhatsApp Links is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
Threat Intelligence
Threat Intelligence
Hacker vs Hacktivist: 5 Dangerous Differences in Modern Cyber Warfare
> read
Threat Intelligence