Threat Intelligence
~/ › Threat Intelligence › article
“Voice of the People”? ./KeraSakti Claims to ‘#SaveIndonesia’ by Doxxing Its Own Students
> By Haider | Aug 04, 2026 | 3 min read
⚠️ THREAT INTELLIGENCE ADVISORY:
A newly emerged Indonesian hacktivist group calling itself ./KeraSakti has launched a series of disruptive cyber campaigns. While their defacement messages boldly claim they are fighting corruption as the “voice of the people,” their actual actions-leaking the highly sensitive personal data of innocent students-reveal a staggering level of hypocrisy.

Recent intelligence gathered from their primary Telegram channel exposes a campaign that relies heavily on patriotic hashtags like #SaveIndonesia and #SuaraRakyat (Voice of the People), while systematically victimizing the very citizens they claim to protect.
Table of Contents
- The Facade: Defacements and Grandiose Claims
- The Reality: Doxxing Innocent Students
- Collateral Damage: Municipal Data Leaks
- The Hypocrisy of Modern Hacktivism
The Facade: Defacements and Grandiose Claims
The group’s operational modus operandi heavily involves web defacements and broken link hijacking targeting Indonesian educational domains (.sch.id). Victims include institutions such as MTs Wahid Hasyim, SMKN 2 Magelang, and MAN 1 Pasuruan.
Upon compromising these sites, ./KeraSakti leaves behind a manifesto set against a black background, featuring a clenched fist logo and the text: “Hacked By ./KeraSakti , Rakyat Indonesia.”
Their message attempts to justify the cybercrime as a noble crusade: “We are not criminals, we are the voice of the people! … Corruption is rampant, officials only think of their own pockets. Justice is only for those with money and power.” The manifesto concludes with a call for revolution and the hashtag #SaveIndonesia.
The Reality: Doxxing Innocent Students
If ./KeraSakti truly intended to target corrupt elites, their payload delivery entirely missed the mark. Instead of exposing high-level graft, the group escalated their campaign by dumping highly sensitive Personally Identifiable Information (PII) belonging to ordinary citizens.
Intelligence analysis of their data dumps reveals extensive lists of student and teacher records from various regional schools, including SMA N 2 Pariaman and MAN 1 Natuna. The leaked databases contain:
- Full Legal Names
- Active Email Addresses
- Personal Mobile Phone Numbers
- National Identity Numbers (NIK)
- School Affiliations
By publishing the NIK and phone numbers of minors and educators on public Telegram channels, ./KeraSakti has directly exposed these individuals to severe risks of identity theft, phishing, and financial fraud. This act contradicts every tenet of their proclaimed “pro-people” manifesto.
Collateral Damage: Municipal Data Leaks
In addition to educational institutions, the group also leaked administrative data allegedly belonging to the Pekalongan City Government (Pemerintah Kota Pekalongan). This dump included the names, NIKs, dates of birth, and specific departmental roles of municipal civil servants.
While the group may argue this targets the “government,” exposing the personal data of low-level administrative staff working in archives and libraries does nothing to combat systemic corruption. It merely harms the working-class individuals the group purports to defend.
The Hypocrisy of Modern Hacktivism
The actions of ./KeraSakti highlight a growing trend in the cyber underground: threat actors wrapping basic, opportunistic data theft in the noble guise of hacktivism.
Screaming #SuaraRakyat while doxxing your own country’s students is not a revolution; it is simply cybercrime. Until hacktivist collectives align their targeting with their political messaging, they remain indistinguishable from the malicious actors they claim to oppose.
CyberAsia strongly advises affected institutions to initiate incident response protocols and notify victims of the PII exposure. For ongoing updates on this threat actor, monitor our CyberAsia intelligence feed.
> subscribe_to_intel
Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing “Voice of the People”? ./KeraSakti Claims to ‘#SaveIndonesia’ by Doxxing Its Own Students is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
Threat Intelligence
Threat Intelligence
Hacker vs Hacktivist: 5 Dangerous Differences in Modern Cyber Warfare
> read
Threat Intelligence