🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Threat Intelligence › article

Threat Intelligence

“Voice of the People”? ./KeraSakti Claims to ‘#SaveIndonesia’ by Doxxing Its Own Students

> By Haider | Aug 04, 2026 | 3 min read

⚠️ THREAT INTELLIGENCE ADVISORY:
A newly emerged Indonesian hacktivist group calling itself ./KeraSakti has launched a series of disruptive cyber campaigns. While their defacement messages boldly claim they are fighting corruption as the “voice of the people,” their actual actions-leaking the highly sensitive personal data of innocent students-reveal a staggering level of hypocrisy.

./KeraSakti

Recent intelligence gathered from their primary Telegram channel exposes a campaign that relies heavily on patriotic hashtags like #SaveIndonesia and #SuaraRakyat (Voice of the People), while systematically victimizing the very citizens they claim to protect.

> TABLE_OF_CONTENTS [toggle]

Table of Contents

The Facade: Defacements and Grandiose Claims

The group’s operational modus operandi heavily involves web defacements and broken link hijacking targeting Indonesian educational domains (.sch.id). Victims include institutions such as MTs Wahid Hasyim, SMKN 2 Magelang, and MAN 1 Pasuruan.

Upon compromising these sites, ./KeraSakti leaves behind a manifesto set against a black background, featuring a clenched fist logo and the text: “Hacked By ./KeraSakti , Rakyat Indonesia.”

Their message attempts to justify the cybercrime as a noble crusade: “We are not criminals, we are the voice of the people! … Corruption is rampant, officials only think of their own pockets. Justice is only for those with money and power.” The manifesto concludes with a call for revolution and the hashtag #SaveIndonesia.

The Reality: Doxxing Innocent Students

If ./KeraSakti truly intended to target corrupt elites, their payload delivery entirely missed the mark. Instead of exposing high-level graft, the group escalated their campaign by dumping highly sensitive Personally Identifiable Information (PII) belonging to ordinary citizens.

Intelligence analysis of their data dumps reveals extensive lists of student and teacher records from various regional schools, including SMA N 2 Pariaman and MAN 1 Natuna. The leaked databases contain:

> COMPROMISED_DATA_RECORDS

  • Full Legal Names
  • Active Email Addresses
  • Personal Mobile Phone Numbers
  • National Identity Numbers (NIK)
  • School Affiliations

By publishing the NIK and phone numbers of minors and educators on public Telegram channels, ./KeraSakti has directly exposed these individuals to severe risks of identity theft, phishing, and financial fraud. This act contradicts every tenet of their proclaimed “pro-people” manifesto.

Collateral Damage: Municipal Data Leaks

In addition to educational institutions, the group also leaked administrative data allegedly belonging to the Pekalongan City Government (Pemerintah Kota Pekalongan). This dump included the names, NIKs, dates of birth, and specific departmental roles of municipal civil servants.

While the group may argue this targets the “government,” exposing the personal data of low-level administrative staff working in archives and libraries does nothing to combat systemic corruption. It merely harms the working-class individuals the group purports to defend.

The Hypocrisy of Modern Hacktivism

The actions of ./KeraSakti highlight a growing trend in the cyber underground: threat actors wrapping basic, opportunistic data theft in the noble guise of hacktivism.

Screaming #SuaraRakyat while doxxing your own country’s students is not a revolution; it is simply cybercrime. Until hacktivist collectives align their targeting with their political messaging, they remain indistinguishable from the malicious actors they claim to oppose.

CyberAsia strongly advises affected institutions to initiate incident response protocols and notify victims of the PII exposure. For ongoing updates on this threat actor, monitor our CyberAsia intelligence feed.


> subscribe_to_intel

Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.

> establish_connection:
[X/Twitter]
[Telegram]

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing “Voice of the People”? ./KeraSakti Claims to ‘#SaveIndonesia’ by Doxxing Its Own Students is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Cyber Threat Intelligence (CTI) Editor at CyberAsia, specializing in regional cybercrime syndicates, threat actor tracking, and dark web intelligence investigations.

> related_intel --suggest