{"id":365,"date":"2026-08-04T15:30:00","date_gmt":"2026-08-04T15:30:00","guid":{"rendered":"https:\/\/cyberasia.io\/article\/blog\/voice-of-the-people-kerasakti-claims-to-saveindonesia-by-doxxing-its-own-students\/"},"modified":"2026-08-17T08:58:42","modified_gmt":"2026-08-17T08:58:42","slug":"voice-of-the-people-kerasakti-claims-to-saveindonesia-by-doxxing-its-own-students","status":"publish","type":"post","link":"https:\/\/cyberasia.io\/article\/threat-intelligence\/voice-of-the-people-kerasakti-claims-to-saveindonesia-by-doxxing-its-own-students\/","title":{"rendered":"&#8220;Voice of the People&#8221;? .\/KeraSakti Claims to &#8216;#SaveIndonesia&#8217; by Doxxing Its Own Students"},"content":{"rendered":"<p style=\"background-color: #0f0f0f;color: #ffffff;padding: 15px;border-left: 5px solid #ef4444;border-radius: 4px;font-size: 16px;margin-bottom: 25px;line-height: 1.8\"><strong style=\"color: #f97316\">\u26a0\ufe0f THREAT INTELLIGENCE ADVISORY:<\/strong><br \/>\nA newly emerged Indonesian hacktivist group calling itself <strong style=\"color: #f97316\">.\/KeraSakti<\/strong> has launched a series of disruptive cyber campaigns. While their defacement messages boldly claim they are fighting corruption as the \u201cvoice of the people,\u201d their actual actions-leaking the highly sensitive personal data of innocent students-reveal a staggering level of hypocrisy.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/upload-1785256149-0.png\" alt=\".\/KeraSakti\" style=\"max-width:100%;height:auto\" \/ loading=\"eager\" fetchpriority=\"high\"><\/p>\n<p>Recent intelligence gathered from their primary Telegram channel exposes a campaign that relies heavily on patriotic hashtags like <code>#SaveIndonesia<\/code> and <code>#SuaraRakyat<\/code> (Voice of the People), while systematically victimizing the very citizens they claim to protect.<\/p>\n<h2  style=\"color: #facc15;\">Table of Contents<\/h2>\n<ul>\n<li><a href=\"#defacements\">The Facade: Defacements and Grandiose Claims<\/a><\/li>\n<li><a href=\"#reality\">The Reality: Doxxing Innocent Students<\/a><\/li>\n<li><a href=\"#government\">Collateral Damage: Municipal Data Leaks<\/a><\/li>\n<li><a href=\"#conclusion\">The Hypocrisy of Modern Hacktivism<\/a><\/li>\n<\/ul>\n<h2 id=\"defacements\"  style=\"color: #facc15;\">The Facade: Defacements and Grandiose Claims<\/h2>\n<p>The group\u2019s operational modus operandi heavily involves web defacements and broken link hijacking targeting Indonesian educational domains (<code>.sch.id<\/code>). Victims include institutions such as MTs Wahid Hasyim, SMKN 2 Magelang, and MAN 1 Pasuruan.<\/p>\n<p>Upon compromising these sites, <strong style=\"color: #f97316\">.\/KeraSakti<\/strong> leaves behind a manifesto set against a black background, featuring a clenched fist logo and the text: <em>\u201cHacked By .\/KeraSakti ,  Rakyat Indonesia.\u201d<\/em><\/p>\n<p>Their message attempts to justify the cybercrime as a noble crusade: <em>\u201cWe are not criminals, we are the voice of the people! \u2026 Corruption is rampant, officials only think of their own pockets. Justice is only for those with money and power.\u201d<\/em> The manifesto concludes with a call for revolution and the hashtag <strong style=\"color: #f97316\">#SaveIndonesia<\/strong>.<\/p>\n<h2 id=\"reality\"  style=\"color: #facc15;\">The Reality: Doxxing Innocent Students<\/h2>\n<p>If <strong style=\"color: #f97316\">.\/KeraSakti<\/strong> truly intended to target corrupt elites, their payload delivery entirely missed the mark. Instead of exposing high-level graft, the group escalated their campaign by dumping highly sensitive Personally Identifiable Information (PII) belonging to ordinary citizens.<\/p>\n<p>Intelligence analysis of their data dumps reveals extensive lists of student and teacher records from various regional schools, including SMA N 2 Pariaman and MAN 1 Natuna. The leaked databases contain:<\/p>\n<div style=\"border: 1px solid #ef4444;border-radius: 4px;padding: 16px;margin: 20px 0\">\n    <strong style=\"font-family: 'Fira Code', monospace;color: #ef4444\">> COMPROMISED_DATA_RECORDS<\/strong><\/p>\n<ul style=\"margin-top: 12px;margin-bottom: 0;padding-left: 24px;color: #a1a1aa;font-size: 0.95rem\">\n<li style=\"margin-bottom: 5px\">Full Legal Names<\/li>\n<li style=\"margin-bottom: 5px\">Active Email Addresses<\/li>\n<li style=\"margin-bottom: 5px\">Personal Mobile Phone Numbers<\/li>\n<li style=\"margin-bottom: 5px\">National Identity Numbers (NIK)<\/li>\n<li style=\"margin-bottom: 0\">School Affiliations<\/li>\n<\/ul>\n<\/div>\n<p>By publishing the NIK and phone numbers of minors and educators on public Telegram channels, <strong style=\"color: #f97316\">.\/KeraSakti<\/strong> has directly exposed these individuals to severe risks of identity theft, phishing, and financial fraud. This act contradicts every tenet of their proclaimed \u201cpro-people\u201d manifesto.<\/p>\n<h2 id=\"government\"  style=\"color: #facc15;\">Collateral Damage: Municipal Data Leaks<\/h2>\n<p>In addition to educational institutions, the group also leaked administrative data allegedly belonging to the Pekalongan City Government (Pemerintah Kota Pekalongan). This dump included the names, NIKs, dates of birth, and specific departmental roles of municipal civil servants.<\/p>\n<p>While the group may argue this targets the \u201cgovernment,\u201d exposing the personal data of low-level administrative staff working in archives and libraries does nothing to combat systemic corruption. It merely harms the working-class individuals the group purports to defend.<\/p>\n<h2 id=\"conclusion\"  style=\"color: #facc15;\">The Hypocrisy of Modern Hacktivism<\/h2>\n<p>The actions of <strong style=\"color: #f97316\">.\/KeraSakti<\/strong> highlight a growing trend in the cyber underground: threat actors wrapping basic, opportunistic data theft in the noble guise of hacktivism.<\/p>\n<p>Screaming <code>#SuaraRakyat<\/code> while doxxing your own country\u2019s students is not a revolution; it is simply cybercrime. Until hacktivist collectives align their targeting with their political messaging, they remain indistinguishable from the malicious actors they claim to oppose.<\/p>\n<p>CyberAsia strongly advises affected institutions to initiate incident response protocols and notify victims of the PII exposure. For ongoing updates on this threat actor, monitor our <a href=\"https:\/\/cyberasia.io\/\">CyberAsia intelligence feed<\/a>.<\/p>\n<hr style=\"border: 1px solid #333;margin: 40px 0\">\n<div style=\"padding: 20px;border: 1px solid #facc15;border-radius: 4px\">\n<h3 style=\"color: #facc15;margin-top: 0;font-family: 'Fira Code', monospace\">> subscribe_to_intel<\/h3>\n<p style=\"color: #9ca3af;font-size: 0.95rem\">Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. <a href=\"https:\/\/cyberasia.io\/privacy-policy\/\" style=\"color: #9ca3af;text-decoration: underline\">Privacy Policy<\/a>.<\/p>\n<div style=\"display: flex;gap: 10px;margin-top: 15px;flex-wrap: wrap\">\n<p>        <button type=\"button\" style=\"padding: 10px 20px;background: #facc15;color: #000;border: none;font-weight: bold;cursor: pointer;font-family: 'Fira Code', monospace\">> initialize<\/button>\n    <\/div>\n<\/div>\n<div style=\"margin-top: 20px;font-size: 0.95rem;font-family: 'Fira Code', monospace\">\n    <span style=\"color: #9ca3af\">> establish_connection: <\/span><br \/>\n    <a href=\"https:\/\/twitter.com\/cyberasia_io\" target=\"_blank\" style=\"color: #facc15;text-decoration: none;margin-right: 15px\" rel=\"noopener\">[X\/Twitter]<\/a><br \/>\n    <a href=\"https:\/\/t.me\/cyberasiaio\" target=\"_blank\" style=\"color: #facc15;text-decoration: none;margin-right: 15px\">[Telegram]<\/a>\n<\/div>\n<h3>Mitigation &#038; Prevention Strategies<\/h3>\n<p>Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:<\/p>\n<ul>\n<li><strong>Patch Management:<\/strong> Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.<\/li>\n<li><strong>Isolate OT Networks:<\/strong> SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.<\/li>\n<li><strong>Continuous Monitoring:<\/strong> Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.<\/li>\n<\/ul>\n<hr>\n","protected":false},"excerpt":{"rendered":"<p>\u26a0\ufe0f THREAT INTELLIGENCE ADVISORY: A newly emerged Indonesian hacktivist group calling itself .\/KeraSakti has launched a series of disruptive cyber campaigns. While their defacement messages boldly claim they are fighting corruption as the \u201cvoice of the people,\u201d their actual actions-leaking the highly sensitive personal data of innocent students-reveal a staggering level of hypocrisy. Recent intelligence [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":364,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[254,157,13,172,255,257,256],"threat_actors":[],"class_list":["post-365","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-intelligence","tag-kerasakti","tag-cyber-crime","tag-data-breach","tag-defacement","tag-hacktivist-indonesia","tag-hypocrisy","tag-student-data-leak"],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/comments?post=365"}],"version-history":[{"count":7,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/365\/revisions"}],"predecessor-version":[{"id":3890,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/365\/revisions\/3890"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media\/364"}],"wp:attachment":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media?parent=365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/categories?post=365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/tags?post=365"},{"taxonomy":"threat_actor","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors?post=365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}