INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On January 28, 2025, the babuk2 ransomware group listed Indonesia Taxpayer Identification Number (NPWP) data on its leak site, indicating that internal files had been exfiltrated. Individuals are advised to verify whether their records appear in the listing and to monitor their accounts for any unusual activity.
For millions of Indonesians who rely on the national tax system, the appearance of taxpayer identification records on a ransomware leak site raises immediate practical concerns. Personal identifiers, financial histories, and contact details tied to tax filings are among the most sensitive categories of data a government holds, and any unauthorized access can create lasting risks of fraud or misuse.
On 28 January 2025, the ransomware group known as babuk2 listed INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) on its leak site, claiming to have exfiltrated internal files. Public information about the incident remains limited: the number of people affected is unknown, and no detailed inventory of the stolen material has been released. What is known is that the listing itself signals a claimed ransomware attack involving data theft.
What happened
According to the available record, INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) was listed by the babuk2 ransomware group on 28 January 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further operational details—such as the date of initial access, the method of intrusion, the volume of data taken, or any ransom demand—have been publicly confirmed. The number of individuals whose information may be involved is listed as unknown. At present, the listing constitutes an unverified claim by the threat actor rather than an independently verified disclosure by the affected organisation.
Who is babuk2?
Babuk2 is a ransomware operation that has appeared in public reporting as a successor or rebranded variant of earlier Babuk activity. Like many ransomware groups, it typically employs a double-extortion model: encrypting systems while also stealing data and threatening to publish it if payment is not made. The group has been observed listing victims on dedicated leak sites and has previously targeted organisations across multiple sectors and regions. Its tactics generally include initial access through common vectors such as compromised credentials or unpatched systems, followed by lateral movement and data exfiltration before encryption. Specific claims made by babuk2 about any individual victim, including the present listing of INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP), should be treated as assertions by the group until corroborated by independent evidence.
About INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP)
NPWP is Indonesia’s official Taxpayer Identification Number system, administered by the Directorate General of Taxes under the Ministry of Finance. It serves as the unique identifier for individuals and entities required to file taxes, pay duties, or interact with government financial services. Organisations of this type routinely maintain large databases containing personal identification details, addresses, income information, tax returns, and related administrative records. Because the NPWP underpins tax compliance, banking relationships, and many official transactions across the country, a breach involving its systems carries consequences that extend well beyond a single agency. Any compromise of such records can affect citizens’ ability to manage their tax affairs securely and can expose them to secondary risks if the data is later misused.
What was likely exposed
The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No specific categories—such as names, NPWP numbers, addresses, income figures, or contact details—have been confirmed as part of the claimed theft. Organisations that manage national taxpayer identification systems typically hold precisely these kinds of records, along with supporting administrative and audit documentation. However, because the exact contents of the files claimed by babuk2 remain undisclosed, it is not possible to state with certainty what information was taken. Readers should treat any assumption about particular data elements as unconfirmed.
Why it matters
When tax-related personal data is exposed, the practical risks for individuals include identity theft, fraudulent tax filings, unsolicited contact, and attempts to open financial accounts in their name. Even limited internal files can contain enough identifiers to enable social-engineering attacks or to be combined with other leaked datasets. For the organisation itself, a ransomware incident can disrupt tax-administration services, erode public trust, and require extensive recovery and notification efforts. Because the scale of the claimed breach is unknown, the full extent of these risks cannot yet be quantified, but the sensitivity of taxpayer records means that even a partial exposure warrants careful attention from those who may be affected.
If your data was in this claimed breach
If you hold an Indonesian NPWP or have filed taxes through the national system, treat the possibility of exposure seriously even while details remain limited. Monitor your tax account and any linked financial services for unexpected activity, and consider placing fraud alerts with relevant credit or identity-protection services if available in your jurisdiction. Change passwords on government portals and email accounts associated with tax correspondence, and enable multi-factor authentication wherever it is offered. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets. Remain cautious of unsolicited messages that reference tax matters or request personal details, as such communications may attempt to exploit public awareness of the incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) Listed by babuk2 Ransomware GroupBangladesh Armed Forces (BangLadesh Army) Listed by babuk2 Ransomware GroupSaudi Arabian military and government internal center Listed by babuk2 Ransomware Grouppln.co.id - PLN INDONESIA Listed by babuk2 Ransomware GroupLatest breaches
Publicly posted by babuk2 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.