linebank.co.id Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
linebank.co.id was listed by the apt73 ransomware group on December 23, 2024, with an undisclosed number of people potentially affected by the exposure of internal files. Users are advised to check whether their information was involved and to monitor their accounts for any unusual activity.
On December 23, 2024, linebank.co.id, an Indonesian digital banking platform, was listed by the apt73 ransomware group. The group claims to have carried out a ransomware attack that included the exfiltration of internal files. The number of people affected is unknown, and public detail on the incident remains limited. For customers and others whose information may have been held by the organisation, the listing raises questions about what data left the network and what practical steps follow.
What is confirmed so far is only the public claim on the group's leak site and the reported characterisation of the material as internal files from an Indonesia digital banking environment that may include personal information. No independent confirmation of the breach's full scope or contents has been provided in the available record.
What happened
According to the available record, linebank.co.id was listed by apt73 on or around December 23, 2024. The listing describes a ransomware attack in which internal files were allegedly exfiltrated. No further operational details—such as the precise date the intrusion began, how initial access was obtained, whether encryption was deployed alongside theft, or the volume of data taken—have been disclosed publicly. The number of individuals whose information may be involved is listed as unknown. The reported summary characterises the organisation as Indonesia digital banking and notes personal information in connection with the claim. Beyond that listing and summary, the public facts do not establish additional timeline, scale, or technical method.
Ransomware incidents of this type typically involve both data theft and a threat to publish or sell the material if demands are not met. In this case, the only concrete public assertion is the group's own listing of the victim and the description of exfiltrated internal files. Whether the organisation has confirmed the incident, notified regulators, or begun remediation is not stated in the available facts.
Inside apt73
apt73 is a ransomware group that has appeared in public reporting as an actor that lists claimed victims on dedicated leak sites. Like many contemporary ransomware operations, groups operating under such names commonly practice double extortion: they exfiltrate data before or during encryption and then threaten to release it. Public documentation of the broader ransomware ecosystem shows that such actors often target organisations holding valuable operational or customer records, post sample files or file lists to pressure victims, and maintain leak sites as both a negotiation tool and a reputation mechanism within criminal forums.
The listing of linebank.co.id should be treated as a claim by the group rather than independently verified fact. No additional statements attributed to apt73 about this specific victim—beyond the fact of the listing and the description of internal-file exfiltration—are present in the provided record. Established public knowledge of ransomware groups in general indicates they frequently exaggerate or selectively present stolen material; therefore the precise contents and completeness of any claimed haul remain unconfirmed until corroborated by the victim organisation or independent analysis.
Who is linebank.co.id?
linebank.co.id operates in Indonesia's digital banking sector. Digital banks and online banking platforms in that market typically provide account services, payments, transfers, and related financial products through web and mobile channels. Organisations of this kind routinely hold customer identity data, contact details, account identifiers, transaction records, and authentication-related information necessary to operate regulated financial services.
A breach claim against such an entity is consequential because the data held is both personally sensitive and financially actionable. Even when the exact files taken are not fully catalogued in public reporting, the sector context means that any successful exfiltration of internal systems can place customer records, internal documentation, or operational data at risk of misuse. The available facts do not describe the organisation's size, customer base, or security posture; they simply identify it as the listed entity in an Indonesia digital banking context.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack and that the reported summary references personal information in connection with Indonesia digital banking. No itemised inventory of file types, databases, or record counts has been disclosed. The number of people affected is explicitly unknown.
Organisations in digital banking typically maintain customer personal data (names, identification numbers, addresses, phone numbers, email addresses), account and transaction information, and internal operational documents. It is therefore possible that material of those kinds was among the internal files claimed by the group. However, the exact contents remain unconfirmed. Public statements should not treat any specific category of data as proven until the organisation or a competent authority provides a verified description. Readers should regard the exposure as a claimed exfiltration of internal files that may include personal information, not as a fully documented catalogue of every record taken.
What's at stake
For individuals, the primary risks associated with personal information leaving a banking environment are identity misuse, targeted phishing or social-engineering attempts that reference real account details, and potential financial fraud if account or authentication data were included. Even partial records can be combined with data from other incidents to increase the credibility of scams. For the organisation, a claimed or claimed ransomware incident can trigger regulatory scrutiny, customer notification obligations, reputational damage, and the operational cost of investigation and recovery.
Because the scale is unknown and the precise data types are not fully enumerated in public sources, the concrete impact on any given person cannot yet be measured from the available record alone. The prudent stance is to treat the claim seriously enough to take protective steps while recognising that not every listing results in the wholesale release of every customer record.
If your data was in this claimed breach
If you hold or previously held an account or relationship with linebank.co.id, begin with basic hygiene: monitor account statements and login notifications for unexpected activity, change passwords and enable multi-factor authentication where available, and be alert to unsolicited messages that reference banking details or urge urgent action. Consider placing fraud alerts with relevant credit or identity services if you are in a jurisdiction that offers them. Avoid clicking links in unexpected emails or messages claiming to be from the bank; instead navigate directly to official channels.
Because the full list of affected individuals is unknown, one practical check is to run a free exposure scan of your email address against known breach data sets. That will not confirm or deny presence in this specific incident, but it can show whether your address has already appeared in other publicly documented breaches and help you prioritise further monitoring. Stay attentive to any official notices the organisation may issue; those remain the authoritative source for Reported Details about this event.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
bri.co.id Listed by apt73 Ransomware Groupfederalbank.co.in (PART1) Listed by apt73 Ransomware Groupfederalbank.co.in Listed by apt73 Ransomware Groupbankily.mr Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the linebank.co.id Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.