Mochtar Karuwin Komar: Indonesian law firm - MKK Listed by crypto24 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Mochtar Karuwin Komar, an Indonesian law firm, was listed by the crypto24 ransomware group on April 08, 2025, after internal files were exfiltrated in a ransomware attack. Because the number of individuals affected is undisclosed, anyone connected to the firm should check for official notices and follow recommended security steps.
On April 8, 2025, the Indonesian law firm Mochtar Karuwin Komar, also known as MKK, was listed by the ransomware group crypto24. Public reporting indicates that internal files were exfiltrated in a ransomware attack, with the named categories including legal advice, case-related documents, financial information, contracts, and billing materials. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.
This matters because law firms routinely handle confidential client matters and sensitive commercial records. When such material is claimed to have been taken, the potential consequences extend beyond the firm itself to clients, counterparties, and anyone whose information appears in those files. At present the listing stands as a claim by the group rather than an independently verified confirmation of every asserted detail.
Breaking down the breach
According to the available record, Mochtar Karuwin Komar was listed by crypto24 on or around April 8, 2025. The incident is described as a ransomware attack in which internal files were allegedly exfiltrated. The data types identified in reporting are legal advice, case-related documents, financial information, contracts, and billing. No figure has been published for the volume of data taken, the number of individuals affected, or the precise method of initial access. Timing of the intrusion itself, beyond the listing date, is undisclosed. Public detail is therefore limited to the group’s claim of exfiltration and the categories of material named above.
Ransomware incidents of this type typically involve both encryption of systems and theft of data for leverage. In this case the facts state only that files were reported as exfiltrated and that the firm appeared on the group’s listing. No independent confirmation of the full scope or of any ransom demand has been provided in the source material.
Who is crypto24?
crypto24 is a ransomware operation that has appeared in public reporting as a group that targets organizations, encrypts their systems, and exfiltrates data before posting victims on a leak site. Like many contemporary ransomware actors, it employs a double-extortion model: the threat of permanent data loss through encryption is paired with the threat of public release of stolen files if payment is not made. The group’s listings are claims intended to apply pressure; they do not by themselves constitute verified proof of every detail asserted about a particular victim.
Public knowledge of crypto24 centers on its pattern of selecting organizational targets, moving laterally once inside a network, and advertising stolen data to compel negotiation. No statements attributed specifically to crypto24 about Mochtar Karuwin Komar beyond the listing itself are included in the facts. Therefore any description of this incident remains framed as the group’s claim rather than established fact.
Mochtar Karuwin Komar and its sector
Mochtar Karuwin Komar is an Indonesian law firm. Law firms in general maintain large volumes of privileged and confidential material: client correspondence, legal opinions, litigation files, transactional documents, billing records, and financial information related to both the firm and its clients. These records often contain personal identifiers, commercial secrets, and strategy discussions that are protected by professional secrecy rules.
A breach affecting a firm of this type is consequential because the data is not merely internal operational material; it frequently belongs to or concerns third parties who entrusted the firm with sensitive matters. Exposure can undermine attorney-client privilege, create competitive or litigation disadvantages for clients, and generate regulatory or reputational issues for the firm. The exact size of MKK’s practice and the full range of its client base are not detailed in the breach record, but the sector-wide sensitivity of legal data is well established.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack, specifically listing legal advice, case-related documents, financial information, contracts, and billing. These categories align with the kinds of records a law firm would be expected to hold. No further inventory—such as exact file counts, named clients, or confirmation that every listed category was in fact taken—has been published.
Organizations of this kind typically also store contact details, identification documents, bank information, and correspondence that could identify individuals. Because the precise contents remain unconfirmed beyond the named categories, it is not possible to state with certainty which specific records or whose personal data were included. The listing asserts that such internal files were taken; independent verification of the complete set is not part of the public record.
The real-world impact
For individuals whose information appears in the files, the concrete risks include unauthorized access to legal strategies, financial details, or personal identifiers that could be used for fraud, social engineering, or further targeting. Clients may face exposure of privileged communications or commercial terms that were never intended for public view. Counterparties named in contracts or case documents could likewise see sensitive positions revealed.
For the firm, the consequences can include operational disruption from any encryption component of the attack, potential regulatory scrutiny under data-protection or professional-conduct rules, loss of client trust, and the cost of investigation and remediation. Because the number of people affected is unknown and the full data set is unconfirmed, the scale of individual harm cannot yet be quantified. The impact remains real in principle even while many specifics stay undisclosed.
If your data was in this claimed breach
If you have reason to believe your information may have been held by Mochtar Karuwin Komar, begin by monitoring financial accounts and credit activity for unusual transactions. Consider placing fraud alerts with relevant credit bureaus where available, and be cautious of unsolicited communications that reference legal or financial matters, as these can be used in phishing attempts. Change passwords on any accounts that may have shared credentials or recovery information with the firm, and enable multi-factor authentication wherever possible.
Retain any notices you receive from the firm or from authorities, and follow official guidance if it is issued. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides one additional data point but does not replace vigilance or direct communication with the organization involved. Public detail on this incident remains limited, so continued caution is warranted until more verified information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Yource Bulgaria & Greece Listed by crypto24 Ransomware GroupBayu Buana Travel Listed by crypto24 Ransomware GroupBayu Buana Travel Service Listed by crypto24 Ransomware GroupSOUBEIRAN CHOBET S.R.L. Listed by crypto24 Ransomware GroupLatest breaches
Publicly posted by crypto24 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.