Samuel Sekuritas Indonesia & Samuel Aset Manajemen Listed by trigona Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Samuel Sekuritas Indonesia & Samuel Aset Manajemen Listed by trigona Ransomware Group (reported January 18, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target financial institutions worldwide, using data theft and public leak-site postings as leverage. In this climate, listings of investment firms and asset managers have become a recurring feature of the threat landscape, raising practical questions for clients and counterparties about what may have been taken and how to respond.
On 18 January 2024, the ransomware group Trigona listed Samuel Sekuritas Indonesia and Samuel Aset Manajemen. Public reporting describes the incident as involving the exfiltration of internal files in a ransomware attack. The number of people affected remains unknown, and many operational details have not been disclosed.
Inside the incident
According to available reporting, PT Samuel Sekuritas Indonesia and Samuel Aset Manajemen were named on a Trigona leak site on 18 January 2024. The group’s listing is presented as a claim that internal files were exfiltrated during a ransomware attack. No confirmed figures for the volume of data, the precise date of intrusion, or the initial access method have been made public. The number of individuals whose information may have been involved is listed as unknown. Beyond the statement that internal files were taken, further technical specifics of the incident remain undisclosed.
Who is trigona?
Trigona is a ransomware operation that has been publicly documented since at least 2022. Like many contemporary groups, it has typically followed a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group has used dedicated leak sites to name victims and, in some cases, to release sample files. Public analyses of earlier campaigns have described the use of common initial-access vectors such as compromised remote services and phishing, followed by lateral movement and data staging. These patterns are drawn from well-established reporting on the group’s broader activity; they do not constitute Reported Details of the methods used against this particular organisation. In the present case, the only specific claim is the leak-site listing itself and the assertion that internal files were exfiltrated.
Who is Samuel Sekuritas Indonesia & Samuel Aset Manajemen?
PT Samuel Sekuritas Indonesia (SSI) is a financial advisory firm based in Jakarta, Indonesia. Established in 1992, it operates as a full-service investment bank serving both institutional and retail clients and is described as taking a selective approach to its businesses and clients. Samuel Aset Manajemen is associated with the same corporate grouping and operates in the asset-management space. Organisations of this type routinely handle sensitive commercial and personal information: client identities and contact details, account and portfolio data, transaction records, know-your-customer documentation, internal research, and correspondence with counterparties. A breach affecting such an entity is consequential because the data it holds can be used for fraud, identity misuse, or competitive intelligence, and because trust is central to the relationship between a securities firm, its clients, and the markets in which it operates.
What was likely exposed
Public reporting states that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases, or specific categories of personal or financial data has been disclosed. Exact contents therefore remain unconfirmed. Firms in the investment-banking and asset-management sector typically maintain records that can include client names and contact information, account identifiers, transaction histories, investment holdings, compliance and onboarding documents, employee records, and internal operational files. Whether any or all of these categories were among the material claimed by Trigona has not been independently verified in the available facts. Readers should treat any assertion of precise data types beyond “internal files” as unconfirmed.
Why it matters
For individuals and institutions whose information may have been among the internal files, the practical risks include targeted phishing, social-engineering attempts that reference genuine account or portfolio details, and potential misuse of identity or financial data. Even when full account credentials are not present, fragments of personal or commercial information can be combined with other sources to increase the credibility of fraud. For the organisation, a public listing by a ransomware group can affect client confidence, trigger regulatory and contractual notification duties, and require sustained incident-response and monitoring work. Because the scale of exposure and the precise data elements remain unknown, the concrete impact on any given person or counterparty cannot yet be measured from public sources alone.
If your data was in this claimed breach
If you have a relationship with Samuel Sekuritas Indonesia or Samuel Aset Manajemen, treat the listing as a prompt for caution rather than proof that your specific records were taken. Practical first steps include:
- Monitor account statements and transaction alerts for unexpected activity and report anomalies promptly to the firm and your bank.
- Be sceptical of unsolicited emails, calls, or messages that reference the firm or your investments; verify any request through official channels you already trust.
- Enable multi-factor authentication on financial and email accounts where available, and avoid reusing passwords across services.
- Consider placing fraud alerts or credit freezes with relevant bureaus if you hold significant personal financial exposure in the region.
- Run a free exposure scan of your email address against known breach data sets to see whether your address has appeared in previously published collections; this does not confirm or rule out involvement in this specific incident but can surface other exposures worth addressing.
Public detail on this incident remains limited. Continue to rely on official communications from the firm and from Indonesian financial regulators for any confirmed notifications or guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Indoarsip Listed by trigona Ransomware GroupHotel Avenida, Hostal Espoz y Mina, Hostal Arriazu, Pension Alemana Listed by trigona Ransomware GroupTreadwell, Tamplin & Company, Certified Public Accountants, Madison, GA Listed by trigona Ransomware GroupClaro Listed by trigona Ransomware GroupLatest breaches
Publicly posted by trigona — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.