Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo PLN

Group: Dragonforce

Discovered by ransomware.live: 2025-08-21

Estimated attack date: 2025-03-31

Country: ID

Description:

Core business is the supply of electricity, especially in generation, transmission and distribution. Obtaining the task of electrifying all over the archipelago, PLN has the obligation to increase installed capacity for power supply and the development of electricity infrastructure such as transmission networks, substations, and distribution networks. At all times, we continue to improve ourselves and improve services, considering that electricity is a basic infrastructure need that will create a multiplier effect for the progress of the Indonesian economy. Our business continues to expand into various business sectors through subsidiaries, associated entities, joint ventures, and special purpose vehicles (SPV) under the auspices of the PLN Group. Through the implementation of SOLID (Securing Business Sustainability, Optimizing Cost Efficiency, Leading Industry Capabilities, Increasing Profit Contribution and Developing New Edge) business portfolios, we will continue to develop services to become a World Class Electricity Company.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2960

Compromised Users: 26109

Third Party Employee Credentials: 823


External Attack Surface: 200


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxpln.pln.co.id.
TXT Records
  • MS=7CC2D89AFE23298EAEA8805BBB9A6538CA6BC4AD
  • v=spf1 include:_spf-pln.pln.co.id include:_spf-icon.pln.co.id include:spf.iconplus.id +ip4:103.145.30.229 +ip4:103.145.30.230 a mx -all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot