One hundred and thirty-three compromised user credentials and 39 exposed items on the external attack surface: those are the figures ransomware tracking platform Ransomware.live attributed to the Nova group's claim against Badan Pangan Nasional (BPN), Indonesia's National Food Agency, logged on 29 May 2026. The agency manages commodity pricing, food supply coordination, safety standards, and nutrition policy for a country of 280 million people.
What Nova Claims It Has
Nova's leak post follows the group's standard double-extortion playbook. The group states it will supply a file-tree and data samples to the agency if BPN contacts its support channel — a pressure tactic designed to demonstrate the depth of access before negotiations begin. No ransom figure has been disclosed publicly, and the full scope of exfiltrated data has not been independently verified. The claim should be treated as an unverified threat-actor assertion until BPN or Indonesia's Badan Siber dan Sandi Negara (BSSN) issues an official response.
Monitoring data cited by Ransomware.live indicates infostealer activity — consistent with Nova's documented modus operandi of harvesting valid credentials prior to encryption. BPN's infrastructure included multiple mail servers but no major cloud or SaaS platforms, which limits some exposure pathways but also suggests on-premise systems that may carry older patch profiles.
Who Is Nova
Nova is a ransomware-as-a-service (RaaS) operation with roots in an earlier group called RALord, which began operating in March 2025. Towards the end of April 2025, the group renamed its leak site "Nova" — a rebrand that preserved the affiliate model while scaling recruitment. According to threat intelligence reporting by Xcitium Threat Labs, affiliates retain approximately 85 per cent of ransom payments, an arrangement that accelerates recruitment and explains the group's rapid expansion. As of late May 2026, Ransomware.live's tracker listed 129 confirmed Nova victims across five continents, though this figure has not been independently corroborated. For comparison, Xcitium's analysis in January 2026 cited over 86 victims, indicating continued growth.
Government entities are not incidental targets for Nova. The group's confirmed victim list includes Brazilian secretariat bodies, Argentina's Ministry of Health, and — separately — another Indonesian local government body, Pemerintah Kabupaten Bojonegoro. BPN is the second Indonesian public institution Nova has claimed.
Indonesia's Ransomware Pattern
The BPN claim arrives less than two years after the most damaging ransomware incident in Indonesian government history. In June 2024, the Brain Cipher group — operating a LockBit 3.0 variant — struck the Pusat Data Nasional Sementara (PDNS), the national temporary data centre. The attack disrupted over 200 government agencies, shutting down immigration processing at airports and prompting a US$8 million ransom demand that Jakarta refused to pay.
The structural problem has not abated. BSSN recorded 3.64 billion cyber anomalies against Indonesian entities in the first seven months of 2025 alone — a figure BSSN's deputy for cyber operations noted "nearly matches the total anomalies over the past five years." Malware-based attacks accounted for 83.68 per cent of that volume.
Why a Food Agency Is a High-Stakes Target
The concern here extends beyond data privacy. BPN is the operational nerve centre for Indonesia's food security, monitoring commodity prices, coordinating distribution, and informing government subsidy decisions. A disruption to its systems — even temporary — could delay pricing data that markets and regulators depend on. For a country where rice and cooking oil prices are politically sensitive, that is not a trivial risk.
Indonesia enacted BSSN Regulation No 1/2024 on cybersecurity incident management, but regulatory frameworks have consistently lagged behind operational cyber hygiene in government agencies. The PDN breach exposed the absence of offsite backups; the BPN claim, if substantiated, points to credential management as the proximate failure point.
Defensive Posture
This article reports threat-actor claims for situational awareness only. No exploit methodology is reproduced here. Organisations in the Indonesian public sector should treat this incident as a prompt to audit externally exposed services, rotate credentials flagged by infostealer monitoring services, and validate that backup integrity is not contingent on the same network segment as production systems. BSSN's incident-reporting channel remains the appropriate first contact for agencies that identify anomalous activity.
Three months on, the claim is still only a claim
The caution in this piece was that a leak-site post is an assertion by an attacker, not a confirmed breach. Nothing has changed that.
Badan Pangan Nasional has not confirmed an incident. No ransom figure has appeared, no data has been published that anyone has independently verified against the agency, and no national authority has attributed the intrusion. The 133 credentials and 39 exposed attack-surface items remain figures from a tracking platform describing what the group said, not what an investigation found.
That is the ordinary outcome for a leak-site claim against a government body, and it is worth stating plainly rather than leaving as an open thread. Most claims of this kind resolve into silence. From the outside, there is no way to distinguish whether silence means a quiet negotiation is underway, the initial claim was inflated, or the agency simply saw no reason to comment.
The extortion playbook moved on in the same period
The double-extortion pattern described here, offering a file tree and samples to prove depth of access, is now the conservative end of the practice.
After a July ransomware attack closed 83 medical offices at AnMed, the attackers took their pressure campaign to the health system's own Facebook page on 11 August. That is a step past publishing to a leak site, because it puts the demand in front of the victim's patients rather than in front of researchers.
The relevance to a food agency is the audience. An organisation that manages commodity pricing and supply coordination for 280 million people has constituencies that respond to a public claim regardless of whether it is true. The pressure available to a group like Nova does not depend on the data being what it says it is.
Why unverified claims against agencies still deserve reporting
Covering an unconfirmed leak-site post has an obvious hazard, which is amplifying an attacker's marketing. The case for it rests on what the alternative costs.
A claim against a national food agency is a statement about where an adversary believes it has reached. If it is true, the affected parties are suppliers, distributors and the pricing data they rely on, none of whom will be told by the leak site. If it is false, the record of the group having claimed it is still useful, because a group that inflates claims is a group whose future claims can be discounted.
The crucial distinction is how the event is labelled. This piece correctly called the leak-site post a claim, and three months later, that is still all it is.
What would settle it
Two things would move this from claim to fact, and neither has happened.
The first is the agency or an Indonesian authority acknowledging an incident. The second is published data that a third party can match against BPN records rather than against the group's own description of them.
Absent either, the honest status three months on is unchanged from the day it was logged, and anyone citing this incident as an established Indonesian government breach is citing a leak-site post.