TheJakartaPost

Please Update your browser

Your browser is out of date, and may not be compatible with our website. A list of the most popular web browsers can be found below.
Just click on the icons to get to the download page.

Jakarta Post

Police ends probe into alleged eHAC data leak

Cyber experts have called the discontinuation of the police investigation into the alleged e-HAC data leak "premature" while lamenting the absence of a data protection law, with the bill languishing in the deliberation stage between legislators and the government.

Dio Suhenda (The Jakarta Post)
Jakarta
Sat, September 11, 2021 Published on Sep. 10, 2021 Published on 2021-09-10T16:33:00+07:00

Change text size

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!
Police ends probe into alleged eHAC data leak

A

uthorities on Tuesday called off their investigation into the alleged leak of electronic Health Alert Card (eHAC) data from an unsecured third-party database, but experts have called the move "premature", as it remained unclear whether the data had been leaked before encryption provider vpnMentor first reported the issue in July.

The move comes after a seven-day investigation involving the National Cyber and Encryption Agency (BSSN), the National Police and the Health Ministry into the vpnMentor report initially submitted to the ministry on July 21. The alleged data leak is thought to have compromised the personal data of around 1.3 million eHAC users, including their contact details and national identity (ID) cards.

Health Ministry’s eHAC is a mandatory requirement for both domestic and international travelers so the government can keep track of COVID-19 cases across the country.

“Following the probe by the National Police at the Health Ministry and its partners, [we] did not detect any attempts to retrieve the data stored on the eHAC server,” National Police spokesman Insp. Gen. Argo Yuwono said on Tuesday, as quoted by antaranews.com.

Argo also confirmed that the police had dropped their investigation into the alleged data leak.

Anas Ma’ruf, who heads the Health Ministry’s Data and Information Center, stressed that the eHAC database, which was now linked to official COVID-19 tracking app PeduliLindungi, was adequately protected. He added that the findings of the investigation provided reassurances that the database was secured against potential leaks and breaches.

Read also: Cyber-attack haunts Indonesia's COVID-19 strategy

However, experts have urged caution in light of the government’s move to wrap up the probe quickly, arguing that it remained unclear whether eHAC data had been leaked prior to vpnMentor’s reporting the issue.

“It’s too premature to conclude if there was a data leak or if any crimes were committed [using the leaked data],” Wahyudi Djafar, executive director at the Institute for Policy Research and Advocacy (ELSAM), said on Thursday.

He said that any investigation of a reported data leak must be handled by the appropriate data protection authorities to uncover the cause of the alleged leak first, before the police launched their own investigation into potential crimes resulting from the leaked data.

Drone Emprit cofounder and cyber activist Ismail Fahmi echoed Wahyudi’s view that the policy had ended their investigation prematurely.

“What the police are claiming is only from what they know, but the situation is [that] the eHAC database has been vulnerable to a leak since July 15 or even longer before [then],” Ismail said on Thursday. “The real question is whether a hacker actually got ahold of the data before [vpnMentor reported it].”

Even if the data leak was confirmed, he continued, it would be impossible to hold the perpetrators to account because the country did not have a regulation on data protection.

Read also: Indonesian's data 'just sitting there', hackers say

The proposed establishment of a data protection agency is a major sticking point in the deliberation of the long-awaited data protection bill, with the government and lawmakers still unable to resolve their differences over the agency’s structural position.

The government has proposed that the agency be placed under the Communications and Information Ministry, while lawmakers have insisted on the agency’s independence to avoid any potential conflicts of interest.

After news emerged last week on the alleged data leak, House of Representatives Speaker Puan Maharani reaffirmed lawmakers’ commitment to finalizing the data protection bill. She also called on the government to show its “seriousness” in deliberating the bill.

Your Opinion Matters

Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.

Enter at least 30 characters
0 / 30

Thank You

Thank you for sharing your thoughts. We appreciate your feedback.

Share options

Quickly share this news with your network—keep everyone informed with just a single click!

Change text size options

Customize your reading experience by adjusting the text size to small, medium, or large—find what’s most comfortable for you.

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!

Continue in the app

Get the best experience—faster access, exclusive features, and a seamless way to stay updated.