Ransomware victim disclosure
← All victimsPKF Hadiwinata
Claimed by METAENCRYPTER · listed 23 hours ago
Status timeline
- ListedSep 28, 2026
Current state: Listed for ransom
At a glance
- Group
- METAENCRYPTER
- Status
- Listed for ransom
- Country
- Indonesia
- Sector
- Professional Services
- Listed on leak site
- Sep 28, 2026
- Data size
- 130 GB
About the victim
AI dossier — public-source company profilePKF Hadiwinata is a top-10 accounting and professional services firm in Indonesia, headquartered in Jakarta's financial district. Founded in 1987, it is a member of PKF International and provides audit, tax, business solutions, and consulting services.
- Industry
- Accounting & Professional Services
- Address
- Jakarta, Indonesia (financial district)
- Founded
- 1987
Attack summary
Severity: high — Confirmed exfiltration of 130 GB from a major professional services firm; likely includes client financial data, audit materials, and sensitive business information. Professional services firms hold regulated financial and tax data at scale.METAENCRYPTER claims to have exfiltrated 130 GB of data from PKF Hadiwinata. The group operates on a deadline-based disclosure model: if the victim does not negotiate, representative samples are published, followed by progressive release of the full dataset to the public and regulatory authorities.
Data the group says was taken
AI dossier — extracted from the leak post- Audit records
- Tax documentation
- Client financial information
- Business consulting materials
- Corporate administrative files
What the group claims
A top-10 accounting and professional services firm in Indonesia, headquartered in the financial district of Jakarta. Founded in 1987, member of PKF International, providing audit, tax, business solutions, and consulting services.
The leak post
captured from the group's siteThis platform publishes data belonging to organizations that have elected to forgo negotiation entirely.Upon a company's initial listing, the complete manifest of exfiltrated files is disclosed alongside a curated selection of representative samples. Should the organization fail to establish contact prior to the stated deadline, a portion of the compromised data is released into the public domain.Should all subsequent attempts at resolution prove fruitless, the full volume of acquired data is made permanently and unconditionally available to the general public — accessible without restriction to journalists, researchers, competitors, and any other interested party. Simultaneously, formal notifications are dispatched to the relevant data protection and regulatory authorities: the and in the United States; the , , , and the across Europe; the (Singapore), (South Korea), and (Japan) throughout Asia — all of whom are mandated to investigate and impose penalties upon the affected organization.In the event that a mutual agreement is reached, every file in our possession is permanently and irrevocably destroyed, and all references to that organization are expunged from this platform in th…
Screenshot of the leak post

Sources
Source
Indexed 23 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

