Ransomware victim disclosure
← All victimsKoperasi Karyawan PT Aplikanusa Lintasarta
Claimed by Nova · listed 8 days ago
Status timeline
- ListedJul 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Nova
- Status
- Data leaked
- Country
- Indonesia
- Sector
- Telecommunication
- Listed on leak site
- Jul 21, 2026
About the victim
AI dossier — public-source company profileKOPKARLA (Koperasi Karyawan PT Aplikanusa Lintasarta) is an Indonesian employee cooperative providing savings, loans, telecommunications engineering, network installation, and related business services to its members and customers.
- Industry
- Telecommunications & Financial Services (Employee Cooperative)
Attack summary
Severity: medium — Disclosed status indicates data published, but no proof files are currently visible; the threat actor claims samples exist but are conditional. Victim is a cooperative handling financial and personal member data, suggesting moderate sensitivity. Lack of public proof samples prevents higher severity classification.Nova claims to have exfiltrated data from KOPKARLA. The group states that proof samples and documentation will only be provided if the company engages with their support department through recovery channels.
Data the group says was taken
AI dossier — extracted from the leak post- employee financial records
- member account data
- loan documentation
- customer records
- telecommunications engineering data
What the group claims
Kopkarla.org is the website of KOPKARLA (Koperasi Karyawan PT Aplikanusa Lintasarta), an Indonesian employee cooperative that provides savings, loans, telecommunications engineering, network installation, and related business services for its members and customers - Nova Provide Tree and samples and proofs only when company get in touch with support department in channels provided in recovery file.
Sources
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

