Ransomware victim disclosure
← All victimsStar Energy Geothermal Salak
Claimed by Ransomhouse · listed 13 days ago
Status timeline
- Listed
May 7, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- Indonesia
- Sector
- energy
- Listed on leak site
- May 7, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileStar Energy Geothermal Salak is an Indonesian energy company established in 2003, focused on geothermal power generation and oil & gas exploration. It operates approximately 926 MW of geothermal capacity in West Java, supplying clean renewable energy to Indonesia's national grid. Under parent company Barito Renewables, it is targeting 2.3 GW of renewable capacity by 2032.
- Industry
- Geothermal Power Generation & Oil and Gas Exploration
- Address
- Indonesia (precise street address not stated on public site)
- Employees
- 150
- Founded
- 2003
Attack summary
Severity: critical — 743 GB of data from a critical energy infrastructure operator (geothermal power generation supplying a national grid) has been published. Exfiltration and encryption of data from a national-grid-connected energy company constitutes critical infrastructure compromise with potential for significant operational, regulatory, and national-security impact.RansomHouse claims to have encrypted systems at Star Energy Geothermal Salak on or around 11 April 2026 and has published data totalling 743 GB. The disclosed status is listed as 'data_published', indicating exfiltrated data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- 743 GB of company data
- Operational/energy infrastructure files
- Potentially financial and business records
What the group claims
Star Energy is an Indonesian energy company focused on geothermal power generation and oil & gas exploration, operating a total of 926 MW of geothermal capacity in West Java.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436242"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 13 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
