The RansomHouse ransomware operation added Pertamina, Indonesia's state-owned energy major, to its dark web leak site on 17 September 2026. The listing was timestamped at approximately 21:14:29 UTC+3 by the ThreatMon Threat Intelligence Team, whose alert was picked up by UnderCode News, and separately logged by dark web monitoring vendor DeXpose. As of publication, there is no primary-source confirmation of this incident: no statement from Pertamina, no filing from Indonesian regulators, no advisory from BSSN or any national CERT, and no vendor incident response report tied to the claim. Every account currently available traces back to leak site monitoring feeds. This brief treats the intrusion as alleged, and readers should do the same.
What Happened
The sequence, as far as the public record supports it, is thin but consistent. On 17 September 2026, RansomHouse published a victim entry naming Pertamina. DeXpose recorded the domain as www.pertamina.com and captured the extortion note attached to the listing: "The full leak will be published soon, unless a company representative contacts us via the channels provided." That phrasing matches the group's standard pre-leak posture, where a victim is named first and data is withheld pending negotiation, rather than dumped immediately.
UnderCode News, reporting the same ThreatMon alert, placed the entry within a wider wave of activity that day. The Brain Cipher group listed Canadian firm Xpera at 21:25:54 UTC+3, roughly eleven minutes after the Pertamina entry. The two are unrelated beyond timing, but the clustering is a useful reminder that leak site listings are published in batches and that proximity in a feed implies nothing about shared tooling or shared access brokers.
The sources disagree on a basic detail. DeXpose's incident table lists Pertamina's country as Singapore, almost certainly a WHOIS or corporate-registry artifact picked up from the domain rather than a considered attribution. Both UnderCode News pieces correctly identify Pertamina as Indonesia's state energy company. Company revenue figures also diverge sharply: a Dark Eye tracker entry cites $23.2 billion, while corporate profile data attached to a Pertamina executive's LinkedIn page puts annual revenue in the $70 billion to $80 billion range, with 6,000 to 7,000 direct employees across 32 countries. The gap is likely a subsidiary-versus-group accounting difference, and neither figure should be treated as authoritative.
One further complication deserves attention. The Dark Eye Indonesia tracker records an earlier Pertamina listing dated 31 July 2026, attributed not to RansomHouse but to a group tracked as "thegentlemen." Whether the September RansomHouse entry is a distinct intrusion, a re-listing of the same stolen data under a different brand, or two affiliates working from the same initial access is not established by any source. Accounts genuinely differ here, and the honest answer is that nobody outside Pertamina currently knows.
What Was Taken
RansomHouse has published no data volume, no file count, and no sample set for the Pertamina listing. The extortion note is a countdown, not an inventory. Anyone citing a specific record count for this incident is inventing it.
The only detailed claim about Pertamina data in the source set belongs to the earlier July listing by "thegentlemen," which asserted possession of NDA files, HR data, user data, employee data, technical drawings and models, bank, accounting, tax and legal statements, and SCADA documents. That last category is the one worth sitting with. SCADA documentation is not the same as SCADA access, and design documents are not control system compromise, but stolen engineering drawings and process documentation materially lower the cost of a future intrusion against operational technology. That claim, however, comes from a single tracker entry describing a different listing by a different actor, and it is unverified.
Adjacent context from the same Indonesian tracker shows what a fully realised breach of a state-owned entity looks like in this market: the 2023 Bank Syariah Indonesia incident, in which LockBit 3.0 exposed more than 7.4 million customer records after a refused ransom, including over 3.1 million unique email addresses alongside names, phone numbers and activation codes. That is a separate incident from a separate year, included here only as a scale benchmark for Indonesian state-owned sector exposure.
On whether RansomHouse follows through: the group's recent handling of Japanese cold storage and logistics firm Nichirei suggests it does. Following a July 2026 attack that disrupted Nichirei's warehouse and shipping systems, RansomHouse posted files it claimed came from the company's servers. Nichirei acknowledged that affected servers held personal information and reported the matter to authorities, with human resources, accounting and business partner relations among the areas under investigation. Analysts monitoring that leak cautioned that initial dumps from extortion groups often mix genuine files with padding, and verification takes time. Expect the same caveat to apply if Pertamina data appears.
Why It Matters
Pertamina is a sovereign asset, not merely a large corporation. It spans petroleum, gas, refining, distribution and trading across an archipelago of more than 17,000 islands where fuel logistics is a matter of national continuity. A confirmed compromise of its corporate IT estate would raise questions well beyond data protection: business continuity, third-party and contractor dependencies, and the integrity of systems that sit adjacent to critical energy infrastructure.
It is worth being precise about what has and has not been observed. There is no reporting of fuel supply disruption, refinery downtime or retail outage connected to this claim. Pertamina's subsidiary communications have continued on routine matters through the period, including a late August consumer affairs response from Pertamina Patra Niaga's northern Sumatra region regarding fuel quality complaints at a Bintan filling station. That is not evidence of security posture, but it is evidence that public-facing operations were running normally.
The defensive lesson for peer organisations is structural. Pertamina maintains a dedicated Vice President of Enterprise Cyber Security, a role held since April 2025 by a long-tenured internal engineer with prior experience as Cyber Security Manager and VP of Shared Service ICT. A named executive owner for security is exactly what maturity frameworks ask for, and it did not immunise the organisation against being named on a leak site. Governance structure is necessary and insufficient at the same time.
The Attack Technique
No source identifies an initial access vector, an exploited CVE, a compromised credential set or an access broker for this listing. Nothing about dwell time, lateral movement or whether encryption was deployed at all is publicly known.
What is known is the operator. RansomHouse runs as a ransomware-as-a-service platform, linked by Palo Alto Networks Unit 42 to an actor cluster tracked as Jolly Scorpius, and structured around three roles: the operator maintaining the RaaS platform, leak site and ransom collection infrastructure; the affiliate attacker performing intrusion, exfiltration and deployment; and the victim. The group has operated a double extortion model since December 2021, stealing data before encrypting it and threatening publication, and at least 123 victims appear on its leak site with data disclosed or sold. Its named targets have spanned healthcare, finance, transportation and government.
Technically, the operation has been upgrading. Unit 42 analysis of recent samples documents a shift in the encryption routine from a basic single-pass linear method to a more sophisticated multi-layered scheme, with the reporting flagging ESXi as an environment of interest. For defenders, the practical read is that virtualisation infrastructure remains a priority target for this actor, and that partial-encryption or intermittent-encryption heuristics tuned to older RansomHouse behaviour may no longer fire reliably.
Given the RaaS structure, the affiliate who allegedly hit Pertamina may have no relationship to the affiliate who hit Nichirei beyond renting the same platform. Tradecraft will vary. Treat the tooling as the constant and the intrusion method as unknown.
What Organizations Should Do
- Harden and monitor the hypervisor layer. RansomHouse's recent encryption work points at ESXi. Restrict management interface access to a dedicated administrative network, enforce lockdown mode, disable SSH unless actively in use, apply vendor patches on an accelerated cycle, and alert on any unexpected process execution on hypervisor hosts.
- Assume exfiltration precedes encryption. Double extortion means your first detectable signal is often large outbound transfer, not file encryption. Baseline normal egress volume per host and alert on deviation, with particular attention to cloud storage endpoints, file transfer utilities and anomalous archive creation.
- Verify backups are immutable and offline. Current, encrypted, air-gapped or immutable backups are what converts a ransomware event from a crisis into an outage. Test the restore, not just the backup job. The BSI case is a reminder that refusing to pay only works when recovery actually functions.
- Segment IT from OT, then verify the segmentation. For energy sector operators specifically, treat engineering documentation, technical drawings and control system documentation as crown jewel data requiring its own access controls and monitoring, distinct from general file shares.
- Close the credential and identity gap. Enforce phishing-resistant MFA on all external access paths, including VPN, remote desktop and third-party contractor accounts. Monitor infostealer marketplaces and credential dumps for your own domains, since reused and previously stolen credentials remain a dominant entry route.
- Run a compromise assessment rather than waiting for confirmation. If you are a Pertamina supplier, contractor or regional peer, review authentication logs, remote access sessions and outbound transfer records for the July to September 2026 window now. Retrospective hunting after a leak drops is significantly harder.
- Prepare the disclosure path in advance. Nichirei's handling, acknowledging that affected servers contained personal information and notifying authorities while the investigation continued, is the model. Decide who speaks, to which regulator, and on what timeline, before you need to.
Sources: Ransomhouse Targets Energy Leader Pertamina - DeXpose | RansomHouse Claims Pertamina as Its Latest Victim, Raising Fresh Qu... | Indonesia Ransomware & Cyber Attacks Dark Eye | Brain Cipher and RansomHouse Add New Victims as Ransomware Activity... | RansomHouse Ransomware Upgrade: From Linear to Complex Encryption (... | Indradi W Kusuma | Nichirei warns RansomHouse posted stolen data that may include pers... | Gerak Cepat Tindaklanjuti Laporan Masyarakat, Pertamina Patra Niaga...