Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hacker Claims to Leak Indonesia TNI Military Academy Recruitment Data

Hacker Claims to Leak Indonesia TNI Military Academy Recruitment Data

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 12, 2026

Human Written
Hacker Claims to Leak Indonesia TNI Military Academy Recruitment Data
  • A threat actor using the name KNOK666X reportedly published a database tied to Indonesia’s 2025 TNI military academy recruitment.

  • The alleged records include NIK numbers, names, status details and session information, based on samples shared by the actor.

  • The claim has not been independently verified, and there is no public evidence yet showing that TNI systems were directly breached.

A threat actor has reportedly released a database linked to Indonesia’s 2025 recruitment process for TNI military academy candidates.

The alleged leak bears the title “Penerimaan Calon Taruna Akademi TNI TA 2025.” The actors called themselves KNOK666X and used the name “Badan Intelijen Database Indonesia.”

Samples posted as proof appear to show structured records belonging to people who took part in the recruitment process. According to reports, the database contains Indonesian National Identification Numbers, also referred to as NIK, along with the name and other details of attendance/status and session.

Verification of the data is pending. There is also no confirmed evidence that the database came directly from TNI servers.

That distinction is important. A leaked database can originate from different sources. The actor may have stolen the database from a government computer system or even a contractor.

It could be from a recruitment office in Indonesia or any other service handling applicant data. At this point in time, only evidence can lead to an alleged breach being reported.

The Data Matches a Real 2025 Recruitment Process

The database title matches a genuine TNI recruitment program. Indonesia reportedly opened applications for Taruna Akademi TNI on March 3, 2025, and closed on April 17. Candidates could register online, and each applicant could use an NIK only once.

The recruitment process involved several stages. These included administrative checks, health tests, physical tests, psychological screening and ideological checks.

TNI units publicly documented the process in several regions. Take Aceh, for instance—out of all the applicants, 249 reportedly moved past the first round, but only 72 made it to the final regional selection in June.

In South Sulawesi, 157 candidates took part in the final regional selection in June. Those records show the academy collected a large amount of personal information during recruitment.

The official recruitment website also shows the type of information applicants may provide. Its current registration system asks for identity information and social media account details. That makes the alleged database plausible in broad terms. It does not, however, prove that the leaked records are genuine.

KNOK666X has Targeted Indonesian Organizations

The name attached to the alleged leak is not entirely new. A June 2026 cyber threat report from Thomas Murray listed KNOK666X among the most active actors targeting Indonesian organizations. The report recorded 15 incidents linked to the actor during June.

That same month, Indonesia logged 130 cyber incidents; of those, 112 either involved data leaks or data theft. Public administration took the hardest hit, with 76 cases there.

HackNotice also recorded KNOK666X-linked reports involving Indonesian government websites in July. These included domains associated with local government and population services.

This history gives the latest claim more context. Still, past activity does not prove that KNOK666X obtained the military applicant database.

Why NIK Exposure Matters

The NIK is a sensitive piece of information, with direct links to a person’s identity. Under Indonesia’s data protection rules, names and NIKs count as personal data. The government also cautions that when identity info gets out and bad actors combine it with other personal details, the risks become higher.

For military academy applicants, the risk may go beyond ordinary identity theft. A person with access to an applicant’s name, NIK and recruitment status could create convincing messages about selection results, document checks or recruitment payments.

The stakes of military data breaches are even higher when classified defense documents are involved, a hacker recently claimed to have stolen sensitive data from a Chinese government supercomputer, including missile schematics and military research.

This would make it even easier to conduct a phishing attack. In particular, criminals can pose as recruitment officers and ask people to send even more documents or pay some imaginary fees.

The TNI warns about the fact that the process of recruiting is free of charge. Its official recruitment system says anyone asking candidates to transfer money while claiming to represent the committee is a scam.

The “Intelligence” Name Needs Caution

The actor’s use of “Badan Intelijen Database Indonesia” should not be confused with Indonesia’s actual military intelligence body.

Indonesia’s Badan Intelijen Strategis TNI, or BAIS TNI, is in charge of all strategic intelligence activities and operates under the TNI command structure.

There is no basis in the available evidence to link BAIS TNI to the actor behind this alleged leak. The unusual name used in the post may simply be an online identity chosen by the threat actor.

No Confirmation of a TNI Breach Yet

The biggest unanswered question is where the alleged data came from.

Our independent searches found no public statement confirming any form of compromise of the TNI infrastructure. There is no verified data regarding the number of applicants and the period during which the leak occurred.

In this context, the only conclusion we can draw from this is the fact that some threat actor claims to have disclosed a TNI Academy applicant database from 2025. Though the samples they provided reportedly hold some sensitive personal information, the source and authenticity remain questionable.

If genuine, the exposure would create privacy and security risks for applicants. It could also raise questions about how recruitment data is stored, shared and protected across the many organizations involved in the selection process.

For now, the claim warrants investigation rather than treating the alleged database as proof of a confirmed military network breach.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.