Health Employers Association of BC
Incident posture
Linked entities
- Victim
- Health Employers Association of BC
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
An Indonesian hacking group known as Gantengers Crew defaced the official website of the President of Kenya, replacing the homepage with a message showcasing the online handles of its members. The attackers did not disclose a specific motive for targeting the site, though one member stated the goal was to demonstrate to governments that their servers are not secure. The defacement was confirmed via a mirror of the page, and the website was subsequently restored. The same crew had previously claimed responsibility for hacking MasterCard and several other high-profile websites, including Australian National University, WWF, and Earth Hour Philippines.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 11 May 2015, the official website of the President of Kenya, Uhuru Kenyatta, was compromised by an Indonesian-based hacker collective known as the Gantengers Crew. The attackers replaced the site's homepage with a defacement page bearing the group's online handles, including SultanHaikal, d3b~X, Brian Kamikaze, Coupdegrace, Mdn_newbie, and NG689Skwng689skwyahoocom. The targeted website was hosted at president.go.ke. A mirror of the defacement was subsequently logged on the Zone-H defacement archive under identifier 24287890, providing external confirmation of the intrusion. The defacement was visible on the site's main landing page, which served as the primary public-facing point of access for visitors seeking official information from the Office of the President. At the time of the article's publication, the Kenyan President website had been restored, indicating that the defacement was temporary and remediation efforts had already been initiated or completed by site administrators.
The Gantengers Crew did not publicly state a political or ideological motive for the intrusion. In an exclusive conversation with HackRead, a member of the group indicated that the reason for targeting the President's website was to demonstrate the vulnerability of government servers to hacking. The crew member stated that governments should know their servers are never secure from them. This statement frames the incident as part of a broader pattern of the group targeting high-profile websites to demonstrate capability rather than to advance a specific cause. The article notes that the same Indonesian hacker collective had previously conducted other notable intrusions, including the defacement of the MasterCard website on 29 April 2015, shortly before the Kenyan President website incident. The group had also been involved in hacking several high-profile websites the previous year, including the Australian National University, WWF, and Earth Hour Philippines, establishing a pattern of targeting institutions with significant public visibility.
The incident appears to have been limited in technical scope, consisting primarily of a website defacement rather than a deeper compromise of government systems. No evidence is provided in the source material indicating that sensitive data, internal communications, or classified information were accessed, exfiltrated, or manipulated during the intrusion. The visible impact was confined to the public-facing homepage, which displayed the attackers' handles and defacement content until site administrators restored the original page. The response action visible from the source material was the restoration of the website to its original state by the time the article was published. Beyond this, no further details are provided regarding detection mechanisms, containment procedures, forensic investigation, attribution efforts, or post-incident hardening of the president's office web infrastructure. The available source evidence does not include official statements from the Kenyan government, the Office of the President, or any cybersecurity authorities regarding the breach.
The Gantengers Crew has been characterized in the source material as a "famous Indonesian based" hacking group, suggesting a degree of public recognition within cybersecurity and hacking communities prior to this incident. The Kenyan President website hack represented one in a series of high-profile defacements attributed to the group during 2014 and 2015. The recurring pattern across these incidents involved public defacement with displayed handles, lack of a stated ideological motive, and targeting of organizations with significant public profiles, including government offices, educational institutions, and international non-governmental organizations. The website of the President of Kenya, as the official online presence of a head of state, represented a symbolically significant target within this pattern. The Zone-H mirror of the defacement provided a persistent public record of the intrusion even after the original site had been restored, ensuring that the event remained documented within the defacement tracking community. No information is available in the provided source material regarding potential follow-up investigations, security improvements implemented by the Office of the President following the incident, or any broader implications for Kenyan government cybersecurity policy.
Sources
Sources available to members: 1 source.