Unverified claim. On 27 September 2026, Daily Dark Web reported an underground-forum sale listing that offers an alleged PT Pertamina (Persero) dataset of roughly 1.2 TB and about 257,658 files, framed as a complete internal NAS / production filesystem dump spanning 2019–2026. Pertamina — Indonesia’s state-owned integrated oil and gas company — had not confirmed any intrusion, theft, or authenticity of the archive at indexing time. Treat every category inventory, credential claim, and file count as actor marketing until the company, a regulator, or independent attestation says otherwise.
Canonical BreachHistory row: https://breachhistory.com/pertamina/pertamina-forum-sale2026. This article does not promote purchasing or downloading the alleged dump. A forum sale is not a company notice and not proof Indonesia’s energy SOE lost a terabyte of production storage.
Two earlier 2026 Pertamina-adjacent claims sit in the same conversation and must stay separate. In late July 2026, TheGentlemen’s leak-site copy also claimed more than 1.2 TB from Pertamina — the same headline volume as this September forum sale. In mid-September 2026, RansomHouse published a far smaller, researcher-reviewed sample set estimated at roughly 6 GB. Same brand name does not mean one corpus. Catalog them as distinct observed claims until someone proves overlap with forensics, not vibes.
What Daily Dark Web reported on 27 September
DDW’s public alert summarizes a classic dark-web sale listing. A threat actor on an underground forum named PT Pertamina (Persero) and marketed a large archive with negotiable, crypto-only pricing. Observed claim details include:
- Alleged volume: ~1.2 TB and ~257,658 files
- Alleged scope: complete filesystem dump from a Pertamina internal NAS / production environment
- Alleged span: 2019–2026 in listing copy
- Alleged content categories: IT credentials and infrastructure artifacts; engineering drawings / CAD; financial and audit records; banking / treasury materials; legal contracts / compliance; HR / personnel records; HSSE / training materials; field operations and drilling programs; employee workspaces / backups; executive communications archives
- Commercial framing: negotiable price, crypto only
- Observation date: 27 September 2026
That inventory reads like a full enterprise file share — marketing language meant to frighten executives and attract industrial-espionage and BEC buyers. Precision in the file count does not equal precision in the intrusion; forum sellers pad trees with duplicates, recycled archives, and screenshots. Until Pertamina attests a census, BreachHistory carries recordsAffected: 257658 as an unverified actor file count — not unique people and not a regulator figure. DDW’s own note is the right default: high-impact if authentic, but a forum sale is not proof of compromise.
What this is not
What this is not is a confirmed Pertamina data breach with a customer letter, status-page incident, Indonesian PDP Law notification packet, or named forensics firm quote. It is not proof that SCADA drawings, treasury wire templates, or executive mail archives left Pertamina’s perimeter in September 2026. It is not automatic confirmation of TheGentlemen’s July leak-site story. It is not the same incident as RansomHouse’s ~6 GB sample review. It is not permission to panic-wire “incident counsel” who cold-call finance teams the same afternoon a screenshot trends on X.
It is also not a reason to shrug. Energy SOEs are high-value targets. “Wait for the company” remains the right posture — paired with skepticism toward anyone emailing a “Pertamina NAS dump portal” or selling “1.2TB proof packs” on Telegram.
Keep three Pertamina claims on separate shelves
1. July 2026 — TheGentlemen ~1.2 TB leak-site claim (unverified)
On 31 July 2026, secondary monitors including DeXpose and GalaxyWarden indexed a TheGentlemen leak-site listing that named Pertamina and claimed more than 1.2 TB of internal data. Actor copy summarized in those write-ups alleged NDA files, HR and employee data, user data, technical drawings and models, bank / accounting / tax / legal statements, SCADA documents, photographs, screenshots, and related materials. Pertamina confirmation was not located in those secondary sources either.
The volume coincidence is glaring — both stories lead with ~1.2 TB. That could be the same corpus recycled into a sale listing, two unrelated exaggerations, or different shares with the same marketing number. BreachHistory’s rule is deliberate: catalog the forum sale separately pending evidence they are the same corpus. Do not collapse July ransomware theater and September sale theater into one “confirmed 1.2TB Pertamina breach” headline.
2. August–September 2026 — RansomHouse ~6 GB claim (unverified, distinct volume)
SearchInform’s 23 September 2026 write-up describes a RansomHouse listing that surfaced around 17 September 2026, with attackers claiming an 21 August attack date. Researcher Alfons Tanujaya of Vaksincom reviewed published samples and estimated more than 6 GB across documents linked to roughly nine departments and around 50 user accounts — financial and HR records, maintenance, refinery and pipeline operations, investigations, cybersecurity and risk analysis, plus a pension-related file allegedly holding about 1,600 names, dates of birth, and employee numbers. Sample language also pointed at entities tied to PT Kilang Pertamina Internasional and PHE Jambi Merang.
Six gigabytes is not 1.2 terabytes. Keep pertamina-ransomhouse2026 and pertamina-forum-sale2026 as separate rows — mixing them invents certainty and confuses retirees in a pension sample with partners fearing a full CAD / treasury share.
3. 27 September 2026 — underground forum NAS sale (this row)
This blog indexes the DDW-observed forum sale: ~1.2 TB / ~257,658 files, NAS / production dump framing, crypto-negotiable price, no Pertamina confirmation. Same-day note from DDW: the same seller alias path also posted an Ecopetrol sale claim. Do not treat either listing as corroboration of the other. Two oil majors named by one seller path is a marketing pattern, not mutual proof.
Who Pertamina is — and why a NAS dump claim travels
PT Pertamina (Persero) is Indonesia’s flagship state-owned energy enterprise — upstream and downstream oil and gas, refining, distribution, and renewables — sitting at the center of national fuel supply and contractor ecosystems. When a seller pastes that name next to a terabyte figure and a CAD / SCADA / treasury shopping list, employees, drilling contractors, and foreign partners start searching overnight.
If a dump of this shape were ever confirmed, the stakes would be concrete: credential reuse for follow-on intrusion, CAD and field-ops files for industrial espionage, treasury materials for BEC, HR and HSSE files for spear-phishing, executive archives for blackmail theater. None of that is confirmed here. Size of SOE ≠ size of breach — do not invent a “millions of motorists exposed” figure because Pertamina sells fuel. This claim is primarily an enterprise and contractor story unless Pertamina later publishes a consumer-facing census.
What we know vs what we do not
Supported by DDW / listing language (still unverified as to authenticity): a seller named PT Pertamina (Persero); claimed ~1.2 TB and ~257,658 files; described a complete NAS / production filesystem dump; listed broad enterprise categories from IT credentials through executive archives; alleged a 2019–2026 span; asked for crypto; listing observed 27 September 2026; same seller path also pushed a same-day Ecopetrol sale claim per DDW.
Not supported at indexing: Pertamina confirmation; an Indonesian PDP Law notice with an attested census; proof the archive is fresh production data rather than recycled TheGentlemen material or padded junk; proof July’s 1.2 TB and September’s 1.2 TB are the same bytes; a published access path; regulator letters naming individuals.
To be clear: this is not a confirmed Pertamina data breach. Amplification on social media does not upgrade a forum sale into attestation.
Who might be at risk if the claim were true
Until Pertamina speaks, treat the audiences below as hypothetical risk groups suggested by the seller’s category list — not as confirmed victims.
Employees, contractors, and retirees
HR, personnel, HSSE training, and workspace backup categories — if authentic — are classic spear-phishing fuel. Expect themes like “rotate VPN after the NAS leak,” fake payroll redirection, and MFA fatigue pushes that cite Daily Dark Web screenshots. Retirees who already appeared in separate RansomHouse sample coverage should still treat that claim as unverified and distinct; do not assume the September sale automatically includes the same pension file.
Engineering, drilling, and HSSE partners
CAD, field-ops, and drilling-program materials are high-value for competitors and for attackers who want to sound like project controls staff. Partners should freeze unusual document-sharing requests and verify any “we need you to re-upload drawings after the Pertamina dump” email out of band.
Treasury, legal, and joint-venture finance teams
Banking / treasury and legal / compliance categories are BEC gold. A fake “update escrow for incident response counsel” wire instruction that name-drops a 1.2 TB Pertamina dump is exactly the fraud pattern to expect after headlines like this — whether or not the dump is real.
Foreign partners and fuel customers
Partners running third-party risk should ask Pertamina through established channels whether any notice applies — and ignore Telegram “Pertamina NAS sample” zips, which are often malware. Buying Pertalite or Pertamax does not put consumer PII in an enterprise NAS tree by default. Pump-side panic about “my fuel app was in the 1.2 TB dump” is almost always phishing bait unless Pertamina later publishes a consumer-facing field list.
Industry context: energy majors on leak sites and forums in 2026
Oil and gas names appear in ransomware and underground-sale chatter because they combine sprawling document stores, contractor VPN sprawl, and national visibility. Confirmed energy incidents leave FAQs or named spokesperson quotes. Unverified claims leave a screenshot, a terabyte number, and a negotiable crypto price.
Colombia’s Ecopetrol has had separately reported cyberattack coverage in 2026 — and, per DDW, a same-day forum sale claim from the same seller path as this Pertamina listing. Interesting for clustering; not proof either archive is real. Indonesia’s PDP Law No. 27 of 2022 still matters if personal data were confirmed stolen — controllers face notification clocks — but confirmed SOE breaches of this sensitivity usually produce paper. Unverified forum posts often produce only monitoring blogs like this one.
What Pertamina and regulators have said
As of this article’s createdAt timestamp, sources used for cataloguing did not include a Pertamina notice, status-page incident, Indonesian authority filing with an attested census, or a spokesperson quote confirming the September forum archive. Silence is not proof either way — operators sometimes investigate quietly. Until Pertamina or a regulator speaks with substance, this remains an unverified actor / forum sale claim. Ignore mirrors that rewrite DDW as “Pertamina confirms 1.2 TB stolen.” Amplification is not confirmation.
Timeline readers can actually use
- 31 July 2026: TheGentlemen leak-site monitors index a Pertamina listing claiming >1.2 TB (NDA/HR/SCADA/technical categories in secondary coverage). Company confirmation not located — separate unverified claim.
- ~21 August 2026 (actor-claimed): RansomHouse attack date cited in later monitoring for a distinct, smaller Pertamina listing.
- ~17 September 2026: RansomHouse Pertamina claim surfaces; researcher sample review estimates >6 GB across multiple departments (~50 user accounts cited). Still unverified; distinct from 1.2 TB stories.
- 23 September 2026: SearchInform summarizes the RansomHouse / Vaksincom sample review publicly.
- 27 September 2026: Daily Dark Web reports underground forum sale of alleged Pertamina NAS dump (~1.2 TB / ~257,658 files, 2019–2026 span, crypto negotiable). Same seller path also notes Ecopetrol. No Pertamina confirmation located. This blog indexes the claim as unverified with
recordsAffected: 257658andcompanyConfirmed: false.
If you only remember one sentence: a forum seller claimed a ~1.2 TB / ~258K-file Pertamina NAS dump on 27 September 2026; Pertamina had not confirmed it — and the matching 1.2 TB figure from July’s TheGentlemen claim is a coincidence to investigate, not a closed case.
Phishing and fraud patterns to expect
Whether or not the archive is authentic Pertamina data, the brand will attract fraud. Concrete examples to reject without clicking:
- “Pertamina Security: validate your account after the 1.2 TB NAS leak — upload KTP here.”
- Contractor email: “Re-share drilling CAD packages; old share compromised in the DDW dump.”
- Treasury BEC: “Update wire instructions for incident-response retainers after the Pertamina breach.”
- Fake HSSE portal: “Mandatory training reset after HSSE files appeared in the 257,658-file sale.”
- Telegram sellers offering “Pertamina 1.2TB sample” zips that are malware or recycled junk.
- Cold calls that paste DDW screenshots as “proof” you must enroll in paid monitoring or pay crypto to “remove your row.”
Legitimate remediation, if it ever comes, will not ask you to unlock a forum download, dictate MFA codes by phone, or wire crypto to a cold-calling “remediation” vendor. It will use domains Pertamina already owns.
Was I affected by a Pertamina data breach?
Short answer: there is no company-attested census tied to the 27 September 2026 forum sale. The ~257,658 figure is a seller’s file count — not a headcount. Bookmark official Pertamina contact pages; ignore “breach check” sites that ask for NIK or bank details; treat a later Pertamina letter as the signal only after verifying the domain. Do not assume TheGentlemen, RansomHouse, and this sale are the same event. Contractors should still watch unusual CAD / HSSE re-share requests — the phishing wave does not require the archive to be real.
What you should do
- Wait for official Pertamina notices before changing banking details, contractor portal credentials, or joint-venture escrow instructions based solely on forum screenshots.
- Treat the ~1.2 TB / ~257,658 figures as unverified actor counts. Do not forward them to staff or partners as confirmed fact.
- Keep TheGentlemen (July) and RansomHouse (~6 GB) claims mentally separate until primary evidence bridges them to this sale listing.
- Employees and contractors: treat “NAS dump / DDW / TheGentlemen” themed IT resets as hostile until verified out of band; prefer authenticator MFA over SMS where possible.
- Finance and treasury: freeze nonstandard ACH / wire / escrow changes; use callback directories you already trust.
- Engineering partners: verify any urgent re-upload of drawings or drilling programs through known project controls channels.
- Do not download alleged Pertamina proof packs from forums or Telegram — archives are often malware or recycled unrelated dumps.
- Do not pay anyone offering to “remove your row” from an unverified leak.
- Security teams elsewhere: use the claim as a hunting trigger for odd file-share exports, vendor VPN anomalies, and energy-themed phishing — not as automatic evidence your tenant is next.
- Journalists and analysts: quote the seller as an alleged listing. Prefer primary Pertamina language if it appears. Cite DDW and reputable secondary monitors for TheGentlemen / RansomHouse context — not Breachsense mirrors.
None of those steps require you to believe the dump. Slow down, verify out-of-band, and do not let a forum poster set the incident narrative.
Why recordsAffected carries 257658 (still unverified)
For unverified extortion-adjacent claims, BreachHistory uses a clearly cited actor/reporter count — still labeled unverified — or 0 when none exists. DDW cites ~257,658 files alongside ~1.2 TB, so the catalog carries 257658 as an unverified file count, not a people census. File count ≠ people count. Rewriting it as “Pertamina confirmed 258,000 employees stolen” manufactures confirmation.
Canonical record and sources
BreachHistory indexes this incident as an unverified underground-forum sale claim against PT Pertamina (Persero) observed 27 September 2026, with actor volume about 1.2 TB / 257,658 files described as a complete internal NAS / production filesystem dump (2019–2026 span; IT credentials, CAD, finance, treasury, legal, HR, HSSE, field ops, workspaces, executive archives in claim language), crypto-negotiable pricing, possible overlap with an earlier unverified TheGentlemen ~1.2 TB July listing, and a separate unverified RansomHouse ~6 GB sample claim — with no Pertamina confirmation at indexing. Full catalog entry: https://breachhistory.com/pertamina/pertamina-forum-sale2026.
Primary open source for the September sale language: Daily Dark Web — Pertamina data allegedly offered for sale (1.2 TB / ~258K files). Context on earlier unverified Pertamina-adjacent claims: DeXpose — TheGentlemen / Pertamina July 2026 listing summary, GalaxyWarden — Pertamina TheGentlemen July 2026, and SearchInform — RansomHouse ~6 GB Pertamina sample review.
If Pertamina publishes a confirmation, denial with substance, or a regulator posts an attested census, the parent catalog row should be updated — and the unverified label revisited. Until then: a forum seller claimed a ~1.2 TB / ~258K-file Pertamina NAS dump in September 2026; Pertamina had not confirmed it — and readers should not collapse that claim with July’s TheGentlemen 1.2 TB listing or RansomHouse’s separate ~6 GB sample story without evidence.