{
    "success": true,
    "data": {
        "id": 1875182,
        "msgid": "civil-servant-attendance-fraud-scheme-uncovered-in-brebes-1784728305",
        "date": "2026-07-22 20:00:00",
        "title": "Civil Servant Attendance Fraud Scheme Uncovered in Brebes",
        "author": "",
        "source": "CNBC",
        "tags": "",
        "topic": "Legal",
        "summary": "Police in Brebes, Central Java, have uncovered a scheme involving nine civil servants who manipulated the electronic attendance system to appear present while absent. Cybersecurity experts explained the fraud likely involved exploiting server-side vulnerabilities, allowing fake GPS coordinates to be submitted directly to the backend system.",
        "content": "<p>Police have revealed a manipulation of the attendance system\ninvolving several civil servants (ASN) in Brebes. The perpetrators\nallegedly used various methods to deceive the online attendance system\nso that their recorded location did not match their actual position.<\/p>\n<p>Cybersecurity expert Alfons Tanujaya explained that perpetrators can\nutilise at least three scenarios to falsify their location. One method\ninvolves using the Mock Location feature on Android devices, where a\nfraudulent app registers as a fake location provider, replacing the GPS\nsignal so other applications read the false coordinates.<\/p>\n<p>Another method involves rooting the device or using a framework to\nhook directly into the Location Manager API. This allows the target\napplication to receive fake coordinates without detecting the mock\nprovider. The third and most likely scenario in this case, according to\nTanujaya, involves sending requests directly to the attendance backend\nAPI using a pre-prepared list of coordinates.<\/p>\n<p>\u201cThis is likely what happened and should be a concern because the\nweakness lies in the attendance server. The app most likely sent\nrequests directly to the attendance backend API with a list of\ncoordinates that had been prepared beforehand,\u201d Tanujaya told CNBC\nIndonesia. \u201cThis means the backend was accessed because it was not\nproperly protected or was left open for some reason. This is serious and\nindicates reverse engineering of the protocol\/API. This is suspected\nbecause there was an official statement that \u2018the server was down but\nattendance was still recorded\u2019, so the third point is more likely.\u201d<\/p>\n<p>To prevent similar incidents, Tanujaya shared several\ncountermeasures. First, validate requests to ensure they come from\nunmodified devices. Second, ensure requests without a valid signature to\nthe API are immediately rejected. He also advised cross-checking\nmultiple location signals, not just GPS, but also office WiFi BSSID and\ncell tower IDs, as GPS spoofing cannot fake these.<\/p>\n<p>He further recommended detecting anomalies on the server, such as\ndrastic location jumps in a short time or many different devices\nreporting identical coordinates, which indicates hardcoded spoofing.\nFinally, he suggested considering an upgrade to a liveness\nbiometric-based attendance system to ensure the authenticity of the\nperson clocking in, while maintaining server-side security by\nrestricting direct access to the API.<\/p>\n<p>The Brebes Police previously uncovered the alleged misuse of the\nelectronic attendance system within the Brebes Regency Government,\nnaming nine suspects. The case came to light following a report of\nsuspected illegal online attendance on 29-30 April 2026 by the Regional\nPersonnel and Human Resources Development Agency (BKPSDMD) of Brebes\nRegency. Investigations found that coordinate points in the system had\nbeen altered, allowing civil servants to clock in without being at the\ndesignated location.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/civil-servant-attendance-fraud-scheme-uncovered-in-brebes-1784728305",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}