{
    "success": true,
    "data": {
        "id": 1842930,
        "msgid": "civil-servants-caught-faking-attendance-how-they-manipulated-the-system-and-how-to-prevent-it-1783324308",
        "date": "2026-07-06 14:05:00",
        "title": "Civil Servants Caught Faking Attendance: How They Manipulated the System and How to Prevent It",
        "author": "",
        "source": "CNBC",
        "tags": "",
        "topic": "Technology",
        "summary": "Police in Brebes have uncovered a scheme where civil servants used fake GPS coordinates to manipulate the electronic attendance system. Cybersecurity expert Alfons Tanujaya outlined three possible methods, including exploiting mock location apps and directly sending forged requests to the backend server. He recommends implementing biometric liveness detection and stricter server-side validation to prevent future fraud.",
        "content": "<p>The Brebes Police have uncovered a case of alleged misuse of the\nelectronic attendance system by civil servants (ASN) within the Brebes\nRegency Government, resulting in the arrest of nine suspects. The case\ncame to light following a report of illegal online attendance on 29-30\nApril 2026 by the Regional Human Resources Development and Personnel\nAgency (BKPSDMD). Investigations revealed that coordinate points were\nmanipulated, allowing ASN to clock in even when they were not at the\ndesignated location.<\/p>\n<p>Cybersecurity expert Alfons Tanujaya explained three possible methods\nused to carry out the fake attendance. The first involves using the Mock\nLocation feature on Android devices, where a cheating application\nregisters as a fake location provider, replacing the actual GPS signal.\nThe second method uses a rooted device or a framework to hook directly\ninto the Location Manager API, feeding fake coordinates to the target\napplication without being detected as a mock provider.<\/p>\n<p>The third scenario, which Alfons suspects is the most likely in this\ncase, involves sending requests directly to the attendance backend API.\n\u201cThis is likely what happened and should be a concern because the\nweakness lies in the attendance server. The app probably sent a request\ndirectly to the presensi backend API with a list of coordinates prepared\nbeforehand,\u201d Alfons told CNBC Indonesia. He noted that this is a serious\nissue, indicating that the server was not properly secured or was left\nopen, allowing reverse engineering of the protocol or API. This\nsuspicion is supported by an official statement that \u201cthe server was\nturned off but attendance records still went through.\u201d<\/p>\n<p>To prevent similar incidents, Alfons suggested several security\nmeasures. He recommended validating requests to ensure they come from\nunmodified devices and rejecting any direct API access without a valid\nsignature. He also advised cross-checking location signals beyond just\nGPS, such as verifying the WiFi BSSID and cell tower ID, as these cannot\nbe spoofed by mock location apps. Finally, he proposed upgrading to a\nbiometric liveness-based attendance system to ensure the physical\npresence of the individual, while maintaining strict server-side\nsecurity to block unauthorized direct API access.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/civil-servants-caught-faking-attendance-how-they-manipulated-the-system-and-how-to-prevent-it-1783324308",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}