Cyber security expert warns of personal data misuse risks in MPLS uploads
Cyber security observer Pratama Persadha has stated that the trend of new students uploading ‘twibbon’ frames to social media during the School Environment Introduction Period (MPLS) carries risks to personal data if not published wisely. He noted that students’ personal information shared through MPLS twibbon uploads can be accessed, copied, stored, and even exploited by irresponsible parties.
‘From the perspective of togetherness and pride in being part of a new school, this trend certainly has positive value. However, from a cyber security and personal data protection standpoint, this habit also needs to be addressed more wisely,’ Pratama said when contacted by ANTARA in Jakarta on Saturday.
The chairman of the cyber security research institute CISSReC assessed that uploads displaying facial photos, full names, domiciles, school origins, and other identities are not inherently dangerous. However, the risk to personal data increases when all this information is published openly, making it easy for cyber criminals to collect it using Open Source Intelligence, or OSINT, techniques.
‘This technique allows various pieces of information scattered across the internet to be collected, correlated, and compiled into a person’s digital profile without needing to hack their account. The more data shared voluntarily, the easier it is to map someone’s identity,’ he explained.
Pratama explained that criminals can use students’ personal information to conduct social engineering by impersonating others and influencing people through seemingly convincing communication. According to him, fraud schemes involving individuals posing as teachers, school committee members, classmates, or parents are easier to execute if the perpetrator has basic information about the victim.
Furthermore, published facial photos risk being exploited to create fake identities and for image manipulation using artificial intelligence. Other risks include an increased potential for digital bullying, online harassment, stalking, and surveillance of children’s activities.
Pratama explained that armed with personal information, a perpetrator can identify the victim’s school, estimate the location of their daily activities, recognise their friends, and then build communication that appears natural. ‘This is particularly dangerous for children and teenagers, who generally do not yet have the ability to recognise various digital manipulation schemes,’ he said.
Therefore, Pratama encouraged schools and parents to enhance digital literacy education for children from an early age so they understand the importance of safeguarding personal data and the risks of digital footprints. Information displayed in MPLS uploads should ideally be limited to what is necessary, such as only including a first name or nickname.
‘MPLS twibbon frames are not something to be avoided. What needs to be built is a better digital literacy culture so that the spirit of introducing oneself can still be carried out without sacrificing personal data security,’ he said.