Skip to content
Research

Indonesia Cyber Attacks Inflict US$6.2 Billion in Losses This Year

By Minjun ParkIndonesia
2 min read
data protection and cyber
data protection and cyber
In this article (9)

Cyber attacks caused an estimated US$6.2 billion in financial damage across Indonesia during 2026, Bank Indonesia Governor Destry Damayanti announced in Jakarta on Thursday.

Central bank officials linked the losses directly to automated tools and artificial intelligence. These technologies multiply payment fraud, scam operations, and data theft across consumer networks.

Surging Risks in Digital Payments

Destry urged government ministries and commercial agencies to tighten payment security standards and enforce direct consumer protections. The central bank holds the statutory mandate to supervise and develop the country’s payment infrastructure.

Digital networks expand domestic economic output. Still, the governor warned that interconnected systems leave merchant acquiring channels and retail banking endpoints exposed to automated intrusion. Joint security literacy programs with the Financial Services Authority are planned to train consumers and retail operators.

ISP Group Pushes Security Bill

Backing the central bank’s warning, the Indonesian Internet Service Providers Association (APJII) demanded swift passage of the Cyber Security and Resilience Bill. Commercial internet providers require uniform technical standards and legal clarity to defend national digital infrastructure against automated threats, according to APJII Chair Muhammad Arif.

“Indonesian service providers need legal certainty to grow, not disruptive regulations,” said Arif.

Monitoring data from APJII tracked 246.4 million connections to dangerous IP addresses between June 13 and August 28, 2026. A separate three-day network scan by the association recorded roughly 68 million distinct cyber attack events targeting domestic routes.

Direct Pressures on Retail and Finance

For retail merchants, digital lenders, and e-commerce platforms operating across Southeast Asia’s largest market, these financial losses raise basic operating costs. Acceptance of QR codes and instant transfer rails expanded rapidly over the past three years. Back-end defense budgets frequently lagged that growth.

Platforms now face higher chargeback rates, elevated verification costs, and direct liability when account credentials leak. Operators that fail to upgrade transaction authentication face friction at checkout. Financial institutions risk regulatory penalties if compromised channels disrupt daily settlement flows.

Escalating Breach Scale Since 2025

The US$6.2 billion tally reflects climbing attack sophistication following major infrastructure breaches over the previous eighteen months. Regional lender Bank DKI suffered repeated network intrusions that produced over US$15 million in irregular transactions, showing how attackers breach core accounting ledgers.

Parliamentary debate on the Cyber Security and Resilience Bill now enters committee reviews. Enterprise software providers and payment processors are tracking whether mandatory incident-reporting rules will carry statutory fines before the legislative session closes.

Questions & Answers

Q.

What is the primary cause identified for the increase in cyber attack losses?

A.

Central bank officials directly linked the losses to automated tools and artificial intelligence. These technologies multiply payment fraud, scam operations, and data theft across consumer networks.

Q.

Which government bodies are working together to address the cyber security risks?

A.

Bank Indonesia is planning joint security literacy programmes with the Financial Services Authority. These programmes aim to train consumers and retail operators to improve their security awareness.

Q.

What is the Indonesian Internet Service Providers Association (APJII) demanding?

A.

The APJII is demanding the swift passage of the Cyber Security and Resilience Bill. They state that commercial internet providers need uniform technical standards and legal clarity to defend national digital infrastructure.

Q.

How do these cyber attacks impact retail merchants and financial institutions?

A.

Retail merchants face higher chargeback rates, elevated verification costs, and direct liability from credential leaks. Financial institutions risk regulatory penalties if compromised channels disrupt daily settlement flows.

Reader pulse

Is Indonesia doing enough?

19,629 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready