Indonesia Cyber Attacks Inflict US$6.2 Billion in Losses This Year

In this article (9)
Cyber attacks caused an estimated US$6.2 billion in financial damage across Indonesia during 2026, Bank Indonesia Governor Destry Damayanti announced in Jakarta on Thursday.
Central bank officials linked the losses directly to automated tools and artificial intelligence. These technologies multiply payment fraud, scam operations, and data theft across consumer networks.
Surging Risks in Digital Payments
Destry urged government ministries and commercial agencies to tighten payment security standards and enforce direct consumer protections. The central bank holds the statutory mandate to supervise and develop the country’s payment infrastructure.
Digital networks expand domestic economic output. Still, the governor warned that interconnected systems leave merchant acquiring channels and retail banking endpoints exposed to automated intrusion. Joint security literacy programs with the Financial Services Authority are planned to train consumers and retail operators.
ISP Group Pushes Security Bill
Backing the central bank’s warning, the Indonesian Internet Service Providers Association (APJII) demanded swift passage of the Cyber Security and Resilience Bill. Commercial internet providers require uniform technical standards and legal clarity to defend national digital infrastructure against automated threats, according to APJII Chair Muhammad Arif.
“Indonesian service providers need legal certainty to grow, not disruptive regulations,” said Arif.
Monitoring data from APJII tracked 246.4 million connections to dangerous IP addresses between June 13 and August 28, 2026. A separate three-day network scan by the association recorded roughly 68 million distinct cyber attack events targeting domestic routes.
Direct Pressures on Retail and Finance
For retail merchants, digital lenders, and e-commerce platforms operating across Southeast Asia’s largest market, these financial losses raise basic operating costs. Acceptance of QR codes and instant transfer rails expanded rapidly over the past three years. Back-end defense budgets frequently lagged that growth.
Platforms now face higher chargeback rates, elevated verification costs, and direct liability when account credentials leak. Operators that fail to upgrade transaction authentication face friction at checkout. Financial institutions risk regulatory penalties if compromised channels disrupt daily settlement flows.
Escalating Breach Scale Since 2025
The US$6.2 billion tally reflects climbing attack sophistication following major infrastructure breaches over the previous eighteen months. Regional lender Bank DKI suffered repeated network intrusions that produced over US$15 million in irregular transactions, showing how attackers breach core accounting ledgers.
Parliamentary debate on the Cyber Security and Resilience Bill now enters committee reviews. Enterprise software providers and payment processors are tracking whether mandatory incident-reporting rules will carry statutory fines before the legislative session closes.
Questions & Answers
Q.What is the primary cause identified for the increase in cyber attack losses?
What is the primary cause identified for the increase in cyber attack losses?
Central bank officials directly linked the losses to automated tools and artificial intelligence. These technologies multiply payment fraud, scam operations, and data theft across consumer networks.
Q.Which government bodies are working together to address the cyber security risks?
Which government bodies are working together to address the cyber security risks?
Bank Indonesia is planning joint security literacy programmes with the Financial Services Authority. These programmes aim to train consumers and retail operators to improve their security awareness.
Q.What is the Indonesian Internet Service Providers Association (APJII) demanding?
What is the Indonesian Internet Service Providers Association (APJII) demanding?
The APJII is demanding the swift passage of the Cyber Security and Resilience Bill. They state that commercial internet providers need uniform technical standards and legal clarity to defend national digital infrastructure.
Q.How do these cyber attacks impact retail merchants and financial institutions?
How do these cyber attacks impact retail merchants and financial institutions?
Retail merchants face higher chargeback rates, elevated verification costs, and direct liability from credential leaks. Financial institutions risk regulatory penalties if compromised channels disrupt daily settlement flows.
Reader pulse
Is Indonesia doing enough?
19,629 votes so far