Ransomware Attacks and Criminal Accountability: Contemporary Issues in Indonesian Cybercrime Enforcement

Authors

  • Kurniawan Akbar Ministry of Law Republic of Indonesia Author

Keywords:

Ransomware, Cybercrime, Indonesia, Criminal Accountability, Cybersecurity, Digital Crime, Electronic Evidence

Abstract

Ransomware attacks have become one of the most disruptive forms of cybercrime globally, including in Indonesia, targeting government institutions, businesses, and critical infrastructure. These attacks pose significant challenges for criminal accountability due to anonymity of perpetrators, cross-border execution, and use of encrypted technologies. This article analyzes the legal and enforcement challenges associated with ransomware crimes in Indonesia. Using normative legal research and doctrinal analysis, the study examines the adequacy of existing cybercrime provisions under Indonesian law in addressing ransomware-related offences. The findings indicate that while ransomware activities may be prosecuted under general cybercrime and electronic information laws, the absence of specific legal categorization creates interpretive and enforcement difficulties. Challenges also arise in attribution of liability, recovery of digital assets, and international cooperation in tracing perpetrators. The article argues that Indonesia’s current legal framework requires modernization to effectively respond to ransomware threats. It proposes the development of specialized cybercrime regulations, enhanced incident response mechanisms, and stronger collaboration with international cybersecurity agencies. The study concludes that effective criminal accountability for ransomware attacks depends on integrating legal reform with technological and institutional capacity-building.

References

Ashworth, A., & Zedner, L. (2014). Preventive Justice. Oxford University Press. https://doi.org/10.1093/acprof:oso/9780199675556.001.0001

Badan Siber dan Sandi Negara (BSSN). (2023). Indonesia National Cybersecurity Strategy and Cyber Resilience Framework. Jakarta: BSSN.

Brenner, S. W. (2010). Cybercrime: Criminal Threats from Cyberspace. Praeger.

Brewer, R. (2016). Ransomware attacks: Detection, prevention and cure. Network Security, 2016(9), 5–9. https://doi.org/10.1016/S1353-4858(16)30086-1

Broadhurst, R., Grabosky, P., Alazab, M., & Chon, S. (2014). Organizations and cybercrime: An analysis of the nature of groups engaged in cybercrime. International Journal of Cyber Criminology, 8(1), 1–20.

Casey, E. (2011). Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet (3rd ed.). Academic Press.

Council of Europe. (2001). Convention on Cybercrime (Budapest Convention). Strasbourg: Council of Europe.

Council of Europe. (2022). Second Additional Protocol to the Budapest Convention.

Duff, R. A. (2018). The Realm of Criminal Law. Oxford University Press.

ENISA. (2023). ENISA Threat Landscape 2023.

European Union Agency for Cybersecurity (ENISA). (2023). ENISA Threat Landscape 2023.

Europol. (2023). Internet Organised Crime Threat Assessment (IOCTA) 2023.

FATF. (2023). Virtual Assets and Virtual Asset Service Providers: Updated Guidance.

Greenleaf, G. (2022). Global Data Privacy Laws 2021: Despite COVID Delays, 145 Laws Show GDPR Dominance. Privacy Laws & Business International Report.

Holt, T. J. (2016). Exploring the intersections of technology, crime, and terrorism. Terrorism and Political Violence, 28(2), 337–354. https://doi.org/10.1080/09546553.2016.1155948

Indonesia. Law No. 1 of 2024 concerning the Second Amendment to the Electronic Information and Transactions Law.

Indonesia. Law No. 11 of 2008 concerning Electronic Information and Transactions.

Indonesia. Law No. 19 of 2016 concerning Amendments to Law No. 11 of 2008 concerning Electronic Information and Transactions.

Indonesia. Law No. 27 of 2022 concerning Personal Data Protection.

INTERPOL. (2023). Global Crime Trend Report.

Kshetri, N. (2022). Cybersecurity Management: An Organizational and Strategic Approach. University of Toronto Press.

Leukfeldt, E. R., Lavorgna, A., & Kleemans, E. R. (2017). Organised cybercrime and criminal networks. Trends in Organized Crime, 20(4), 347–356. https://doi.org/10.1007/s12117-017-9308-z

Maras, M. H. (2016). Computer Forensics: Cybercriminals, Laws, and Evidence (3rd ed.). Jones & Bartlett Learning.

Moeljatno. (2008). Asas-Asas Hukum Pidana. Jakarta: Rineka Cipta.

OECD. (2022). Enhancing Trust and Security in the Digital Economy.

Paquet-Clouston, M., Haslhofer, B., & Dupont, B. (2019). Ransomware payments in the Bitcoin ecosystem. Journal of Cybersecurity, 5(1), tyz003. https://doi.org/10.1093/cybsec/tyz003

UNODC. (2013). Comprehensive Study on Cybercrime. United Nations Office on Drugs and Crime.

Wall, D. S. (2007). Cybercrime: The Transformation of Crime in the Information Age. Polity Press.

Yar, M., & Steinmetz, K. F. (2019). Cybercrime and Society (3rd ed.). Sage Publications.

Downloads

Published

2025-07-15

How to Cite

“Ransomware Attacks and Criminal Accountability: Contemporary Issues in Indonesian Cybercrime Enforcement”. 2025. Indonesian Journal of Digital Crime and Criminal Justice 1 (2): 245-76. https://journal.criminallawinstitute.org/JDCCJ/article/view/27.