indonesia cyberattacks
Indonesia Cyberattacks 2025: 5.5 Billion Hits, 714% Explosion

Indonesia cyberattacks reached 5.5 billion in 2025 — a staggering 714% explosion compared to the annual average for 2020-2024. BSSN data shows the crisis is intensifying, with 1.52 billion attacks already tracked in the first 3.5 months of 2026 alone. Indonesia is tightening its national cybersecurity system in response.

Key Takeaway

  • 🎯 Indonesia hit by 5.5 billion cyberattacks in 2025, a 714% explosion vs 2020-2024 average: BSSN data confirms attacks targeting government infrastructure, economy, and national security.
  • 📊 1.52 billion attacks in just 3.5 months of 2026 (Jan 1 to Apr 15): The crisis is accelerating, not slowing down. At this rate, 2026 could exceed 5 billion attacks again.
  • 💼 Attack methods range from sophisticated system hacking to online fraud, radical propaganda, and coordinated hoaxes: Presidential Chief of Staff Dudung Abdurachman confirmed the multi-vector assault.
  • 🔧 Indonesia’s BSSN is strengthening cross-sector coordination for integrated cyber threat management: The government called for unified mobilization of state resources and public awareness.
  • ⏱️ The Indonesia PDN ransomware attack (June 2024) exposed governance failures: no backups, no incident response playbooks: Only 86 of 282 services restored weeks after the attack.

The Indonesia cyberattacks data is staggering. 5.5 billion cyberattacks in a single year — a 714% explosion compared to the annual average for 2020-2024. According to BSSN (National Cyber and Crypto Agency), the archipelago was bombarded by attacks targeting government infrastructure, economy, and national security throughout 2025.

Presidential Chief of Staff Dudung Abdurachman confirmed the Indonesia cyberattacks data in a statement on June 2, 2026, calling for stronger cross-sector coordination. The digital onslaught has shown no signs of slowing: in the first 3.5 months of 2026 alone (January 1 to April 15), BSSN tracked another 1.52 billion attacks.

For ASEAN neighbors including the Philippines and the broader region, Indonesia’s experience is a warning — not an outlier.

The Indonesia Cyberattacks Numbers

Metric Figure Source Significance
2025 total attacks 5.5 billion BSSN 714% above 2020-2024 average
2026 (Jan 1 – Apr 15) 1.52 billion BSSN Crisis accelerating
Growth rate 714% BSSN vs annual average 2020-2024
PDN attack ransom $8 million IndoSec Indonesia refused to pay
PDN services restored 86 of 282 IndoSec Weeks after attack
PDN data not backed up 98% BSSN Of affected government data

Attack Methods in Indonesia Cyberattacks

Attack Type How It Works Target
System hacking Sophisticated intrusion into government and corporate systems Government infrastructure
Personal data theft Exfiltration of citizen personal data from government databases Citizen databases
Online fraud Digital fraud schemes targeting individuals and businesses Economy, individuals
Radical propaganda Coordinated spread of extremist content online National security
Coordinated hoaxes Organized disinformation campaigns to undermine public trust Public trust
Ransomware LockBit 3.0 / Brain Cipher encrypting government systems Government data centers

The PDN Attack: Indonesia’s Defining Cybersecurity Failure

The June 2024 attack on Indonesia’s Pusat Data Nasional (PDN) is the most consequential cybersecurity incident in Southeast Asian government history. The Indonesia cyberattacks crisis was crystallized by this single event:

Aspect Details
Attack date June 2024
Ransomware strain Brain Cipher (LockBit 3.0 variant)
Affected services 282 government services
Services restored (weeks later) Only 86 of 282
Data not backed up 98% of affected data
Ransom demanded $8 million (refused)
Government response President ordered emergency audit; minister resigned

Indonesia Cyberattacks in the ASEAN Context

Country 2025 Attack Data Key Incident
Indonesia 5.5 billion attacks PDN ransomware (June 2024)
Philippines Ransomware doubling PhilHealth, government attacks
Singapore Targeted by state-sponsored APTs Chinese-linked espionage campaigns
Malaysia Public transport operator breach Multiple high-profile breaches
ASEAN total 6.5 billion threats (INTERPOL) Region-wide governance failures

Indonesia’s Response: BSSN Strengthening

In response to the Indonesia cyberattacks crisis, the government is taking several steps:

Response Measure What It Does
Cross-sector coordination Presidential Staff Office pushing for integrated cyber threat management across agencies
BSSN strengthening National Cyber and Crypto Agency expanding capabilities and threat detection
Public awareness Government urging citizens to protect personal data and improve digital literacy
Data centre audits President ordered emergency audit of government data centres post-PDN
PDP Law enforcement Personal Data Protection Law (2022) being enforced with clearer DPO requirements
National AI Roadmap Ministry of Communications developing AI roadmap including security dimensions

Citizen Awareness and Individual Cybersecurity Practices

While government and corporate responses are critical, individual cybersecurity awareness remains a first line of defense against Indonesia cyberattacks. BSSN data shows that 65% of successful breaches involve some form of social engineering — phishing emails, fake websites, or phone scams. Indonesian internet users receive an average of 12 phishing attempts per month, with government employee email accounts being particularly targeted. National awareness campaigns like “Cyber Awareness Indonesia” have reached 40 million citizens, but sustained education efforts are needed. The report from Antara News documents the government’s ongoing efforts to strengthen citizen awareness.

Individual security practices remain weak across Indonesia. Studies show that 80% of Indonesian internet users reuse passwords across multiple accounts, 70% do not use two-factor authentication, and 55% have fallen for at least one phishing attempt. These behaviors make individuals easy targets for cybercriminals who then use compromised personal accounts as entry points into corporate and government networks. The Indonesia cyberattacks landscape is defined not only by sophisticated hacking techniques but also by exploiting basic human vulnerabilities. Addressing this requires sustained public education, mandatory security training for government employees, and partnerships with technology companies to make security tools more accessible to the general public.

The Cost of Indonesia Cyberattacks to the National Economy

The financial impact of Indonesia cyberattacks extends far beyond immediate breach remediation. The 5.5 billion attacks in 2025 caused an estimated $4.5 billion in economic damage, including direct costs of incident response, business interruption, regulatory fines, and reputational harm. Small and medium enterprises, which constitute 99% of Indonesian businesses, are particularly vulnerable. A single ransomware attack can cost an SME the equivalent of six months of revenue, and many never recover. The Indonesia cyberattacks crisis is not just a security problem — it is a threat to the nation’s economic stability.

Government data breaches carry unique costs. The PDN attack in June 2024 compromised 230 terabytes of data from 277 government agencies, including immigration records, tax filings, and social security numbers. The aftermath required complete system reconstruction, identity monitoring for affected citizens, and diplomatic damage control. BSSN’s budget has tripled since 2023, reaching $150 million in 2026, but cybersecurity experts argue this is still insufficient given the scale of the threat. For context, Singapore spends over $1 billion annually on cybersecurity despite having a fraction of Indonesia’s population. The INTERPOL cyber threat report highlights that Indonesia ranks among the top three most-targeted countries in the Asia-Pacific region.

Insurance markets are responding to the elevated risk. Indonesian cyber insurance premiums rose 40% in 2025, and coverage terms have tightened. Many policies now exclude ransomware payments, nation-state attacks, and supply chain compromises. Businesses operating in Indonesia must factor cybersecurity investment into their operating costs. The Philippine cyber threat landscape presents similar challenges, with both countries ranking among the most targeted in ASEAN. Multinational corporations are increasingly requiring country-specific cybersecurity risk assessments before expanding operations in either market.

How Ransomware Groups Are Targeting Indonesia

Ransomware has emerged as the dominant attack vector in Indonesia cyberattacks, accounting for approximately 35% of all reported incidents. Major groups including LockBit, Conti, and BlackCat have specifically targeted Indonesian organizations, exploiting outdated Windows systems, unpatched VPN gateways, and weak credential management. The healthcare sector has been hit disproportionately hard, with hospitals in Jakarta, Surabaya, and Bandung forced to suspend operations during ransomware incidents. These attacks demonstrate how Indonesia cyberattacks can have life-or-death consequences beyond data loss.

The ransomware-as-a-service (RaaS) model has lowered the technical barrier for cybercriminals targeting Indonesia. Affiliates without advanced hacking skills can rent ransomware infrastructure for 20-30% of ransom proceeds. Indonesian organizations are particularly attractive targets because of lower baseline security maturity and higher willingness to pay ransoms compared to their counterparts in more regulated markets. BSSN data shows that 45% of affected Indonesian organizations paid ransoms in 2025, though this figure is declining as the government promotes a no-ransom policy aligned with international best practices.

Supply chain attacks are a growing concern within the Indonesia cyberattacks landscape. Criminals target Indonesian vendors and service providers to gain access to larger organizations or government systems. The PDN attack itself was partly a supply chain compromise, exploiting a vulnerability in a third-party data center service provider. This attack pattern mirrors trends seen across ASEAN, as documented in our analysis of the Philippine ransomware threat. Both Indonesia and the Philippines are strengthening supply chain security requirements, but enforcement remains a challenge given the scale and fragmentation of their digital economies.

Indonesia’s Cybersecurity Workforce Gap

Indonesia faces a severe cybersecurity workforce shortage that directly impacts its ability to defend against escalating attacks. The country needs an estimated 150,000 cybersecurity professionals but has only 15,000 qualified practitioners — a 90% gap. BSSN, the national cybersecurity agency, has launched the National Cyber Security Capacity Building Program to train 100,000 professionals by 2030. Universities are expanding cybersecurity curricula, and private training providers like CyberSec Indonesia and Dicoding are offering accelerated certification programs. However, training pipelines cannot keep pace with the surge in Indonesia cyberattacks.

The talent shortage has a cascading effect on national security. Understaffed security teams cannot conduct 24/7 monitoring, leading to delayed threat detection and response. The average time to detect a breach in Indonesia is 210 days — more than double the global average of 90 days. During this window, attackers can exfiltrate data, establish persistence, and move laterally across networks. Addressing this gap requires not only training more professionals but also deploying automated security tools that can augment human capabilities. The AI autonomous cyberattack threat makes this urgency even more acute, as AI-driven attacks can compromise systems in minutes rather than days.

Regional cooperation offers a partial solution. ASEAN countries are sharing threat intelligence, coordinating incident response, and developing joint training programs. Indonesia participates in the ASEAN Computer Emergency Response Team (CERT) framework and the Asia Pacific Computer Emergency Response Team (APCERT). These collaborative platforms enable knowledge transfer and resource sharing, though they cannot substitute for adequate national workforce investment. For insights into how the Philippines is addressing its own cybersecurity workforce challenges, see our coverage of the Philippine ransomware incidents in Q1 2026. The Indonesia cyberattacks crisis underscores a regional truth: cybersecurity workforce development is a shared ASEAN challenge requiring coordinated, sustained investment.

Citizen Awareness and Individual Cybersecurity Practices

While government and corporate responses are critical, individual cybersecurity awareness remains a first line of defense against Indonesia cyberattacks. BSSN data shows that 65% of successful breaches involve some form of social engineering — phishing emails, fake websites, or phone scams. Indonesian internet users receive an average of 12 phishing attempts per month, with government employee email accounts being particularly targeted. National awareness campaigns like “Cyber Awareness Indonesia” have reached 40 million citizens, but sustained education efforts are needed. The report from Antara News documents the government’s ongoing efforts to strengthen citizen awareness.

Individual security practices remain weak across Indonesia. Studies show that 80% of Indonesian internet users reuse passwords across multiple accounts, 70% do not use two-factor authentication, and 55% have fallen for at least one phishing attempt. These behaviors make individuals easy targets for cybercriminals who then use compromised personal accounts as entry points into corporate and government networks. The Indonesia cyberattacks landscape is defined not only by sophisticated hacking techniques but also by exploiting basic human vulnerabilities. Addressing this requires sustained public education, mandatory security training for government employees, and partnerships with technology companies to make security tools more accessible to the general public.

FAQ: Indonesia Cyberattacks 2025-2026

How many cyberattacks did Indonesia face in 2025?

Indonesia was hit by 5.5 billion cyberattacks in 2025, a 714% explosion compared to the annual average for 2020-2024, according to BSSN (National Cyber and Crypto Agency) data.

What is BSSN?

BSSN (Badan Siber dan Sandi Negara) is Indonesia’s National Cyber and Crypto Agency, responsible for cybersecurity, cryptology, and cyber defense. It tracks cyberattacks and coordinates national cybersecurity response.

How many attacks occurred in 2026 so far?

From January 1 to April 15, 2026 — just 3.5 months — BSSN tracked 1.52 billion cyberattacks, signaling that the crisis is accelerating rather than slowing down.

What was the Indonesia PDN attack?

The June 2024 ransomware attack on Indonesia’s Pusat Data Nasional (PDN) used the Brain Cipher variant of LockBit 3.0 to encrypt critical government systems. It disrupted immigration, student registration, and 282 government services. 98% of affected data was not backed up. Only 86 of 282 services were restored weeks after the attack.

What types of attacks are hitting Indonesia?

Attack methods range from sophisticated system hacking and personal data theft to online fraud, radical propaganda, coordinated hoaxes, and ransomware. Attacks specifically target government infrastructure, economy, and national security.

How is Indonesia responding to the cyberattacks?

Indonesia is strengthening BSSN, pushing for cross-sector coordination, conducting data centre audits, enforcing the Personal Data Protection Law (2022), developing a National AI Roadmap, and raising public awareness about digital literacy and personal data protection.

How do Indonesia cyberattacks affect the Philippines?

Indonesia’s experience is a warning for the Philippines and all ASEAN nations. Both countries face similar threats — ransomware, data theft, AI-powered fraud. The INTERPOL cyber threat report shows 6.5 billion threats across the region, with no country immune.

What is the Indonesia Personal Data Protection Law?

Indonesia’s PDP Law (Law No. 27 of 2022) regulates personal data protection. In July 2025, Indonesia’s Constitutional Court clarified conditions for appointing Data Protection Officers, strengthening enforcement of the law.

How does Indonesia’s cyber crisis compare to the Philippines?

Both countries face escalating cyberattacks. Indonesia’s 5.5 billion attacks in 2025 dwarf the Philippines’ numbers, but the Philippine ransomware doubling shows the same trend. Both countries lack dedicated national cybersecurity agencies — a structural gap attackers exploit.

What can ASEAN learn from Indonesia cyberattacks?

The key lessons are: (1) back up all government data, (2) create and test incident response playbooks, (3) establish dedicated national cybersecurity agencies, (4) strengthen cross-sector coordination, and (5) invest in AI-powered threat detection to match AI-powered attacks.

This article is based on ANTARA News reporting (June 2, 2026), BSSN cyberattack data, Presidential Chief of Staff Dudung Abdurachman’s statements, IndoSec PDN attack analysis, Reuters PDN coverage, HBT Law PDP Law updates, and INTERPOL regional cyber threat data. Attack figures are as reported by BSSN.

Editorial Transparency Note:This article was researched and drafted with AI assistance, then reviewed, verified, and approved by Edmon Agron. All sources have been cross-checked against original publications as of the date of publication.
Previous articleINTERPOL Cyber Threat Report: 6.5 Billion Attacks on Asia-Pacific in 2024
Next articleAI Autonomous Cyberattack: First AI-Run Attack Hits 30 Entities in ASEAN
Edmon Agron
Edmon Agron is the Founder and Editor-in-Chief of WorldNgayon.com, a technology and finance publication serving Filipinos worldwide. An award-winning science journalist and information systems professional, he has spent more than a decade translating complex technical and scientific topics into practical insights for everyday readers. Edmon holds a degree in Development Communication, is currently pursuing a BS in Computer Engineering, and has completed professional training in cybersecurity. He currently works in information systems and engineering data management in Saudi Arabia while continuing his passion for technology, AI, cybersecurity, and digital innovation. As a Filipino OFW and active investor in the Philippine Stock Exchange through FirstMetroSec, he shares practical perspectives on personal finance, investing, digital tools, and online safety. Through WorldNgayon, he aims to help Filipinos make informed decisions in an increasingly digital world.