Cybersecurity in Capital Markets: A Wake-Up Call for Indonesia Protecting Investor Funds in the Age of Digital Threats

Cybersecurity in Capital Markets: A Wake-Up Call for Indonesia Protecting Investor Funds in the Age of Digital Threats

By Dr. Ir. Charles Lim, Msc., Bsc., CSAP, Security+, CySA+, CND, CCSE, CTIA, CHFI, EDRP, ECSA, ECSP, ECIH, CEH, CEI

Deputy Head of Master IT Program
Head of Cybersecurity Research Centre of Excellence
Head of Security Operations Center
Swiss German University

In Mid-September 2025, Indonesia’s capital market was shaken by a series of high-profile cybersecurity incidents. Several securities firms became victims of attacks that led to disrupted operations, unauthorized fund withdrawals, and shaken investor confidence.  These incidents highlight not only weaknesses in technology but also the urgent need for stronger governance, regulatory oversight, and investor awareness.  This article explores what happened, the lessons learned, and how investors and institutions can prepare for a safer digital future.

The Incidents: What Happened

Four major cases stood out in 2025:

  • RHB Sekuritas
    Unauthorized withdrawals of approximately IDR 70 billion were made from investor settlement accounts (Rekening Dana Nasabah, or RDN) held at Bank Permata. The breach was linked to suspicious transfers through Permata E-Business. RHB’s trading app, TradeSmart, also suffered disruptions [1].
  • NH Korindo Sekuritas
    In May, a cyberattack crippled its trading system for over a week. While no RDN funds were lost, the firm suffered significant reputational damage [2].
  • Trimegah Sekuritas
    Faced a system attack similar to NH Korindo. Media reports estimated industry-wide losses of up to IDR 200 billion, though Trimegah did not confirm direct financial impact [2].
  • Panca Global Sekuritas
    The most severe case. In September, IDR 70 billion was siphoned from RDN accounts at Bank Central Asia (BCA). Funds were repeatedly withdrawn via BCA Klik Bisnis, raising suspicions of compromised credentials or insider involvement. The Financial Services Authority (OJK) launched an investigation, and some stolen funds were eventually returned [3]–[5].

Together, these events represent one of the largest security shocks in Indonesia’s capital market history.

Lessons Learned

  1. Strong Authentication and Access Control Are Non-Negotiable
    Hackers exploited weak or compromised RDN access points. Enforcing multi-factor authentication (MFA), transfer limits, and stricter whitelist rules could have reduced risks [3], [6].
  2. Insider Threats Cannot Be Ignored
    Certain transactions would have been difficult without insider knowledge. Internal audits, job rotations, and stronger separation of duties are crucial [4].
  3. Real-Time Fraud Detection Saves Money and Trust
    Suspicious withdrawals occurred multiple times before detection. AI-driven fraud monitoring could have flagged unusual patterns earlier [7], [8].
  4. Transparency and Quick Response Matter
    Investor trust depends not only on incident prevention but also on how firms respond. Panca Global’s swift fund recovery and regulatory cooperation were key steps [3].
  5. Regulatory Oversight Must Evolve
    OJK and IDX urged firms to strengthen cybersecurity, but more is needed. Mandatory audits, compliance standards, and global best-practice adoption are essential [5], [9].
  6. Cybersecurity Is Not Only a Technical Problem
    Culture, governance, and awareness matter. Employees must follow safe practices, while investors should secure OTPs and avoid phishing [7].
  7. Preparedness and Recovery Plans Are Crucial
    NH Korindo and Trimegah’s outages showed how attacks paralyze markets. Backup systems, response playbooks, and crisis communication are vital [2].

Recommendations

For Securities Firms and Banks

  • Enforce MFA and strict transfer whitelisting.
  • Conduct regular penetration testing and independent audits.
  • Deploy AI-driven fraud detection systems.
  • Strengthen insider risk management through logging and access controls.
  • Establish clear incident response frameworks and investor communication strategies.

For Regulators (OJK, IDX, KSEI)

  • Update RDN security guidelines with mandatory fraud detection.
  • Impose stricter penalties for non-compliance.
  • Encourage industry-wide cybersecurity drills and simulations.
  • Foster stronger collaboration among banks, brokers, and regulators.

For Investors

  • Monitor RDN accounts regularly.
  • Use strong passwords, 2FA, and secure devices.
  • Stay alert for phishing attempts via SMS, email, or fake apps.
  • Report suspicious activity immediately to brokers and banks.

Conclusion

The 2025 cyberattacks on Indonesia’s capital market revealed systemic vulnerabilities that, if left unaddressed, could erode investor trust.  Technology is only part of the solution. Culture, governance, and regulatory enforcement are equally critical.  The biggest takeaway is clear: cybersecurity must be treated as a core pillar of financial stability, not an afterthought. Only through strong collaboration between investors, institutions, and regulators can Indonesia build a resilient and trustworthy capital market in the digital age.

References
[1] Bloomberg Technoz, “Beredar Dugaan Pembobolan RDN Sebelum Aplikasi Trading RHB Error,” May 2025. [Online]. Available: https://www.bloombergtechnoz.com/detail-news/78608/beredar-dugaan-pembobolan-rdn-sebelum-aplikasi-trading-rhb-error/2
[2] CNBC Indonesia, “Serangan Siber Lumpuhkan NH Korindo & Trimegah Sekuritas,” May 2025. [Online]. Available: https://www.cnbcindonesia.com/market
[3] Tempo, “Kronologi Pembobolan Rekening Rp70 Miliar di BCA,” Sept. 2025. [Online]. Available: https://www.tempo.co/ekonomi/kronologi-pembobolan-rekening-rp-70-miliar-di-bca-2069219
[4] Infobanknews, “Dugaan Pembobolan RDN, Faktor Internal Jadi Sorotan,” Sept. 2025. [Online]. Available: https://infobanknews.com/dugaan-pembobolan-rdn-faktor-internal-dan-sistem-keamanan-jadi-sorotan
[5] CNBC Indonesia, “OJK Turun Tangan Kasus RDN Dibobol Rp70 Miliar,” Sept. 2025. [Online]. Available: https://www.cnbcindonesia.com/market
[6] Detik Finance, “BCA Buka Suara soal Dugaan Pembobolan RDN Sekuritas,” Sept. 2025. [Online]. Available: https://finance.detik.com/moneter
[7] Tech for Good Institute, “Indonesia’s Cyber Resilience at the Epicenter of ASEAN Digital Economy Growth,” 2025. [Online]. Available: https://techforgoodinstitute.org/blog
[8] IndoSec Summit, “The Escalating Cyber Threat in Indonesia: A Wake-Up Call,” 2025. [Online]. Available: https://www.indosecsummit.com
[9] Trade.gov, “Indonesia Cybersecurity Market Intelligence,” 2025. [Online]. Available: https://www.trade.gov/market-intelligence/indonesia-cybersecurity
[10] The Jakarta Post, “Cybersecurity Breaches on Major Securities Firms Raise Alarm,” July 2025. [Online]. Available: https://www.thejakartapost.com/opinion