Belum ada produk di keranjang belanja kamu

Cyber Heist: The Digital “Tuyul” That Quietly Empties Bank Vaults

Oleh Eko B. Supriyanto
Sumber: Infobank

Sumber: Infobank

BEYOND the glare of global headlines, as Trump’s tariffs stirred outrage and uncertainty, something far more silent and sinister crept through Indonesia’s banking system. What began as a media stir around Bank DKI, just before last year’s Eid, was only the tip of the iceberg. In the shadows, four other banks were quietly infiltrated, their systems breached without public notice. The perpetrators? Not your usual cybercriminals, but elusive digital thieves likened to tuyul, a mischievous spirit figures from local folklore said to sneak into homes and steal fortunes. By the time the dust began to settle, more than five hundred sixty billion rupiah had simply vanished.

These attacks occurred in two major waves: the first involving over 414 billion rupiah across six incidents, and the second totalling nearly one hundred forty-seven billion rupiah across two incidents. . This new breed of “digital tuyul” doesn’t merely disrupt, it steals money outright. Funds vanish from systems without a trace.

The methods used targeted financial institutions directly and have impacted six banks, primarily in the KBMI One and KBMI Two categories, consisting of small to medium-sized banks, between late 2024 and the current year. The common modus operandi involves fund transfer transactions in which customer accounts remain untouched, while the bank’s settlement accounts are drained. These breaches can result from system interceptions with vulnerabilities lying across three primary channels: the banks themselves, switching networks, and the BI-Fast system.

Cyber heists differ significantly from the ransomware attacks that were common in earlier years. Ransomware typically involves extortion, encrypting data and demanding a ransom for its release. These attacks target all sectors, including micro, small, and medium enterprises (MSMEs), and often paralyze operations by locking access to vital information.

From the cases examined, there appear to be two main sources of vulnerability, external and internal. The first two banks were compromised through the switching network. The third bank avoided catastrophe when suspicious activity was detected early, and the channel was immediately closed, saving the institution from financial loss.

The fourth and fifth banks, however, were breached via the BI-Fast routing system. The transaction values involved were also considerable. Within the banking community, quiet concerns have been raised about the shortcomings of Fraud Detection Systems (FDS). Transactions that should have been f lagged were only discovered after anomalies appeared in settlement balances. Simply put, neither the banks’ FDS nor BI-Fast’s FDS functioned as they should have.

Rather than placing blame, this crisis calls for collective action. Combating cyber heists demands cooperation and internal reflection from all parties involved, from switching networks and individual banks to Bank Indonesia as the operator of BI-Fast. .

These digital tuyul are still roaming. It’s like a community savings group (arisan) being targeted one by one. If Bank X is hit today, Bank Y may be next. The troubling question is, if even the arisan is being looted, something is fundamentally wrong. Cybercrime is now one of the most terrifying threats facing banks. Operational risk has reached a new level. The challenge is no longer just about bad loans, it’s about the relentless danger of cyber heists.

According to the Infobank Institute, there are three critical lessons to be learned:

First, reform policies and procedures. Regularly review liquidity thresholds, ensure twenty-four-seven transaction monitoring, establish a system for tracing fraudulent fund flows, and report fraud promptly to the Financial Transaction Reports and Analysis Center (PPATK) and the police. Most importantly, develop a communication strategy as an official part of crisis policy, what should be communicated and how, when a breach occurs.

Second, strengthen human resources. Prepare emergency response teams and ensure staffing for real time transaction monitoring. Equally important is educating customers about the reality and dangers of cybercrime.

Third, upgrade technology and processes. This means at minimum, performing daily transaction reconciliations. It is time to stop assigning blame and start reflecting inward. The pattern in these cases suggests that everyone involved bears some responsibility. Let’s begin with self-correction.

Are we truly prepared with early-warning systems that work? Cyber heists are a far greater and more immediate threat than tariff negotiations that leave us looking naïve and economically burdened. These cyber-attacks are like invisible spirits, tuyul digital, that silently raid the vaults of our banks, draining accounts before anyone even notices. Stay vigilant.

These attacks occurred in two major waves: the first involving over 414 billion rupiah across six incidents, and the second totalling nearly one hundred forty-seven billion rupiah across two incidents. . This new breed of “digital tuyul” doesn’t merely disrupt, it steals money outright. Funds vanish from systems without a trace.

Lanjut baca artikel

Rekomendasi Terbaik

Mulai Berlangganan
Premium Infobank Digital

  • Akses ke Semua Artikel dari Semua Edisi Majalah Infobank

  • Baca Artikel & Majalah Tanpa Iklan

  • Kemudahan Akses di Berbagai Perangkat Web & Mobile

MULAI LANGGANAN

Beli majalah
Infobank Edisi Mei 2025

Rp 65.000

BELI