Belum ada produk di keranjang belanja kamu

Perspective

Emergency! Cybersecurity Threat in Neglected Securities Firms

Oleh Eko B. Supriyanto

DIGITAL “muggers” are still on the prowl. The banking sector was the first to be raided by these digital predators. Now, as banks have become somewhat better prepared, these account “phantoms” have shifted their attacks to the capital market. One by one, securities firms are being hacked by cyber heists. The situation has already reached an emergency level. Beyond the inadequacy of cybersecurity systems, awareness of cybersecurity itself remains minimal, leaving 93 securities firms and 17 million investor accounts exposed.

Behind the convenience and speed of online and mobile trading platforms lies a widening black hole of danger. The series of cyberattacks striking the securities sector throughout 2025 are not isolated incidents. They are acute symptoms of a system still unprepared to face the complexity of today’s digital threats.

The cases that have surfaced so far are just the tip of the iceberg. What appears on the surface is already alarming, but what lies beneath may be far worse. Consider a few examples. First, the incidents at Trimegah Sekuritas and Panca Global Sekuritas highlight a fundamental vulnerability: investor fund accounts (Rekening Dana Nasabah, RDN). RDNs are the lifeblood of transactions, linking the banking world with the capital market.

The key issue here is the effectiveness of security protocols. How could large sums of money be transferred without strict double-check mechanisms or multi-factor authentication? This points not merely to individual negligence but to a systemic failure.

Second, the surge in account takeover cases at major securities firms such as Mirae Asset and Sinarmas shows that threats do not always come from sophisticated system hacks. More often, they stem from social engineering that exploits human psychology. Criminals prey on investor carelessness through phishing, fraudulent investment schemes, or malware that steals login credentials.

Third, the attacks on NH Korindo Sekuritas and Mandiri Sekuritas took the threat to a completely different level. These did not merely target individual funds but crippled the core of company operations. Ransomware rendered systems inoperable, dealing a devastating blow to reputation and business continuity. Within hours, all trading activity came to a halt. Public trust—the most vital asset of financial services—was instantly torn apart.

The series of cyberattacks striking the securities sector throughout 2025 are not isolated incidents. They are acute symptoms of a system still unprepared to face the complexity of today’s digital threats.

These incidents raise serious questions about the readiness of business continuity plans (BCP) and disaster recovery centers (DRC) at securities firms. How resilient are their IT infrastructures? Have investments in cybersecurity become a budgetary priority, or are they still viewed merely as additional expenses?

This is why mitigating cybercrime risks is critical—to prevent these digital “muggers” from becoming even more brutal in plundering securities firms. Such efforts can no longer be handled piecemeal by individual firms. They must be approached collaboratively. According to the Infobank Institute, at least three pillars are required for such a collaborative effort.

First, regulators (OJK and IDX). Regulators must move faster than the cybercriminals themselves. OJK needs to issue more specific and mandatory technical guidelines on cybersecurity, supported by strict and regular audits.

Second, securities firms. They must invest in cybersecurity technology (next-generation firewalls, intrusion detection systems, SIEM). This is no longer optional—it is imperative. Equally important are client education, internal training, and transparent communication.

Third, investors. They must realize that they are the first line of defense. Securing devices, avoiding weak passwords, being cautious with suspicious links, and enabling all available security features are responsibilities that cannot be ignored.

It must be acknowledged that the wave of cybercrime in the securities industry in 2025 is not merely a wake-up call. It has already reached an emergency level. One by one, securities firms are being hacked and raided by cybercriminals.

This is not only a test of credibility for Indonesia’s capital market ecosystem—it is already a state of emergency. Market participants can no longer remain idle or treat this as a routine risk. What is urgently required is a paradigm shift: from merely adopting technology to building comprehensive digital resilience.

Cybercrime is no longer just a matter of caution. It is already an emergency—please!

Behind the convenience and speed of online and mobile trading platforms lies a widening black hole of danger. The series of cyberattacks striking the securities sector throughout 2025 are not isolated incidents. They are acute symptoms of a system still unprepared to face the complexity of today’s digital threats.

Lanjut baca artikel

Rekomendasi Terbaik

Mulai Berlangganan
Premium Infobank Digital

  • Akses ke Semua Artikel dari Semua Edisi Majalah Infobank

  • Baca Artikel & Majalah Tanpa Iklan

  • Kemudahan Akses di Berbagai Perangkat Web & Mobile

MULAI LANGGANAN

Beli majalah
Infobank Edisi Oktober 2025

Rp 65.000

BELI