Legal Review of Cyber Crime: Case of Attack Ransomware On Center Data National Temporary Surabaya 2
Abstract
The ransomware attack on the Temporary National Data Center Surabaya 2 (PDNS 2) in June 2024 became a major event that exposed serious vulnerabilities in Indonesia's national cybersecurity infrastructure. The attack, carried out by the hacker group Brain Cipher using the LockBit 3.0 ransomware variant, not only disrupted vital electronic systems across 282 government agencies but also posed a significant risk of personal data breaches. This incident underscores the urgency of evaluating existing regulations and the legal responsibilities of the state in protecting digital data. This study aims to examine the juridical aspects of the PDNS 2 ransomware case by analyzing applicable regulations and the role of government's as the data controller. Using a normative juridical approach, by examining primary data sources consisting of the Indonesian Criminal Code (KUHP), the Law of the Republic of Indonesia Number 11 of 2008 on Electronic Information and Transactions (ITE Law), the Law of the Republic of Indonesia Number 27 of 2022 on Personal Data Protection (PDP Law), as well as other relevant supporting regulations; secondary data sources derived from legal scholarly journals, previous research, official press releases of government institutions, and national news articles; and tertiary data sources in the form of definitions of several terms from encyclopedias, legal dictionaries, technical guidelines, compilations of regulations, and bibliographies. The findings reveal that PDNS Surabaya 2 suffered from weak system protection, including the use of basic security software (Windows Defender), the absence of a centralized backup policy, and administrative negligence in password management. Although Indonesia's current legal framework provides a basis for prosecuting cybercrime, its enforcement remains weak due to inadequate cybersecurity infrastructure. As the data controller, the government has a legal obligation to notify affected data subjects within 14 days and provide compensation for any violation of personal data processing. However, the government's short-term response has been insufficient in addressing underlying structural weaknesses. Comprehensive cybersecurity policy reform is urgently needed. Public trust in digital government services can only be restored through clear legal accountability and the systemic strengthening of national cybersecurity resilience.