Hafid Zakaria
Universitas Islam Batik Surakarta

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

MISUSE OF TAXPAYER DATA FOR PHISING SCAMS Nuradi Budi Prakoso; Hanuring Ayu; Hafid Zakaria
Journal of International Islamic Law, Human Right and Public Policy Vol. 4 No. 3 (2026): September
Publisher : PT. Radja Intercontinental Publishing

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

The rapid development of Indonesia's digital taxation ecosystem has simultaneously introduced new vulnerabilities that were previously absent in conventional tax administration systems. This research examines the misuse of taxpayer data as the primary instrument in phishing schemes, a phenomenon that not only inflicts financial and psychological harm on individual victims, but also erodes public trust in tax institutions and undermines the broader success of digital government transformation. This study employs a juridical-empirical method with a descriptive-analytical character, integrating statutory and conceptual approaches. The research yields three principal findings. First, taxpayer data occupies a uniquely strategic position as information collected under legal obligation, simultaneously encompassing identity, financial, and asset data, making it a high-value target whose misuse erodes the public trust that underpins Indonesia's self-assessment taxation paradigm. Second, the misuse of taxpayer data in phishing practices occurs through five primary modes, namely counterfeit website creation, mass deceptive messaging, malicious application distribution, voice phishing, and spear phishing, all of which exploit a five-phase exploitation chain and employ psychological manipulation techniques grounded in institutional authority, artificial urgency, and data-driven personalization. Third, the effectiveness of existing regulations, including the Electronic Information and Transactions Law, Law Number 27 of 2022 on Personal Data Protection, and the General Tax Provisions Law, remains insufficient due to fragmentation of legal substance, limited institutional enforcement capacity, and low legal awareness among taxpayers. This research recommends the accelerated operationalization of the Personal Data Protection Authority, the establishment of an integrated cross-institutional phishing detection and response system, and the strengthening of international legal cooperation as integral components of a systemic and sustainable data protection strategy.