The rapid advancement of information and communication technology has transformed conventional patterns of criminal conduct into digitally mediated forms, including cyber extortion. Unlike traditional extortion, which relies on physical coercion, cyber extortion operates through threats of disseminating personal data, sensitive information, or digital content to obtain unlawful benefits. Within contemporary criminal law discourse, this offense constitutes an information-control–based crime that generates not only economic harm but also social, psychological, and reputational damage to victims. This study examines the construction of criminal liability in cyber extortion under the Indonesian legal system and evaluates whether existing legal frameworks adequately address the distinctive characteristics of digitally facilitated coercion. Employing a normative juridical method that incorporates statutory, conceptual, and case-based approaches, the research analyzes provisions of the Indonesian Criminal Code and the Law on Electronic Information and Transactions, drawing on doctrinal and scholarly sources. The findings demonstrate that criminal liability remains anchored in the principles of legality and culpability; however, significant challenges arise in formulating offense elements, attributing digital actors operating through virtual identities, and authenticating electronic evidence. This article advocates for a normative reinterpretation of non-physical threats within extortion doctrine, arguing for adaptive penal policy reform to enhance legal certainty, evidentiary reliability, and victim protection in the digital era.