The burden on Indonesia’s counterterrorism (CT) services has increased due to terrorist groups’ exploitation of the internet. Between 2023 and 2025, the National Counter-Terrorism Agency (BNPT) recorded 137 actors who were actively abusing the internet for terrorism; in 2025 alone, 21,199 radical content pieces were reported on key platforms. In this setting, open source intelligence (OSINT), or intelligence drawn from publicly accessible material, has become a crucial strategic weapon; nevertheless, Indonesian scholarship is still dispersed and policy-disconnected. In accordance with PRISMA 2020 principles, a systematic literature review (SLR) of 47 peer-reviewed papers (2014–2025) is presented in this work together with a case study analysis of the 2018 Surabaya bombings and the 2024 disintegration of Jemaah Islamiyah (JI). The research reveals six theme clusters: the growth of OSINT, cyber tools and AI integration, terrorist cyberspace exploitation, OSINT applications in CT, ethical-legal frameworks, and the Indonesian institutional environment. As a result of inter-agency fragmentation across Densus 88, BNPT, BSSN, and BIN, the case studies show that pre-attack OSINT signals in 2018 were observable but not put together into actionable intelligence. The study makes the case that Indonesia needs a federated OSINT doctrine that is in line with Law No. 5/2018 and the Personal Data Protection Law (UU PDP 27/2022). It also suggests a five-part policy framework based on securitization theory, intelligence cycle theory, and second-generation OSINT.
Copyrights © 2026