The digital transformation of Islamic banking brings the consequence of increased cybercrime risks, particularly phishing. Legal issues arise when customers suffer financial losses due to the submission of One-Time Passwords (OTP) under psychological manipulation. This study aims to analyze the legal protection construction for phishing victims from the perspectives of Indonesian Positive Law and Fiqh Muamalah (Islamic Commercial Jurisprudence), and to formulate a fair liability concept. This research is a normative juridical study utilizing statutory and comparative approaches. The results indicate a dualism in legal protection. Positive Law, through the ITE Law (Electronic Information and Transactions Law), tends to place customers in a vulnerable position by citing user negligence when credentials are compromised, which often voids the bank's liability. Conversely, Fiqh Muamalah, through the Wadiah Yad Dhaman contract, positions the bank as a guarantor (dhamin) with strict liability for customer funds, unless gross negligence (tafrith) or violation of sharia principles is proven. This study concludes that the definition of negligence needs reconstruction. Customer ignorance regarding sophisticated social engineering modes cannot be equated with negligence. This article recommends the implementation of Shared Responsibility principles and a shifted burden of proof, where banks must prove the reliability of their fraud detection systems before attributing losses to customers.
Copyrights © 2026